Job Description
In this role, you will:
- Design and implement security controls across the IDAM 2.0 platform.
- Embed Secure by Design principles throughout solution delivery.
- Implement and maintain Zero Trust security controls.
- Configure and maintain authentication and authorisation security mechanisms.
- Implement secure service-to-service communication using mutual TLS (mTLS).
- Support Workload Identity, Human Identity and Agent Identity security controls.
- Implement and maintain Policy-as-Code solutions using OPA and related technologies.
- Integrate secrets management, PKI and certificate life cycle services.
- Support cryptographic key management and certificate rotation processes.
- Perform security reviews of solution designs, infrastructure and application code.
- Conduct threat modelling and security risk assessments.
- Identify, assess and remediate security vulnerabilities.
- Support vulnerability management and security patching activities.
- Develop and maintain security baselines, standards and hardening guides.
- Implement cloud security controls for GCP resources and Kubernetes platforms.
- Configure security monitoring, logging, alerting and audit capabilities.
- Support identity governance, privileged access and least privilege implementation.
- Assist with penetration testing and remediation activities.
- Support security compliance with financial services regulatory requirements.
- Collaborate with Security Operations and Incident Response teams during security events.
- Support security assurance for third-party integrations and supplier solutions.
- Contribute to DevSecOps tooling and automated security testing.
- Promote security awareness and engineering best practice across delivery teams.
- Produce security documentation, implementation guides and operational Procedures.
Key Skills & Experience
Essential Skills
- Information Security Engineering
- Identity and Access Management (IAM)
- Zero Trust Architecture
- Authentication and Authorisation
- Workload Identity
- Agent Identity
- PKI and Certificate Management
- Secrets Management
- Cryptography
- Cloud Security (GCP)
- Kubernetes Security
- Service Mesh Security
- API Security
- Policy-as-Code (OPA)