Information Security Consultant
Core
Provide specialist security consultancy and pragmatic, risk-based advice to business and technology teams, focusing on enabling digital transformation and uplifting application security across modern engineering environments.
Role type
Senior Information Security Consultant (Advisory & Application Security)
Builds
Secure-by-Design practices, secure SDLC integration, and resilient security governance for third-party ecosystems.
Domain
Banking / Financial Services / Cybersecurity
Deliverable
client delivery
Required skills
Security risk consulting, digital transformation program support, application security expertise (secure SDLC, threat modelling, vulnerability management), security framework application (ISO 27001, NIST, CIS, OWASP), stakeholder influence, analytical problem-solving, business acumen
Preferred skills
Professional certifications (CISSP, CISM, CISA, CCSP), cloud and cloud-native technologies experience, knowledge of regulatory standards (PCI DSS, Sarbanes Oxley)
Technologies
CI/CD pipelines, SAST/DAST tools, dependency scanners, container platforms, Infrastructure-as-Code
Responsibilities
Provide specialist security consultancy and risk-based advisory to business and technology teams; Partner with engineering teams to embed Secure-by-Design and secure SDLC practices; Lead application security assurance activities including architecture risk assessments and vulnerability triage; Assess and manage information security risks for projects, systems, APIs, and third-party engagements; Ensure change initiatives align with security frameworks and drive remediation plans; Translate complex security risks into clear business impacts and prioritised recommendations; Support governance of supplier and outsourced security processes
Seniority
Senior, hands-on IC with advisory focus