Information Security Consultant
Information Security Consultant

Information Security Consultant

Temporary 36000 - 60000 Β£ / year (est.) Home office (partial)
Go Premium
E

At a Glance

  • Tasks: Lead advanced security testing initiatives and manage ethical hacking campaigns.
  • Company: Join a pioneering international organisation focused on sustainability and diversity.
  • Benefits: Flexible working, diverse culture, and opportunities for professional growth.
  • Why this job: Make a real impact in cybersecurity while collaborating with experts across various sectors.
  • Qualifications: Experience in cybersecurity, Red/Purple Team operations, and strong analytical skills.
  • Other info: Dynamic environment with a commitment to inclusion and innovation.

The predicted salary is between 36000 - 60000 Β£ per year.

We are seeking a highly skilled Information Security Consultant to lead the scoping, planning, and execution of advanced security testing initiatives, including Red Team and Purple Team engagements. We are looking for a specialist experienced in managing and delivering ethical hacking campaigns, Red/Purple team assessments and technical risk assessments. This role validates defensive capabilities, synthesises complex findings to provide actionable guidance for improvement of cyber posture and resilience. This role bridges technical security and security risk management and requires knowledge of risk assessment methodologies, an ability to produce metrics, reporting and dashboards as well as translate and present technical language, concepts and impacts into a language that facilitates business decision making.

Key Responsibilities

  • Define objectives, scope, and success criteria for Red Team and Purple Team exercises.
  • Develop detailed test plans aligned with organizational risk priorities and compliance requirements.
  • Coordinate scheduling and resource allocation for internal and external stakeholders.
  • Act as the primary liaison between internal teams and external MSSPs/consultants.
  • Ensure testing activities adhere to agreed timelines, methodologies, and ethical guidelines.
  • Monitor progress and provide status updates to senior leadership.
  • Review and validate attack scenarios, tactics, techniques, and procedures (TTPs) used during engagements.
  • Ensure Purple Team exercises effectively integrate offensive and defensive teams for collaborative improvement to enhance detection and response.
  • Analyse findings from Red and Purple Team engagements.
  • Prepare comprehensive reports detailing vulnerabilities, attack paths, and defensive gaps.
  • Prepare and present results to technical and non-technical stakeholders, including reporting for EBRD senior leadership.
  • Incorporate technical findings and outcomes into information security risk reporting templates.
  • Provide actionable remediation steps and strategic recommendations based on findings.
  • Collaborate with IT security, security engineering, architecture and operations teams to guide implementation improvements.
  • Track remediation progress and validate effectiveness through follow-up testing.

Technical Expertise

  • Strong understanding of adversarial tactics (MITRE ATT&CK framework) and threat emulation.
  • Experience with penetration testing, exploit development, and detection engineering.
  • Familiarity with SIEM, EDR, and threat-hunting tools.
  • Commitment to staying up to date with emerging threats and remedies.

Reporting & Presentation

  • Ability to translate technical concepts, including technical risk, into business language and business impact.
  • Experience in proposing actionable remedial steps to address findings.
  • Experience of reporting meaningful metrics to a variety of internal technical and non-technical audiences.
  • Proven ability to work with external MSSPs and consultants.
  • Experience in overseeing and managing testing campaigns with a variety of internal stakeholders.
  • Excellent communication skills for cross-functional engagement.

Certifications (Preferred)

  • OSCP, OSCE, CRTO, or similar offensive security certifications.
  • GIAC certifications (e.g., GCTI, GPEN, GCFA) or equivalent.

Experience

  • Extensive background in cybersecurity, covering all major security domains, with solid hands-on experience in Red and Purple Team operations.
  • Hands-on experience in scoping and managing security testing engagements.
  • Solid experience in metrics and reporting.

Key Attributes

  • Strategic thinker with strong analytical skills.
  • Ability to translate technical findings into business risk language.
  • Ability to partner with a wide range of technical and non-technical stakeholders.

Our agile and innovative approach is what makes life at the EBRD a unique experience! You will be part of a pioneering and diverse international organisation, and use your talents to make a real difference to people's lives and help shape the future of the regions we invest in.

