What’s in it for you?
You will be joining the company at Daintta “Consultant” grade. In addition to being rewarded fairly for your contribution to the business, you get to work in a dynamic organisation that is agile and responsive. A business that is growing fast and where you get to drive and shape the future. A place where you are respected by everyone and your voice is important. Somewhere where you can be innovative and creative. A place where you have the opportunity to learn about all aspects of business from marketing to sales, to delivery and business operations.
Key Responsibilities
- Developing, justifying and implementing organisational and system security management strategies that address risk and control requirements, ensuring a UK Gov’t Secure by Design approach
- Selecting, understanding and adapting/adopting appropriate security control frameworks
- Identifying security risk business and stakeholder security requirements and proposing proportionate assessment, design and implementation of secure systems to meet the requirements
- Performing threat modelling and risk assessments to develop a holistic picture of threat
- Ensuring security principles are applied during solution planning, design, test, deployment and operations to reduce risk and ensure compliance, including:
- Developing or supporting the development of secure solution designs to mitigate the risks posed by new technologies and business practices
- Supporting third-party and supply chain security assessments, including vendor due diligence, secure procurement, software supply chain risk and ongoing assurance of externally sourced technology
- Applying identity-led and zero trust security principles, including strong authentication, least privilege, contextual access control and segmentation of services, users and devices
- Defining and reviewing security assurance activities, including design assurance, verification, validation, vulnerability assessment, penetration testing inputs and interpretation of assurance evidence
- Developing and communicating corporate and domain information security policy, standards, guidelines and design guardrails
- Identifying and monitoring environmental and market trends and proactively assessing impact on business strategies, benefits and risks
- Assessing your client’s needs, understanding how their needs may differ from their wants, and appropriately managing stakeholder relationships
- Delivering high-quality work to agreed milestones, and adapting quickly to unfamiliar client environments.
- Supporting the technical aspects of client engagements, including pitches and presentations
- Helping to support & grow Daintta by actively inputting into the company strategy and helping to shape our future
- Representing us and our core values: Transparency, fairness and being daring.
Skills/Knowledge
- You have relevant and recent practical experience in cyber security engineering, architecture, design or technical assurance, and can apply that knowledge credibly in client-facing consulting engagements
- You have worked in technical client deliveries across a range of cyber security related projects
- You understand technical controls and business risk
- You can demonstrate working-level experience in one or more of the following domains: Security Architecture; Security Operations; Identity & Access Management; Cloud, Infrastructure and Platform Security; Network and Connectivity Security; Application Security and DevSecOps; Data Security and Privacy; Governance, Risk & Compliance;
- You have experience embedding security into agile, DevSecOps and iterative delivery models, including design reviews, security requirements management and pragmatic risk treatment in fast-moving projects
- You have experience working with security control standards and frameworks e.g. ISO27001, NIST, NCSC guidance and NCSC CAF, JSP 440 or others
- You have demonstrable continuous personal development, supported by relevant certifications and accreditations
- You have good interpersonal skills at both the business and technical level
- You have UK security clearance at SC or above or are eligible and willing to go through clearance
- You have experience working with security controls within cloud-based infrastructure (e.g Azure, AWS, GCP). This may include design, configuration, or protective monitoring.
- Knowledge of digital identity and authentication systems
- Experience applying data classification, handling requirements, data residency and sovereignty considerations to solution design, particularly where sensitive, regulated or operationally critical data is involved
- Understanding of security risks and controls for AI-enabled systems, including data governance, access control, prompt injection, model misuse, third-party AI services and monitoring of sensitive data exposure
- Application and governance of fine‑grained access control and permissions
- Experience in UK Gov’t public sector or defence
Location?
Hybrid, with 2-3 days working from Daintta office or on client site as required.
Time Off:
- 25 days annual leave, plus bank holidays
- Up to 5 days annual training leave with a dedicated training budget
- Up to 3 days annual volunteering leave – give back to the community
- Competitive maternity, paternity, shared parental leave & compassionate leave
- Employee Assistance Programme – 24/7 support services
- £2,000 Flex Cash Allowance, paid pro-rata over the year
- Discretionary company awards and bonuses, based on performance and company targets
Professional Development
- Up to £1,000 annual training budget (access to additional training and development budget via business case)
- Up to 5 days annual training leave
- 1 professional membership paid annually
- Up to £200 of additional IT budget for new joiners
- Free breakfast every Tuesday in the London office
- Fortnightly drinks – in London
- Regular social events, quizzes, and guest workshops
- Huckletree perks – including gym and restaurant discounts
- Employee referral programme
- Monthly breakfast club in our Cheltenham office
Security Information
Due to clients’ requirements, all applications are strictly subject to security clearance requirements relevant to the role.
#J-18808-Ljbffr…
