Cyber Security Specialist with Threat Modeling
Primary Roles & Responsibilities
1. Security Architecture Liaison & Enablement ("The Connector")
Act as the dedicated security consultant to business product lines, application developers, and DevOps teams, accelerating safe project delivery.
Embed enterprise security domains—including Endpoints, Network security, Cryptography, and Identity & Access Management (IAM)—directly into emerging engineering streams.
Guide technical squads on implementing secure contemporary architectures, safely handling RESTful APIs and containerized microservices.
2. Threat Modelling & Proactive Risk Management
Maintain an up-to-date stance on the evolving financial service threat landscape.
Lead collaborative Threat Modelling workshops using structured frameworks such as STRIDE and MITRE ATT&CK to systematically uncover architectural vulnerabilities before production deployment.
Formulate clear risk-mitigation strategies that balance agility with strict data-integrity requirements.
3. Strategic Infrastructure & Enterprise Scaling
Assure secure engineering standards during the migration and scaling of bank platforms across any major Public Cloud environments (AWS, Azure, or GCP).
Design and implement technical guardrails that enforce "Secure-by-Design" principles automatically within cloud infrastructure pipelines (Infrastructure as Code).
Regulatory & Compliance Frameworks
A core focus of this role is embedding security controls that ensure absolute alignment with UK and international financial services regulations. You will design architectures that satisfy:
DORA (Digital Operational Resilience Act): Ensure all applications and third-party integrations support rigorous ICT risk management, incident reporting, and operational resilience testing capabilities.
FCA & PRA Guidelines: Align system architectures with the Financial Conduct Authority and Prudential Regulation Authority handbooks on operational resilience (specifically SYSC 15.1 and FG16/5 for cloud outsourcing).
UK GDPR & Data Privacy: Oversee the strict isolation and encryption of Personally Identifiable Information (PII) and financial records at rest and in transit.
Industry Standards: Map security templates against established global models including PCI DSS (v4.0), ISO 27001, NIST SP 800-53, OWASP Top 10, and COBIT.
Technical Stack & Ecosystem Tooling
The candidate will actively utilize, integrate, or govern the following technologies across the secure software development lifecycle (SSDLC):
Cloud Infrastructure (Any Platform): AWS (IAM, CloudTrail, GuardDuty), Microsoft Azure (Microsoft Defender for Cloud, Entra ID), or Google Cloud Platform (GCP Security Command Center).
Infrastructure as Code (IaC) & Security: Terraform, Ansible, or CloudFormation alongside static analysis tools like Checkov, TFLint, or Terrascan.
Containerization & Orchestration: Docker and Kubernetes (K8s) security solutions (e.g., Aqua Security, Prisma Cloud, or Sysdig).
Application Security (SAST/DAST/SCA): Integrations with automated vulnerability platforms like Snyk, SonarQube, Veracode, or Checkmarx.
Identity & Access Management (IAM): OAuth 2.0, OIDC, SAML, and enterprise solutions like Ping Identity, Okta, or CyberArk.
CI/CD Automation & Observability: Jenkins, GitHub Actions, or GitLab CI integrated with logging clusters like Splunk, Datadog, or ELK Stack.
Secondary Roles & Responsibilities
1. Operational Research & Incident Advisory
Evaluate threat intelligence data and primary risk trends to continuously recommend security enhancements to the platform's security stack.
Support incident readiness functions by acting as the domain subject matter expert (SME) during technical forensic review or security post-mortems.
2. Stakeholder Management & Documentation
Develop and deliver transparent security playbooks and design blueprints that reduce security friction for technical teams.
Translate complex risk items into plain, metric-backed summaries for non-technical senior executives and client-facing business partners.
Key Skills & Qualifications
Experience Requirements
5+ years of dedicated professional experience in Cyber Security Engineering, Information Security Architecture, or DevSecOps contexts.
Proven track record of working within the banking or highly regulated financial services sector in the UK.
Demonstrable history of driving secure engineering deliverables across multi-functional development squads.
Technical Knowledge
Enterprise Tech & Architectures: Deep technical familiarity with cloud security fundamentals, container security, and API gateway design paradigms.
Core Security Expertise: Demonstrable history managing core enterprise domains (specifically public-key cryptography, TLS configurations, network zoning, and microsegmentation).
Framework Mastery: Confident hands-on experience utilizing STRIDE or MITRE ATT&CK concepts in real-world software lifecycles.
Professional Certifications
Security Management: At least one active certification such as CISSP, CISM, CCSP, or equivalent baseline credential.
Technical Domains: Valued additions include technical certifications like CEH, OSCP, or cloud-specific security credentials (e.g., AWS Certified Security, Microsoft Certified: Azure Security Engineer).
Person Specification
Exceptional client-facing, communication, and cross-functional negotiation skills.
Proven capability to build consensus and drive resolution when engineering speed conflicts with security policy.
High professional integrity, adaptability, and resilience inside highly regulated environments.