At a Glance
- Tasks: Lead consulting engagements on Cyber Security, focusing on EU regulations and supply chain security.
- Company: Join EPAM, a leader in tech consulting with a focus on security.
- Benefits: Enjoy competitive pay, health coverage, stock options, and learning opportunities.
- Why this job: Make a real impact by tackling complex security challenges across diverse industries.
- Qualifications: Experience in security consulting and knowledge of EU Cyber Resilience Act required.
- Other info: Dynamic work environment with great career growth and exciting perks.
The predicted salary is between 43200 - 72000 £ per year.
As a Cyber Security Consultant at EPAM, you will help clients address complex security challenges with a particular focus on the EU Cyber Resilience Act (CRA), Supply Chain Security, and related GRC topics. This is a senior-level position where you will leverage your expertise to advise on security problems across diverse industries. You will collaborate with cross-functional teams, support pre-sales activities and contribute to practice development, helping EPAM grow its security consulting capabilities.
Responsibilities
- Lead and deliver consulting engagements focused on CRA, Supply Chain Security and related regulations (e.g., NIS2).
- Drive CRA readiness for products with digital elements: scoping, product classification, gap assessments against essential requirements, risk analysis, control design, remediation roadmaps and technical documentation.
- Establish and mature product security capabilities: secure development lifecycle, secure update processes, vulnerability handling and coordinated vulnerability disclosure (CVD), PSIRT setup/operations, SBOM generation/management and vulnerability triage.
- Design and implement supply chain security and third party risk management programs: supplier risk segmentation, due diligence, contractual/security requirements, continuous monitoring and integration with procurement/vendor management.
- Translate regulatory requirements (CRA, NIS2) into actionable control frameworks and policies; map to standards such as ISO 27001/27002/27036, NIST CSF/SP 800/, CIS Controls, OWASP, etc.
- Conduct risk assessments and threat modeling for products and suppliers; define mitigation strategies, metrics and KPIs.
- Produce clear, high quality deliverables: assessment reports, control designs, implementation plans, policies, process maps and training.
- Collaborate with client stakeholders across security, engineering, product, operations, legal and compliance; facilitate workshops and drive change.
- Support pre sales: discovery sessions, solution design, level of effort estimates, proposals, and presentations; contribute reusable content and accelerators.
- Contribute to EPAM's security consulting practice: methodology development, knowledge sharing, mentoring and thought leadership.
- Stay current on emerging threats, regulatory changes and best practices in product security, supply chain security and GRC.
Requirements
- Proven security consulting experience with direct focus on the EU Cyber Resilience Act, Supply Chain Security, NIS2 and broader GRC topics.
- Demonstrable experience establishing product security capabilities (PSIRT, CVD, SBOM management, secure development/update practices) in complex product or software organizations.
- Strong familiarity with EU regulatory context (CRA, NIS2) and practical aspects of conformity assessment, technical documentation and CE marking; experience engaging notified bodies is a plus.
- Broad knowledge of frameworks and standards (ISO 27001, NIST CSF, NIST SP 800 161, NIST SSDF, CIS Controls, OWASP) and the ability to perform control mapping and tailored implementations.
- Experience advising on or implementing security solutions in large enterprise and product engineering environments, including supplier risk management and secure software supply chain practices.
- Strong analytical, communication and facilitation skills; ability to explain complex topics to technical and non-technical stakeholders.
- Demonstrated pre sales experience and contributions to practice development.
- Senior-level consulting experience across multiple industries.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CCSK/CCSP are desirable.
- Bachelor's or master's degree in computer science, Information Security, Engineering, or a related field.
We offer/Benefits
- EPAM Employee Stock Purchase Plan (ESPP).
- Protection benefits including life assurance, income protection and critical illness cover.
- Private medical insurance and dental care.
- Employee Assistance Program.
- Competitive group pension plan.
- Cyclescheme, Techscheme and season ticket loans.
- Various perks such as free Wednesday lunch in-office, on-site massages and regular social events.
- Learning and development opportunities including in-house training and coaching, professional certifications, over 22,000 courses on LinkedIn Learning Solutions and much more.
- If otherwise eligible, participation in the discretionary annual bonus program.
- If otherwise eligible and hired into a qualifying level, participation in the discretionary Long-Term Incentive (LTI) Program.
- All benefits and perks are subject to certain eligibility requirements.
Cyber Security Consultant in London employer: EPAM
Contact Detail:
EPAM Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Consultant in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the cyber security field, attend industry events, and join relevant online forums. The more people you know, the better your chances of landing that dream job.
✨Tip Number 2
Show off your expertise! Create a portfolio showcasing your past projects, case studies, or any relevant certifications. This will help you stand out during interviews and demonstrate your skills in action.
✨Tip Number 3
Prepare for those tricky interview questions! Research common cyber security scenarios and think about how you'd tackle them. Practising your responses will help you feel more confident when it’s time to shine.
✨Tip Number 4
Don’t forget to apply through our website! We’ve got loads of opportunities waiting for you, and applying directly can give you an edge. Plus, it shows you’re genuinely interested in joining our team!
We think you need these skills to ace Cyber Security Consultant in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Cyber Security Consultant role. Highlight your experience with the EU Cyber Resilience Act and Supply Chain Security, as these are key areas for us at EPAM.
Showcase Your Skills: Don’t just list your skills; demonstrate them! Use specific examples from your past work that show how you've tackled security challenges and contributed to practice development.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Explain why you’re passionate about cyber security and how your background makes you a perfect fit for our team. Keep it engaging and relevant!
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s straightforward and ensures your application goes directly to our hiring team!
How to prepare for a job interview at EPAM
✨Know Your Regulations
Make sure you brush up on the EU Cyber Resilience Act and NIS2 regulations. Being able to discuss these topics confidently will show that you understand the core responsibilities of the role and can hit the ground running.
✨Showcase Your Experience
Prepare specific examples from your past work where you've established product security capabilities or conducted risk assessments. Use the STAR method (Situation, Task, Action, Result) to structure your answers and make them impactful.
✨Communicate Clearly
You’ll need to explain complex security concepts to both technical and non-technical stakeholders. Practice simplifying your explanations and be ready to demonstrate your strong communication skills during the interview.
✨Engage with Pre-Sales Scenarios
Since pre-sales activities are part of the role, think about how you would approach discovery sessions or solution design. Be prepared to discuss how you would contribute to proposals and presentations, showcasing your collaborative spirit.