We are seeking an experienced Cyber Prevent Specialist to join a dynamic cyber security team responsible for strengthening preventative security controls across products, services, applications, and technology environments. It's a long-term Contract role
This role will play a critical part in identifying cyber risks early in the delivery lifecycle, ensuring security controls are embedded by design, and providing security assurance across strategic programmer and initiatives. The successful candidate will work closely with business leaders, technology teams, architects, developers, and security stakeholders to reduce cyber risk and protect critical infrastructure, services, and customer data.
Key Responsibilities
Cyber Security Assurance & Risk Management
- Identify cyber security risks within new and existing products, services, applications, and technology solutions.
- Define and recommend preventative security controls to reduce or mitigate identified risks.
- Conduct security reviews and assessments of solution designs and implementations.
- Validate security controls before production deployment and go-live approval.
- Assess security implications of technology changes and transformations.
- Drive remediation activities and track security risks through to resolution.
- Support secure decommissioning of products, services, and technology assets.
Governance, Compliance & Reporting
- Manage Cyber Prevent activities across assigned business units and markets.
- Maintain security governance processes, standards, and reporting mechanisms.
- Support CHARM compliance activities and control assurance reviews.
- Review security evidence and monitor compliance against internal and external requirements.
- Perform risk assessments and provide recommendations to stakeholders.
- Escalate material risks and control weaknesses where required.
- Produce management reports, dashboards, trend analysis, and Key Risk Indicator (KRI) reporting.
Security Architecture & Preventative Controls
- Translate cyber security policies, frameworks, and standards into practical security requirements.
- Define security guardrails, architecture patterns, and security acceptance criteria.
- Review technical solutions to ensure security principles are embedded throughout the SDLC.
- Support the implementation of secure-by-design and secure-by-default practices.
- Collaborate with architects, engineers, and delivery teams to improve cyber resilience.
DevSecOps & Security Enablement
- Support the integration of security controls within Agile and DevSecOps environments.
- Assist in embedding security into CI/CD pipelines and development processes.
- Work with engineering teams to improve automated security controls and tooling.
- Promote cyber security awareness and best practices across delivery teams.
Qualifications
- Degree or Diploma in Information Security, Computer Science, Information Technology, Engineering, or a related field.
- Relevant cyber security certifications would be advantageous:
- CISSP
- CISM
- CISA
- CCSP
- Security+
- Azure Security Certifications
- AWS Security Certifications
Experience
- 5+ years' experience in Cyber Security, Information Security, Risk Management, Security Assurance, or Governance.
- Experience conducting cyber security risk assessments and security reviews.
- Exposure to enterprise technology environments and cloud platforms.
- Experience supporting security governance, compliance, and control assurance activities.
- Strong stakeholder management and communication skills.
Technical Skills Required
- Cyber Security Risk Management
- Security Assurance & Control Validation
- Information Security Governance
- Security Policies & Standards
- Security Architecture Principles
- Cloud Security (AWS, Azure, Google Cloud)