At a Glance
- Tasks: Guide teams in designing secure SaaS and PaaS platforms while reducing risk.
- Company: Major UK retailer investing in cyber security advisory capabilities.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Why this job: Be a trusted advisor and make a real impact on security practices.
- Qualifications: Experience in cyber security consulting and strong knowledge of IAM and API security.
- Other info: Collaborative environment with a focus on enabling delivery and innovation.
The predicted salary is between 36000 - 60000 £ per year.
We're working with a major UK retailer that's continuing to invest heavily in cyber security advisory capability across its digital and platform estate. This is a consultative role focused on guiding, influencing and enabling teams to design and operate secure SaaS and PaaS platforms at scale. Rather than hands-on operational delivery, you'll act as a trusted security advisor, partnering with engineering, platform and product teams to reduce risk, improve configuration hygiene and embed secure-by-design practices.
What you'll be doing:
- Acting as a Cyber Security Consultant to platform and engineering teams across SaaS/PaaS services (Microsoft, Google, Atlassian, MongoDB Atlas)
- Leading security reviews and advisory assessments focused on configuration, access, identity and platform risk
- Providing clear, pragmatic guidance on IAM, least privilege, Zero Trust and secure platform patterns
- Advising on API and database security design, controls and threat mitigation
- Supporting teams to embed security into CI/CD pipelines and IaC workflows, advising on guardrails rather than owning build
- Translating security risk into practical recommendations that delivery teams can implement quickly
- Producing guidance, standards and documentation, and running workshops and knowledge-sharing sessions
- Acting as a bridge between security, engineering, vendors and third parties
What we're looking for:
- Experience in a cyber security advisory, consulting or internal consulting-style role
- Strong grounding in Identity & Access Management (SSO, JWT, OAuth/OIDC, RBAC/ABAC, least privilege)
- Solid understanding of API security and database security fundamentals
- Working knowledge of Terraform, CI/CD and automation concepts (hands-on coding not required)
- Ability to assess risk, challenge designs constructively and influence without authority
- Comfortable engaging senior engineers, architects and product stakeholders
- A pragmatic mindset — focused on enabling delivery, not blocking it
Cyber Security Consultant in London employer: InfoSec People Ltd
Contact Detail:
InfoSec People Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Consultant in London
✨Tip Number 1
Network like a pro! Attend industry meetups, webinars, and conferences related to cyber security. This is your chance to connect with potential employers and showcase your expertise in a casual setting.
✨Tip Number 2
Leverage LinkedIn to its fullest! Update your profile to reflect your skills in IAM, API security, and secure platform patterns. Engage with posts from companies you’re interested in and don’t hesitate to reach out to recruiters directly.
✨Tip Number 3
Prepare for interviews by brushing up on your consultative skills. Be ready to discuss how you can guide teams in embedding security into their workflows without being a roadblock. Show them you’re all about enabling delivery!
✨Tip Number 4
Don’t forget to apply through our website! We’ve got loads of opportunities that match your skills. Plus, it’s a great way to get noticed by our hiring team who are always on the lookout for talent like yours.
We think you need these skills to ace Cyber Security Consultant in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV speaks directly to the role of Cyber Security Consultant. Highlight your experience in advisory roles and any specific projects that showcase your skills in IAM, API security, and secure platform practices.
Craft a Compelling Cover Letter: Use your cover letter to tell us why you’re the perfect fit for this consultative role. Share examples of how you've influenced teams and improved security practices in previous positions, and don’t forget to show your enthusiasm for working with us!
Showcase Your Communication Skills: Since this role involves acting as a bridge between various teams, make sure your application reflects your ability to communicate complex security concepts clearly. Use straightforward language and avoid jargon where possible to demonstrate your consultative approach.
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you get all the updates directly from us. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at InfoSec People Ltd
✨Know Your Cyber Security Fundamentals
Make sure you brush up on your knowledge of Identity & Access Management, API security, and database security. Be ready to discuss how these concepts apply to the role and provide examples from your past experiences where you've successfully implemented these practices.
✨Showcase Your Consultative Skills
This role is all about guiding and influencing teams, so prepare to demonstrate your consultative approach. Think of scenarios where you've acted as a trusted advisor, and be ready to explain how you navigated challenges and provided clear, pragmatic guidance.
✨Familiarise Yourself with Relevant Tools
While hands-on coding isn't required, having a working knowledge of tools like Terraform and CI/CD processes will set you apart. Be prepared to discuss how these tools can enhance security practices and how you've seen them used effectively in previous roles.
✨Prepare for Scenario-Based Questions
Expect questions that assess your ability to translate security risks into practical recommendations. Think through potential scenarios you might face in this role and how you would advise teams to embed security into their workflows without hindering delivery.