Security Assurance Lead
Security Assurance Lead
Location:Lond - 3 days on site a week
Salary: c.£80,000
We are looking for an experienced Security Assurance Lead to act as the primary security partner for the wider regulated business.
This is a highly collaborative role where you'll work closely with delivery teams, architects, engineers and business stakeholders to embed security throughout the delivery life cycle. You'll provide pragmatic, risk-based security guidance, conduct security reviews and threat modelling, coordinate assurance activities, and help ensure secure-by-design principles are applied across a diverse portfolio of business and technology initiatives.
What You'll Do
- Act as the lead Information Security contact for change and transformation projects and programmes.
- Provide practical security consultancy to delivery teams and stakeholders.
- Facilitate threat modelling workshops and conduct security risk assessments.
- Perform security assurance activities, including architecture, design and configuration reviews.
- Coordinate penetration testing and support remediation of identified vulnerabilities.
- Advise on application, cloud and platform security across AWS and Azure environments.
- Support and improve the Information Security Front Door engagement process.
- Work with specialist teams across Security Operations, Cloud Security, Identity and IT Continuity.
- Promote secure engineering practices and contribute to the development of security standards and processes.
About You
You'll be a security professional who combines strong technical knowledge with excellent stakeholder management skills. You enjoy working collaboratively with delivery teams, influencing outcomes and helping the business make informed, risk-based decisions.
Essential Experience
- Experience in Cyber Security, Security Consulting, Application Security or Security Engineering.
- Threat modelling experience, including STRIDE and Data Flow Diagrams (DFDs).
- Security assurance, architecture review and risk assessment experience.
- Experience coordinating penetration testing and vulnerability remediation.
- Knowledge of Secure by Design principles.
- Strong understanding of security frameworks such as ISO 27001 and NIST.
- Experience with AWS and Azure cloud environments.
- Understanding of CI/CD pipelines and secure software development practices.
- Excellent communication and stakeholder management skills.
Desirable
- CISSP or equivalent security certification.
- Experience working within large-scale business transformation programmes.
Why Apply?
You'll join a highly skilled Information Security function and work on a varied portfolio of sustainability, cyber security and business change initiatives. This is an excellent opportunity to influence strategic programmes, work alongside security specialists, and help shape the future of security across the organisation.
If this sounds like the role for you click the apply button now