Security Consultant

Security Consultant

Full-Time On-site
T

The Role

As a Security Consultant focusing on Economic Crime team, provide end-to-end cyber security assurance across the Economic Crime technology estate, ensuring that applications, platforms, infrastructure, integrations and technology changes are designed, built and operated securely. The role will act as a trusted security advisor to engineering, architecture, infrastructure, DevOps, product, risk and business teams, embedding Secure by Design principles throughout the technology lifecycle.

Your responsibilities:

β€’ Act as the primary Security Assurance Consultant for projects and technology initiatives within the Economic Crime domain.

β€’ Conduct security assessments of new systems, material changes, integrations and technology solutions.

β€’ Provide pragmatic security advice that balances risk, regulatory expectations, customer protection and business delivery objectives.

β€’ Determine whether required preventative, detective and responsive controls are present and operating as intended.

β€’ Assess the likelihood and business impact of identified security risks & track them through to remediation, mitigation or formal acceptance.

β€’ Assess solutions against applicable security frameworks, policies and control requirements including NIST CSF 2.0 , ISO/IEC 27001, organisational security guardrails.

β€’ Define and enforce security policies, standards, and best practices ensuring Ensure compliance with financial regulations (e.g., PCI DSS, ISO 27001, GDPR).

β€’ Provide security assurance and guidance regarding IAM and PAM , Network Security , Penetration Testing Results , Vulnerability Scans etc.

β€’ Challenge solutions constructively where required security controls have not been implemented or have been implemented inadequately.

β€’ Maintain traceability between identified risks, security requirements, controls, evidence and residual risks.

Your Profile

Essential skills/knowledge/experience:

β€’ Proven experience performing security assurance or security consultancy within complex enterprise environments.

β€’ Demonstrable experience applying Secure by Design principles.

β€’ Proven understanding of security risk assessment methodologies.

β€’ Experience managing security risks, exceptions and remediation activities.

β€’ Experience and proven knowledge of working with NIST Cybersecurity Framework, ISO/IEC 27001, Zero Trust, OWASP Top 10 etc

β€’ Good understanding of Access Management, Data Security, Cloud Security, Network security guardrails

β€’ Confident enough to challenge architects, engineers and project leadership where security requirements are not adequately addressed.

β€’ Works collaboratively with delivery teams to find secure solutions instead of acting solely as an approval or governance function.

Desirable skills/knowledge/experience:

β€’ Previous experience of working in UK Financial Services or similar highly regulated industry.

β€’ Have a relevant professional qualification (or be working towards certification), such as CISM / CISSP.

β€’ Knowledge / experience of PCI-DSS, NIST CSF , OWASP Top 10 , ISO 27001

β€’ Knowledge / experience of Data privacy and GDPR;

β€’ Experience with regulatory compliance frameworks specific to financial organizations.

β€’ Excellent interpersonal and communication skills.

β€’ Able to differentiate between theoretical security concerns and material business risks, ensuring security decisions remain proportionate.

Security Consultant employer: Tcs Uk

As a Provisioning Engineer at our company, you will thrive in a dynamic work culture that prioritises innovation and collaboration. We offer competitive benefits, including professional development opportunities and a supportive environment that encourages growth in the rapidly evolving telecom sector. Located in a vibrant area, our team enjoys a balance of work and life, making it an excellent place for those seeking meaningful and rewarding employment.

T

Contact Details:

Tcs Uk Recruitment Team