Technical Security Consultant

Barclay Simpson

City Of London

On-site

GBP 75,000 - 110,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Barclay Simpson is seeking a Technical Security Consultant to support the development and continuous improvement of a Secure Software Development Lifecycle (SDLC) capability. This role blends secure SDLC, DevSecOps, application security and architecture expertise to assess control effectiveness, tooling coverage and adoption across modern engineering environments.

Key responsibilities include assessing SDLC controls, reviewing security architecture and tooling, mapping controls to frameworks

Qualifications

  • Strong Secure SDLC, DevSecOps or Application Security experience.
  • Good understanding of security controls throughout the software development lifecycle.
  • Experience with security assurance, control frameworks, architecture or capability mapping.

Responsibilities

  • Assess Secure SDLC controls across design, development, testing, release and operation.
  • Review security architecture, tooling coverage, integration dependencies and control gaps.
  • Assess capabilities incl. SAST, SCA, DAST, secrets scanning, IaC scanning, API security, threat modelling and CI/CD security.
  • Map controls against frameworks including NIST SSDF, OWASP SAMM and OWASP DSOMM.
  • Review security tooling and integrations across GitHub, GitLab, CI/CD and cloud environments.
  • Conduct control-effectiveness assessments, evidence reviews and maturity/gap analysis.
  • Facilitate workshops with engineering, security and product teams.
  • Support KPI/KRI development, assurance reporting and remediation oversight.

Skills

Secure SDLC
DevSecOps
Application Security
Stakeholder management
Vulnerability management
Exception governance
Remediation oversight

Tools

GitHub Advanced Security
CodeQL
Dependabot
Fortify
Qualys
Checkov

Job description

Technical Security Consultant required to support the development and continuous improvement of a Secure Software Development Lifecycle (SDLC) capability. This is a technical assurance role combining Secure SDLC, DevSecOps, application security and architecture expertise to assess control effectiveness, tooling coverage and adoption across modern engineering environments.

Key Responsibilities
  • Assess Secure SDLC controls across design, development, testing, release and operation.
  • Review security architecture, tooling coverage, integration dependencies and control gaps.
  • Assess capabilities including SAST, SCA, DAST, secrets scanning, IaC scanning, API security, threat modelling and CI/CD security.
  • Map controls against frameworks including NIST SSDF, OWASP SAMM and OWASP DSOMM.
  • Review security tooling and integrations across GitHub, GitLab, CI/CD and cloud environments.
  • Conduct control-effectiveness assessments, evidence reviews and maturity/gap analysis.
  • Facilitate workshops with engineering, security and product teams.
  • Support KPI/KRI development, assurance reporting and remediation oversight.
Key Experience
  • Strong Secure SDLC, DevSecOps or Application Security experience.
  • Good understanding of security controls throughout the software development lifecycle.
  • Experience with security assurance, control frameworks, architecture or capability mapping.
  • Knowledge of application security tooling such as GitHub Advanced Security, CodeQL, Dependabot, Fortify, Qualys or Checkov beneficial.
  • Strong stakeholder management with the ability to challenge technical and engineering teams.
  • Knowledge of vulnerability management, exception governance and remediation processes advantageous.
  • SC clearance or ability to obtain SC clearance required.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Security Consultant
Technical Security Consultant

Barclay Simpson • Greater London

Hybrid
GBP 80,000 - 110,000
Security Consultant
Security Consultant

Fruition Group • England

On-site
GBP 55,000 - 75,000
Secure SDLC & AppSec Advisory Lead
Secure SDLC & AppSec Advisory Lead

Barclay Simpson • City Of London

On-site
GBP 75,000 - 110,000
Security Assurance Lead
Security Assurance Lead

Motability Operations Ltd • Greater London

On-site
GBP 70,000 - 100,000
Secure SDLC Architect & DevSecOps Specialist
Secure SDLC Architect & DevSecOps Specialist

Barclay Simpson • Greater London

Hybrid
GBP 80,000 - 110,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Synergize Consulting Limited • Reading

Hybrid
GBP 81,000 - 115,000
IT Assurance Lead
IT Assurance Lead

ARM LIMITED • Reading

On-site
GBP 70,000 - 100,000
Cyber Security Controls Tester (Contractor)
Cyber Security Controls Tester (Contractor)

Cyberfort • Stone Cross

On-site
GBP 65,000 - 90,000
Security Tester | Contract (12 Months+) | SC Clearance Required (Active/Lapsed) | Inside IR35
Security Tester | Contract (12 Months+) | SC Clearance Required (Active/Lapsed) | Inside IR35

WeDoTech • West of England

On-site
GBP 92,000 - 129,000
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources • City Of London

Hybrid
GBP 72,000 - 88,000