Senior Cyber Security Consultant in Gerrards Cross
Senior Cyber Security Consultant

Senior Cyber Security Consultant in Gerrards Cross

Gerrards Cross Full-Time 43200 - 72000 ÂŁ / year (est.) No home office possible
Go Premium
Causeway

At a Glance

  • Tasks: Lead application security strategy and enhance secure software engineering practices.
  • Company: Join the UK's #1 construction software company with a focus on innovation.
  • Benefits: Enjoy 25 days leave, private medical insurance, and a fitness club allowance.
  • Why this job: Make a real impact in cyber security while working with cutting-edge technology.
  • Qualifications: Experience in software engineering and application security is essential.
  • Other info: Hybrid work options and a culture that values diversity and well-being.

The predicted salary is between 43200 - 72000 ÂŁ per year.

Do you want to help shape software that affects thousands of lives? We are ranked as the UK’s #1 construction specific software player and our mission is simple; to provide market leading end‑to‑end software solutions to the construction and construction‑like industries across the entire build life cycle. If you are looking to build an exceptional career with an award‑winning company you’ve come to the right place. Our teams are based in the UK, Europe, and India, working on products that are used on a global scale. We have a clear and defined road map to deliver over the next 3 years, which is centred around a large‑scale digital transformation as well as continuing our growth and expansion. We embrace diversity and equality and want our employees to be comfortable bringing their whole selves to work. We are committed to building a team with a variety of backgrounds, skills and views. Creating a culture of Equality isn’t just the right thing to do, it improves every aspect of our business.

Purpose

This is a senior, people focused role at the intersection of secure software engineering, application security, and enterprise cyber operations. You will lead the strategy and hands‑on execution for AppSec across a broad technology stack, partner with engineers to remediate complex vulnerabilities (first‑party code and third‑party libraries), run and improve offensive security and vulnerability management practices, and ensure alignment with ISO 27001, CE+, SOC2 and internal standards. A core expectation is to coach and upskill teams, embedding security by design and accelerating safe delivery.

Key Responsibilities

  • AppSec program uplift: SAST/DAST/SCA standardised and embedded across CI/CD with clear policies, SLAs and reporting.
  • Risk reduction: Demonstrable reduction in critical/high vulnerabilities in products and platforms; time‑to‑remediate improved quarter‑on‑quarter.
  • Developer enablement: Training programme launched (secure coding, threat modelling, vuln triage), with >90% adoption in priority teams.
  • Zero‑day readiness: Playbooks defined and tested; cross‑functional warroom capability established.
  • Governance: Metrics and KPI/KRI dashboards in place for exec and board‑level reporting.

Core Responsibilities

  1. Strategy & Leadership
    • Own the application security strategy and roadmap across products and platforms, aligned to business risk and compliance obligations (e.g., ISO 27001, NIST).
    • Work with Group Architect to set and govern secure SDLC standards.
    • Influence senior engineering leadership on security architecture decisions, backlog prioritisation, and risk acceptance.
  2. Application Security Engineering
    • Lead and mature SAST, DAST, SCA usage (e.g., Mend for SCA; equivalent SAST/DAST tools), with policy‑as‑code and pipeline gating where appropriate.
    • Conduct lightweight threat modelling and design reviews for new features and critical services (APIs, microservices, containers, serverless).
    • Guide and unblock remediation of complex vulnerabilities in first‑party code and third‑party libraries, providing developer ready fixes and patterns.
    • Design and deliver a hands‑on security training programme (secure coding, threat modelling, cloud AppSec, vuln triage) working closely with the Group Architect and Application Security Engineers.
  3. Offensive Security & Vulnerability Management
    • Direct and coordinate penetration testing (internal or partner-led); define scope, success criteria, and exec level reporting.
    • Validate findings (false positives/negatives), and partner with product/infrastructure teams to track remediation to closure.
  4. Zero‑Day & Incident Readiness
    • Lead the response to zero‑day events affecting our stack: assess exposure, coordinate mitigations, communication, and after‑action reviews.
    • Support security incident investigations; ensure escalation paths and evidence handling align with policy and legal requirements.
    • Lead tabletop exercises alongside incident response partners to ensure the effectiveness of Causeway’s Cyber Incident Response Plan.
  5. Governance, Risk & Compliance
    • Provide security input to policies, standards, and customer/security questionnaires.
    • Report risk posture regularly to the Head of GRC and senior IT leadership; contribute to Compliance Management Forum.
    • Ensure controls remain effective and audit‑ready for ISO 27001 and related frameworks.
    • Provide expertise in customer‑led security reviews and audits, demonstrating the effectiveness of security controls across Causeway products.
  6. DevSecOps Tooling & Platform Enablement
    • Administer and optimise AppSec and vulnerability tooling (e.g., Mend SCA, Qualys/Tenable, Defender for Endpoint), integrated into CI/CD and developer workflows (e.g., Git, build systems, ticketing such as Jira).

Key Skills, Experience and Qualifications

Technical & Engineering

  • Proven background in software engineering (e.g., .NET, Java, JavaScript/TypeScript, Python) and secure coding practices.
  • Strong experience operating and integrating SAST/DAST/SCA and AppSec controls into CI/CD.
  • Understanding of modern architectures: APIs, microservices, containers (Docker/K8s), serverless, secrets management, identity and access.

Offensive Security & Vulnerability Ops

  • Hands‑on with penetration testing methods and tooling (e.g., OWASP, Burp Suite, ZAP); able to set test charters and interpret results.
  • Practical experience with vulnerability scanners and endpoint/cloud security platforms (Qualys/Tenable, Defender for Endpoint), plus asset/coverage hygiene.
  • Skilled at triage and risk framing, mapping to business impact and SLAs.

