Technical Security Consultant

Barclay Simpson

Greater London

Hybrid

GBP 80,000 - 110,000

Full time

11 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Barclay Simpson is seeking a Technical Security Consultant to support the development and continuous improvement of a Secure SDLC capability. This role blends secure software development lifecycle practices with DevSecOps, application security and architecture expertise to assess control effectiveness across modern engineering environments.

You will review security tooling, map controls to frameworks such as NIST SSDF and OWASP DSOMM, conduct control assessments and facilitate engineering

Qualifications

  • Strong Secure SDLC, DevSecOps or Application Security experience.
  • Good understanding of security controls throughout the software development lifecycle.
  • Experience with security assurance, control frameworks, architecture or capability mapping.

Responsibilities

  • Assess Secure SDLC controls across design, development, testing, release and operation.
  • Review security architecture, tooling coverage, integration dependencies and control gaps.
  • Assess capabilities including SAST, SCA, DAST, secrets scanning, IaC scanning, API security, threat modelling and CI/CD security.
  • Map controls against frameworks including NIST SSDF, OWASP SAMM and OWASP DSOMM.
  • Review security tooling and integrations across GitHub, GitLab, CI/CD and cloud environments.
  • Conduct control-effectiveness assessments, evidence reviews and maturity/gap analysis.
  • Facilitate workshops with engineering, security and product teams.
  • Support KPI/KRI development, assurance reporting and remediation oversight.

Skills

Secure SDLC
DevSecOps
Application Security
Stakeholder management

Tools

GitHub Advanced Security
CodeQL
Dependabot
Fortify
Qualys
Checkov

Job description

Technical Security Consultant required to support the development and continuous improvement of a Secure Software Development Lifecycle (SDLC) capability. This is a technical assurance role combining Secure SDLC, DevSecOps, application security and architecture expertise to assess control effectiveness, tooling coverage and adoption across modern engineering environments.

Key Responsibilities
  • Assess Secure SDLC controls across design, development, testing, release and operation.
  • Review security architecture, tooling coverage, integration dependencies and control gaps.
  • Assess capabilities including SAST, SCA, DAST, secrets scanning, IaC scanning, API security, threat modelling and CI/CD security.
  • Map controls against frameworks including NIST SSDF, OWASP SAMM and OWASP DSOMM.
  • Review security tooling and integrations across GitHub, GitLab, CI/CD and cloud environments.
  • Conduct control-effectiveness assessments, evidence reviews and maturity/gap analysis.
  • Facilitate workshops with engineering, security and product teams.
  • Support KPI/KRI development, assurance reporting and remediation oversight.
Key Experience
  • Strong Secure SDLC, DevSecOps or Application Security experience.
  • Good understanding of security controls throughout the software development lifecycle.
  • Experience with security assurance, control frameworks, architecture or capability mapping.
  • Knowledge of application security tooling such as GitHub Advanced Security, CodeQL, Dependabot, Fortify, Qualys or Checkov beneficial.
  • Strong stakeholder management with the ability to challenge technical and engineering teams.
  • Knowledge of vulnerability management, exception governance and remediation processes advantageous.
  • SC clearance or ability to obtain SC clearance required.

Barclay Simpson - global leaders in Cyber Security recruitment:

This is an official job listing by Barclay Simpson:

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Security Consultant
Technical Security Consultant

Barclay Simpson • City Of London

On-site
GBP 75,000 - 110,000
Secure SDLC & AppSec Advisory Lead
Secure SDLC & AppSec Advisory Lead

Barclay Simpson • City Of London

On-site
GBP 75,000 - 110,000
Secure SDLC Architect & DevSecOps Specialist
Secure SDLC Architect & DevSecOps Specialist

Barclay Simpson • Greater London

Hybrid
GBP 80,000 - 110,000
Security Architect (Outside IR35, DV cleared)
Security Architect (Outside IR35, DV cleared)

LA International • Basingstoke

On-site
GBP 60,000 - 80,000
Security Consultant
Security Consultant

Fruition Group • England

On-site
GBP 55,000 - 75,000
Security Assurance Lead
Security Assurance Lead

Motability Operations Ltd • Greater London

On-site
GBP 70,000 - 100,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Synergize Consulting Limited • Reading

Hybrid
GBP 81,000 - 115,000
Application Security Architect (Manchester)
Application Security Architect (Manchester)

Insight Investment • Manchester

On-site
GBP 70,000 - 100,000
Security Tester | Contract (12 Months+) | SC Clearance Required (Active/Lapsed) | Inside IR35
Security Tester | Contract (12 Months+) | SC Clearance Required (Active/Lapsed) | Inside IR35

WeDoTech • West of England

On-site
GBP 92,000 - 129,000
Cyber Security Controls Tester (Contractor)
Cyber Security Controls Tester (Contractor)

Cyberfort • Stone Cross

On-site
GBP 65,000 - 90,000