Technical Security Consultant required to support the development and continuous improvement of a Secure Software Development Lifecycle (SDLC) capability. This is a technical assurance role combining Secure SDLC, DevSecOps, application security and architecture expertise to assess control effectiveness, tooling coverage and adoption across modern engineering environments.
Key Responsibilities
- Assess Secure SDLC controls across design, development, testing, release and operation.
- Review security architecture, tooling coverage, integration dependencies and control gaps.
- Assess capabilities including SAST, SCA, DAST, secrets scanning, IaC scanning, API security, threat modelling and CI/CD security.
- Map controls against frameworks including NIST SSDF, OWASP SAMM and OWASP DSOMM.
- Review security tooling and integrations across GitHub, GitLab, CI/CD and cloud environments.
- Conduct control-effectiveness assessments, evidence reviews and maturity/gap analysis.
- Facilitate workshops with engineering, security and product teams.
- Support KPI/KRI development, assurance reporting and remediation oversight.
Key Experience
- Strong Secure SDLC, DevSecOps or Application Security experience.
- Good understanding of security controls throughout the software development life cycle.
- Experience with security assurance, control frameworks, architecture or capability mapping.
- Knowledge of application security tooling such as GitHub Advanced Security, CodeQL, Dependabot, Fortify, Qualys or Checkov beneficial.
- Strong stakeholder management with the ability to challenge technical and engineering teams.
- Knowledge of vulnerability management, exception governance and remediation processes advantageous.
- SC clearance or ability to obtain SC clearance required.