Cloud & Platform

  • Experience securing workloads in AWS, Azure and/or GCP; multi‑cloud exposure preferred.
  • Familiar with cloud‑native controls (e.g., identity, networking, container security, posture management).
  • Experience in optimisation of perimeter security (WAF/API Security/Bot Protection).

Governance & Standards

  • Working knowledge of ISO 27001, NIST controls, CE+, SOC2 and secure SDLC/DevSecOps practices.
  • Comfortable producing metrics, KPIs/KRIs, and executive reporting.

Soft Skills (Senior)

  • Influential communicator – able to translate complex security issues into clear decisions for engineering and leadership.
  • Coach/mentor mindset; proven track record of uplifting teams.
  • Pragmatic, solutions oriented, and comfortable owning outcomes in ambiguous environments.

Qualifications (Nice to Have)

  • Relevant certs such as OSCP, GWAPT/GWEB, CSSLP, CISSP, CISM, or cloud security (e.g., AWS Security Specialty, AZ‑500).
  • Evidence of building/running training programmes or Security Champions networks.

Tools & Technologies

  • SCA: Mend (preferred), Snyk, etc.
  • SAST/DAST: SonarQube/ Burp Suite/ZAP.
  • Vulnerability Management: Tenable; Defender for Endpoint.
  • Pipelines & Dev: GitHub/GitLab/Azure DevOps; Jira; IaC (Terraform), containers/K8s.
  • Web Application Firewalls.

What you get from us

If you’re looking to build an exceptional career with an award‑winning company you’ve come to the right place. We believe everyone at Causeway has a vital role to play in our success. Causeway is fuelled by curiosity and is a place for people who beam with positivity and burn with ambition. Our team is everything, so we’ll take good care of you. In fact, we give well‑being the same priority as our other business goals. We’re strong advocates of work‑life balance, offering hybrid working alongside the opportunity to work from modern, collaborative offices.

Our Values

  • We are United. As part of a team, we’re better together.
  • We are Agile. Be the change, we’re on a journey.
  • We are Trusted. Do the right thing, we own this.
  • We are Driven. Get stuck in, we make it happen.

Benefits

  • 25 days annual leave + public holidays, increasing with length of service.
  • 4% matched pension.
  • Income protection and life assurance.
  • Access to our award‑winning benefits platform.
  • We take mental health seriously and have a dedicated EAP available 24/7.
  • ÂŁ100 allowance towards a fitness club.
  • Dell discounts.
  • Private Medical Insurance.
  • Paid study leave + volunteering days.
  • Car Scheme.

Like all responsible companies Causeway is aware of the need to recognise the importance of protecting our environment and addressing the climate emergency. Causeway is a carbon neutral company and we offset our calculated carbon footprint. However, we recognise that offsetting is not a permanent solution, so we set environmental objectives to reduce our footprint year‑on‑year.

Senior Cyber Security Consultant in Gerrards Cross employer: Causeway

At Causeway, we pride ourselves on being an award-winning employer that values diversity, well-being, and professional growth. Our hybrid working model allows for flexibility while our commitment to employee development ensures you will have the opportunity to enhance your skills in a supportive environment. With a strong focus on work-life balance, competitive benefits, and a culture that encourages collaboration and innovation, joining our team means being part of a mission-driven company that is making a significant impact in the construction software industry.
Causeway

Contact Detail:

Causeway Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Cyber Security Consultant in Gerrards Cross

✨Tip Number 1

Network like a pro! Reach out to folks in the industry on LinkedIn or at local meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects and contributions. This gives potential employers a taste of what you can do beyond your CV.

✨Tip Number 3

Prepare for interviews by practising common questions and scenarios related to cyber security. Mock interviews with friends can help you feel more confident and ready to impress.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are genuinely interested in joining us!

We think you need these skills to ace Senior Cyber Security Consultant in Gerrards Cross

Application Security
Secure Software Engineering
SAST/DAST/SCA Integration
Vulnerability Management
Penetration Testing
Cloud Security (AWS, Azure, GCP)
ISO 27001 Compliance
NIST Controls
Risk Assessment and Management
Threat Modelling
DevSecOps Practices
Metrics and Reporting
Coaching and Mentoring
Communication Skills
Problem-Solving Skills

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Senior Cyber Security Consultant role. Highlight your experience with secure software engineering and any relevant certifications. We want to see how your skills align with our mission!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Share your passion for cyber security and how you can contribute to our team. Don’t forget to mention specific projects or achievements that showcase your expertise.

Showcase Your Soft Skills: We value communication and teamwork just as much as technical skills. Make sure to highlight your ability to coach and mentor others, as well as your problem-solving mindset. We’re looking for someone who can lead and inspire!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re genuinely interested in joining our team!

How to prepare for a job interview at Causeway

✨Know Your Stuff

Make sure you brush up on your technical skills, especially in software engineering and secure coding practices. Familiarise yourself with SAST, DAST, and SCA tools, as well as the specific technologies mentioned in the job description like .NET, Java, and Python.

✨Showcase Your Leadership Skills

Since this is a senior role, be prepared to discuss your experience in leading teams and influencing decision-making. Think of examples where you've successfully coached others or improved security practices within a team.

✨Prepare for Scenario Questions

Expect questions that ask how you would handle specific security incidents or vulnerabilities. Prepare by thinking through your approach to risk management and incident response, and be ready to explain your thought process clearly.

✨Align with Company Values

Research the company's values and culture, and think about how your personal values align with theirs. Be ready to discuss how you embody their principles of being united, agile, trusted, and driven in your work.

Senior Cyber Security Consultant in Gerrards Cross
Causeway
Location: Gerrards Cross
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>