At a Glance
- Tasks: Conduct security risk assessments and advise on secure design principles.
- Company: Join a leading global financial services firm with a focus on Cyber Security.
- Benefits: Competitive daily rate, hybrid working model, and long-term contract.
- Other info: Collaborative environment with opportunities to work on diverse projects.
- Why this job: Make a real impact in securing innovative technology solutions.
- Qualifications: 10+ years in Cyber Security with strong application security knowledge.
The predicted salary is between 63000 - 77000 £ per year.
Senior Cyber Security Risk Assessment Consultant - DAST / SAST/ OWASP
Location
London
Contract
Long-term contract - 12 months
Working Model
Hybrid
Hiring
Multiple positions available
The Opportunity
We are looking for experienced
Senior Cyber Security Risk Assessment Consultants to join a major Cyber & Information Security function within a global financial services environment.
You will provide security expertise across a broad portfolio of business and technology projects, working closely with architects, engineers, developers, project teams, risk management and business stakeholders.
A key part of the position is performing technical security risk assessments , translating identified risks into security requirements, reviewing and validating solution designs, and defining appropriate security testing requirements.
This is not a SOC or purely operational security role.
We are looking for experienced security professionals who can understand complex technical solutions, identify security risks and vulnerabilities, and advise projects on the controls required to achieve
Secure by Design .
Key Responsibilities
- Perform security risk assessments across business and IT projects.
- Identify threats, vulnerabilities, security weaknesses and potential impacts within proposed solutions.
- Translate security architecture, policies, risks and controls into clear functional and technical security requirements .
- Define and advise on the design, implementation and testing processes required to protect information systems and assets.
- Embed
Secure by Design principles throughout the technology delivery lifecycle.
- Contribute to architectural and solution design discussions and validate designs against security requirements.
- Review applications, platforms and infrastructure from a security perspective.
- Define application security testing requirements , including appropriate use of DAST, SAST, code scanning and penetration testing.
- Define penetration-testing scope and work closely with security-testing teams throughout execution.
- Review security-testing and penetration-testing reports and assess whether identified risks have been appropriately addressed.
- Apply
OWASP principles and guidelines when assessing application security.
- Identify security gaps and recommend appropriate remediation and compensating controls.
- Produce and maintain security standards, principles, baselines and documented security requirements.
- Recommend new or improved security services and controls.
- Act as a
Security Subject Matter Expert for project and business teams.
- Present security risks, findings and recommendations clearly to both senior stakeholders and deep technical specialists.
- Work closely with Business Owners, Business Analysts, Project Managers, Risk Management, Architects, Developers, Engineers and internal/external auditors.
- Application Security / DAST / OWASP
- We are particularly interested in candidates with strong knowledge of
Application Security and experience across areas such as
- OWASP Top 10 and wider OWASP security principles
- DAST / Dynamic Application Security Testing
- SAST / Static Application Security Testing
- Secure SDLC / Secure by Design
- Application vulnerability assessment
- Web application security
- API security
- Code scanning and security-analysis tooling
- Penetration-testing methodology and scoping
- Security testing and test-result validation
- CI/CD security controls
- Dev Sec Ops
- Security and compliance automation
You do not need to be a hands-on penetration tester, but you should have sufficient technical knowledge to define security-testing requirements, scope appropriate testing, challenge findings and determine whether security risks have been adequately addressed .
Your Experience
For the senior positions, we are looking for candidates with
10+ years' experience within Cyber / Information Security .
- Proven experience performing technical security risk assessments .
- Strong understanding of application and/or infrastructure security.
- Experience identifying security risks and translating these into practical security requirements and controls.
- Experience contributing to and/or validating technical and architectural solution designs .
- Strong knowledge of
OWASP and application-security principles .
- Experience with DAST, SAST, vulnerability assessment, penetration testing or related security-testing approaches.
- Experience defining security-testing requirements and reviewing the resulting findings.
- Ability to understand complex applications, infrastructure and technology architectures.
- Experience producing security documentation, standards, principles, requirements or baselines.
- Experience translating business requirements into appropriate technical security solutions.
- Strong analytical and critical-thinking skills.
- Ability to take ownership of security assessments and work independently across multiple projects.
- Excellent stakeholder-management and communication skills.
- Ability to explain and defend security recommendations with both senior business stakeholders and highly technical IT professionals.
- Experience working within large, complex enterprise environments.
- Fluent English.
- Please do send across an up to date CV -
- *Rates depend on experience and client requirements
Senior Cyber Security Risk Assessment Consultant in London employer: Salt Search Careers
As a leading global firm, we pride ourselves on being an excellent employer that values innovation and collaboration. Our work culture fosters continuous learning and growth, providing employees with opportunities to enhance their skills while contributing to critical services in the UK. With a strong focus on employee well-being and a supportive environment, we ensure that our team members thrive both personally and professionally in vibrant locations like London, Manchester, Ipswich, and Cheltenham.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Cyber Security Risk Assessment Consultant in London
✨Get Engaged in Cybersecurity Communities
Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Salt Search Careers.
✨Showcase Your Skills Publicly
Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.
✨Stay On Top of Temp Opportunities
Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Salt Search Careers.
✨Make Contact with Recruiters Specialising in Cybersecurity
Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Salt Search Careers.
We think you need these skills to ace Senior Cyber Security Risk Assessment Consultant in London
Some tips for your application 🫡
Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Salt Search Careers a clear view of your capabilities right off the bat.
Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.
Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Salt Search Careers; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!
Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Salt Search Careers.
How to prepare for a job interview at Salt Search Careers
✨Brush Up on Technical Skills
Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Salt Search Careers for the Senior Cyber Security Risk Assessment Consultant, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.
✨Show Your Problem-Solving Prowess
Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!
✨Demonstrate Your Adaptability
As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Salt Search Careers.
✨Bring Relevant Certifications
If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Senior Cyber Security Risk Assessment Consultant role at Salt Search Careers.