Company Description
Version 1 celebrates 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables customers to navigate the rapidly evolving technology landscape, partnered with leaders such as Microsoft, AWS, Oracle, Red Hat, OutSystems, and Snowflake.
Job Description
We are seeking a hands‑on Security Consultant who can combine deep technical delivery capability with strong client‑facing consulting skills. The role requires assessing, designing, improving, and governing security controls across cloud environments, applications, APIs, infrastructure, and enterprise security domains to challenge assumptions, influence stakeholders, and lead secure outcomes.
Responsibilities
- Assess current‑state security maturity, identify control gaps, and define pragmatic remediation roadmaps aligned to business priorities.
- Lead and support security architecture reviews across cloud, applications, infrastructure, IAM, data protection, and detection/response domains.
- Provide expert consulting on security strategy, risk reduction, control design, and security operating model improvements.
- Challenge weak security assumptions and communicate evidence‑based recommendations to technical and non‑technical stakeholders.
- Design and review secure cloud landing zones, network segmentation, identity models, logging/monitoring patterns, and guardrails.
- Partner with engineering, platform, DevOps, and operations teams to embed security into delivery pipelines and infrastructure‑as‑code practices.
- Support threat detection, incident response readiness, use‑case tuning, and post‑incident improvement activities.
- Contribute to security standards, policies, patterns, reusable accelerators, and client‑facing deliverables such as assessments, risk registers, and executive summaries.
Required Experience
- Cloud Security (preferably AWS) – securing core services, networking, identity, logging, encryption, and monitoring.
- Experience reviewing or implementing secure cloud architectures, landing zones, account/project structures, and preventative/detective controls.
- Knowledge of cloud‑native security services and best practices for workload, storage, network, and platform protection.
- Application / API Security – identifying and mitigating application and API security risks across the software delivery lifecycle.
- Understanding of secure design principles, common web/API vulnerabilities, authentication/authorization models, secrets management, and secure SDLC practices.
- SIEM Experience – log onboarding, correlation rule creation, alert triage, dashboarding, and use‑case tuning.
- Broad understanding of enterprise security domains: policy, governance, risk, compliance, awareness, third‑party risk, and operational security.
- Identity & Access Management (IAM) – hands‑on experience with RBAC, least privilege, privileged access, federation/SSO, MFA, and access governance.
- Data Protection – implementation or advice on data classification, encryption, key management, secrets handling, tokenisation/masking, backup security, and data lifecycle protection.
- Infrastructure Security – securing operating systems, virtual machines, containers/Kubernetes, networks, and platform services using hardening, segmentation, vulnerability management, and secure configuration practices.
- Threat Detection & Incident Response – engineering detection, triage, investigation support, response coordination, and lessons‑learned improvement.
- Infrastructure as Code (IaC) – reviews and embeds policy/compliance checks into delivery pipelines and repeatable platform provisioning.
- Strong Consulting Skills – stakeholder management, challenging assumptions, balancing risk, delivery timelines, business context, and technical constraints; written and verbal communication for workshops, assessments, reports, and executive briefings.
Core Skills & Competencies
- Cloud security architecture and control design.
- Security assessments, gap analysis, and remediation planning.
- Stakeholder engagement and client advisory.
- Security architecture documentation and reporting.
- Risk‑based decision making and prioritisation.
- Cross‑functional collaboration with engineering, operations, and leadership teams.
- Strong analytical, investigative, and problem‑solving capability.
Preferred Qualifications
- Experience working in consulting, professional services, or customer‑facing transformation programmes.
- Relevant certifications in cloud, security, architecture, or incident response.
- Exposure to regulated environments and security frameworks.
- Experience with DevSecOps, CI/CD security integration, and security automation.
Benefits
- Quarterly performance‑related profit share scheme.
- Career progression and mentorship through dedicated programmes.
- Flexible/remote working options.
- Pension, private healthcare cover, life assurance, financial advice, and employee discount scheme.
- Wellbeing programmes – gym discounts, bike‑to‑work, fitness classes, mindfulness workshops, and employee assistance programme.
- Generous holiday allowance and enhanced maternity/paternity leave.
- Educational assistance and incentives for certifications (e.g., AWS, Microsoft, Oracle, Red Hat).
- Reward schemes including annual excellence awards and recognition platform.
- Community initiatives supporting local fundraising and inclusion efforts.
EEO Statement
Version 1 is an equal opportunities employer. We are committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds, identities and lived experiences, and we value the different perspectives people bring, including those shaped by disability and neurodiversity.
#J-18808-Ljbffr…
