At a Glance
- Tasks: Lead security consultancy, advise on digital solutions, and ensure compliance with security requirements.
- Company: Join a leading consultancy firm known for innovation and excellence in security.
- Benefits: Competitive pay, hybrid work model, and opportunities for professional growth.
- Other info: Collaborative team culture with opportunities for travel and personal development.
- Why this job: Make a real impact by securing cutting-edge digital solutions in a dynamic environment.
- Qualifications: Experience in technical security roles and strong understanding of security best practices.
The predicted salary is between 60000 - 80000 € per year.
Work Location: Watford
Role type: Contract Inside IR35
Mode of working: Hybrid 2 days/week
Duration of assignment: 4 Months
Any other working conditions: travel/on call/shifts
Normal UK business hours: 8:00 to 17:00 Hrs, Travel to London Office on ad-hoc basis. May need to travel to Birmingham and other office locations in UK for workshops etc. Expected 2 days a week.
The Role:
This role is within the Security Consultancy sub-team who provide specialist technical security advice collaborating with technical and business teams throughout the entire or part of a digital solution's life cycle. The team owns and develops Security Patterns, Security Specifications, and the Threat Modelling Framework, to support secure technology innovation in a changing threat landscape. The purpose of this role is to advise on the technical security aspects of digital solutions to be evaluated or developed and implemented by technology teams across KPMG Group for internal use, or as a service or product to KPMG clients.
The Technical Security Consultant's responsibilities will vary based on business alignment and will include:
- Lead as an internal consultant at Manager level to an assigned Platform/Product/Capability/Practice Management area as part of our Centre of Excellence function providing technical security direction, stakeholder management, and driving improvements to our ways of working.
- Collaborate with programs and projects, product and engineering teams to help deliver digital solutions that meet the business need, by supporting and contributing to design reviews. Ensuring that the proposed design, build and run are compliant with the KPMG and client security requirements – ensuring all applicable security controls and patterns are implemented.
- Work alongside internal Design Authorities and Change Management functions to ensure all change initiatives are reviewed, supported, and aligned with KPMG security requirements.
- Using threat modelling to provide risk and threat-based advice to program stakeholders along with actionable recommendations where necessary in the design and implementation of digital solutions.
- Advise on secure-by-design adoption of AI/GenAI capabilities (e.g. Microsoft 365 Copilot/Copilot Studio and LLM integrations) including prompt and data protection, model/service selection considerations, misuse and abuse cases, and appropriate technical guardrails.
- Manage the scoping of security testing requirements for new systems and products working closely with our Security Testing function.
- Undertake Post Deployment Security Architecture reviews of existing digital solutions.
- Support the creation of secure development guidance documentation and eLearning, security patterns and specifications in collaboration with Engineering/Development teams and Enterprise Security Architecture.
- Provide solution architecture support (i.e. PoC, design creation, roadmap support) for security solutions (e.g. AI, IAM).
- Work towards and achieve or extend professional certifications as part of personal development (e.g. security or cloud vendor certifications).
- Share experiences with others to assist their learning and understanding, and promote good security hygiene and its benefits.
Prior experience
Essential Skills/Experience:
- Have worked in at least one of: Infrastructure/Solution Architect, Technical Security Architect/Consultant, Security Operations, Secure application development.
- A good understanding of concepts and their application across several key areas including application, cloud, and SaaS security, best practices, and industry standards (and where relevant, AI/GenAI security concepts).
- You will bring hands-on experience and knowledge in securing digital products/solutions in at least one or more of the following areas:
- Artificial intelligence (e.g. AWS Bedrock, CoPilot, CoPilot Studio, Google Gemini, Azure OpenAI, Google Vertex)
- Cloud (e.g. AWS, Azure/M365, Google, ServiceNow, SAP)
- Networks (e.g. firewalls, routers, switches, WIFI, LAN/WAN, SDN)
- Operating Systems and hardware (e.g. Microsoft, Linux, Apple, Android)
- Security Solutions (e.g. Entra ID, CyberArk, SailPoint, Threat Modeler)
- Good experience of working in an Agile/DevOps software development environment using Threat Modelling.
- Be able to demonstrate the ability to adapt communication style to explain technical concepts to different people within an organization whether advising stakeholders, directing teams, or sharing experience.
- Experience prioritizing and delivering in an environment with competing demands and evolving requirements.
- Able to navigate through complex security problems to find the root cause and a balanced outcome, taking ownership of activities.
It would be desirable if you can demonstrate some, or all of the following:
- Container/serverless platforms.
- Infrastructure/network security.
- Modern application development processes and testing.
- AI/GenAI security (e.g. threat modelling for AI solutions, prompt injection and data exfiltration risks, data poisoning/model integrity risks, model/service supply chain considerations, and applying appropriate guardrails and monitoring).
- Have or working towards technical security certifications (e.g. CISSP, CCSP, Microsoft/Google/AWS technologies).
- Having worked in customer service/regulated environments, delivering high quality information security services.
Technical Security Consultant in Watford employer: Infoplus Technologies UK Limited
KPMG is an exceptional employer for a Technical Security Consultant, offering a dynamic hybrid work environment in Watford that fosters collaboration and innovation. With a strong commitment to employee growth, KPMG provides opportunities for professional development through certifications and hands-on experience with cutting-edge technologies, all while promoting a culture of security excellence and teamwork across diverse projects.
Contact Detail:
Infoplus Technologies UK Limited Recruiting Team
StudySmarter Expert Advice🤫
We think this is how you could land Technical Security Consultant in Watford
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even local events. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or a personal website showcasing your projects and achievements. This is especially important for a Technical Security Consultant role where practical experience speaks volumes.
✨Tip Number 3
Prepare for interviews by brushing up on your technical knowledge and soft skills. Practice common interview questions and scenarios related to security consultancy. We want you to feel confident and ready to impress!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Technical Security Consultant in Watford
Some tips for your application 🫡
Tailor Your CV:Make sure your CV speaks directly to the role of Technical Security Consultant. Highlight your experience in security architecture, threat modelling, and any relevant certifications. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about security consultancy and how your background makes you a perfect fit for our team. Don't forget to mention any specific projects or experiences that relate to the job description.
Showcase Your Technical Skills:In your application, be sure to highlight your hands-on experience with AI, cloud security, and secure application development. We love seeing real-world examples of how you've tackled complex security challenges in the past!
Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates. Plus, it’s super easy to do!
How to prepare for a job interview at Infoplus Technologies UK Limited
✨Know Your Stuff
Make sure you brush up on your technical security knowledge, especially around AI/GenAI and cloud security. Be ready to discuss specific tools and frameworks you've used, like threat modelling or security specifications, as this role requires hands-on experience.
✨Showcase Your Collaboration Skills
This position involves working closely with various teams, so be prepared to share examples of how you've successfully collaborated in the past. Highlight any experiences where you’ve led design reviews or worked with stakeholders to ensure compliance with security requirements.
✨Prepare for Scenario Questions
Expect to face scenario-based questions that assess your problem-solving skills in complex security situations. Think about past challenges you've faced and how you navigated them, particularly in Agile/DevOps environments.
✨Ask Insightful Questions
At the end of the interview, don’t shy away from asking questions. Inquire about the team’s current projects or how they approach secure-by-design principles. This shows your genuine interest in the role and helps you gauge if it’s the right fit for you.