About the Role
This is an exciting opportunity to join a leading global Tier 1 financial institution undergoing a major transformation of its technology landscape. We are seeking experienced Information Security Review & Threat Modelling Engineers to join a high-performing cyber security team. The successful candidate will be responsible for conducting security reviews of infrastructure products before production deployment, ensuring compliance with enterprise security standards, identifying security risks, and recommending remediation activities.
Responsibilities
- Perform end-to-end security reviews of infrastructure products and validate compliance with enterprise information security standards.
- Work closely with engineering teams and third-party vendors to obtain information required for security assessments.
- Review technical documentation and perform hands-on security testing of infrastructure products.
- Identify security vulnerabilities, compliance gaps and non-conformities.
- Produce detailed security findings and recommend remediation or risk mitigation strategies.
- Support Information Security teams throughout remediation activities.
- Design and review secure technical architectures.
- Embed quality control measures across security review processes.
- Produce high-quality technical documentation and maintain audit-ready evidence.
- Manage stakeholder expectations and communicate findings effectively.
- Escalate risks and issues appropriately.
- Support internal and external security audits.
Requirements
- Minimum 6 years’ IT experience, including at least 4 years in Cyber Security/Information Security across cloud and on-premises environments.
- 3-5 years’ experience within Information Security or Information Technology.
- Strong experience reviewing infrastructure security.
- Hands-on cloud security experience across AWS and/or GCP.
- Demonstrated expertise in Threat Modelling methodologies such as STRIDE, PASTA or MITRE ATT&CK/ATLAS.
- Strong understanding of authentication, authorisation, encryption, logging & monitoring, infrastructure security and network segmentation.
- Ability to design and review secure technical architectures.
- Strong understanding of Infrastructure as Code (Terraform and/or CloudFormation).
- Experience with Software Development Lifecycle (SDLC) and CI/CD pipelines.
- Hands-on Python scripting skills with the ability to read, write and analyse scripts.
- Experience across multiple technology domains.
- Security testing experience is advantageous.
Skills
- AWS
- GCP
- STRIDE
- PASTA
- MITRE ATT&CK
- MITRE ATLAS
- Terraform
- CloudFormation
- Python
Location
- London
- Belfast
Work Type
- Hybrid
- Contract
Experience Level
- 6 years IT experience
- 4 years Cyber Security/Information Security experience
- 3-5 years Information Security or Information Technology experience
Education Level
- Associate or Professional AWS or GCP Cloud Certification
- Associate or Professional Cyber Security Certification
- Degree in Computer Science, Cyber Security or related discipline preferred
Salary/Compensations
- £90,206 + £10,887 holiday pay
About the Company
- Leading global Tier 1 financial institution undergoing a major transformation of its technology landscape.