The EBRD Environment Provides You With

  • Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public and private sectors across the regions we invest in.
  • A working culture that embraces inclusion and celebrates diversity.
  • An environment that places sustainability, equality and digital transformation at the heart of what we do.

Diversity is one of the Bank’s core values which are at the heart of everything it does. A diverse workforce with the right knowledge and skills enables connection with our clients, brings pioneering ideas, energy and innovation. The EBRD staff is characterised by its rich diversity of nationalities, cultures and opinions and we aim to sustain and build on this strength. As such, the EBRD seeks to ensure that everyone is treated with respect and given equal opportunities and works in an inclusive environment. The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, sexual orientation or disabilities. As an inclusive employer, we promote flexible working and expect our employees to attend the office 50% of their working time.

Information Security Consultant employer: EBRD

The EBRD is an exceptional employer, offering a dynamic and inclusive work environment in the heart of London. Employees benefit from engaging projects that foster collaboration across diverse sectors, alongside opportunities for professional growth and development in the rapidly evolving field of cybersecurity. With a commitment to sustainability and equality, the EBRD empowers its staff to make a meaningful impact while enjoying a flexible working culture that values diversity and innovation.
E

Contact Detail:

EBRD Recruiting Team

StudySmarter Expert Advice 🀫

We think this is how you could land Information Security Consultant

✨Tip Number 1

Network like a pro! Reach out to your connections in the cybersecurity field, attend industry events, and join relevant online communities. You never know who might have the inside scoop on job openings or can refer you directly.

✨Tip Number 2

Show off your skills! Create a portfolio showcasing your past Red Team and Purple Team engagements, including reports and metrics. This will help potential employers see your expertise in action and how you can add value to their team.

✨Tip Number 3

Prepare for interviews by brushing up on your technical knowledge and soft skills. Be ready to discuss your experience with ethical hacking, risk assessments, and how you translate complex findings into business language. Practice makes perfect!

✨Tip Number 4

Apply through our website! We’ve got loads of opportunities waiting for talented individuals like you. Plus, it’s a great way to ensure your application gets seen by the right people. Don’t miss out!

We think you need these skills to ace Information Security Consultant

Red Team Engagements
Purple Team Assessments
Ethical Hacking
Risk Assessment Methodologies
Metrics and Reporting
Technical Risk Translation
Adversarial Tactics (MITRE ATT&CK)
Penetration Testing
Exploit Development
SIEM and EDR Tools
Threat-Hunting Tools
Communication Skills
Collaboration with MSSPs
Strategic Thinking
Analytical Skills

Some tips for your application 🫑

Tailor Your Application: Make sure to customise your CV and cover letter for the Information Security Consultant role. Highlight your experience with Red Team and Purple Team engagements, and don’t forget to mention any relevant certifications you hold!

Showcase Your Skills: We want to see your technical expertise shine! Include specific examples of your hands-on experience in penetration testing and risk assessments. Use metrics and reporting to demonstrate your impact in previous roles.

Be Clear and Concise: When writing your application, keep it straightforward. Use clear language to explain complex concepts, especially when discussing your findings and recommendations. Remember, we need to understand your thought process easily!

Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for this exciting opportunity at StudySmarter.

How to prepare for a job interview at EBRD

✨Know Your Stuff

Make sure you brush up on the MITRE ATT&CK framework and be ready to discuss specific adversarial tactics. Familiarity with penetration testing and detection engineering will show that you’re not just a theory person but someone who can get hands-on.

✨Speak Their Language

Practice translating technical jargon into business language. You’ll need to present findings to both technical and non-technical stakeholders, so being able to articulate complex concepts simply is key. Think about how your past experiences can relate to business impacts.

✨Show Your Strategic Side

Prepare examples of how you've defined objectives and success criteria for previous Red or Purple Team exercises. Highlight your ability to develop detailed test plans and coordinate with various teams, as this role requires strong collaboration skills.

✨Be Ready to Discuss Metrics

Since reporting and metrics are crucial in this role, come prepared with examples of how you've tracked remediation progress and validated effectiveness in past engagements. This will demonstrate your analytical skills and your commitment to continuous improvement.

Information Security Consultant
EBRD
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

E
  • Information Security Consultant

    Temporary
    36000 - 60000 Β£ / year (est.)
  • E

    EBRD

    500-1000
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>