Cyber Security Assurance
A leading organization within the FinTech and digital financial services sector is looking for an experienced Senior Specialist – Cyber Security Assurance to strengthen its security assurance and offensive security capabilities.
This is an excellent opportunity for a highly technical cyber security professional with strong penetration testing, ethical hacking, security architecture, threat modelling, and security-by-design experience.
The successful candidate will work closely with technology and business teams to identify vulnerabilities, assess security risks, and ensure that security and privacy requirements are embedded throughout the technology lifecycle.
Key Responsibilities
- Manage and oversee Security and Privacy by Design assurance processes across technology initiatives.
- Ensure projects incorporate security and privacy principles from design through implementation and delivery.
- Conduct internal and external penetration testing across infrastructure, networks, web applications, APIs, and other technology environments.
- Assess new and existing systems, products, and services against security policies, industry standards, and recognised best practices.
- Perform controlled exploitation of identified vulnerabilities to determine potential business and technical impact.
- Execute both automated and manual security testing across a range of attack vectors.
- Conduct threat modelling and security risk assessments during the design and development lifecycle.
- Review technology projects and provide security assurance to ensure risks are identified and mitigated at an early stage.
- Ensure solutions meet defined security baselines before implementation and production deployment.
- Contribute to the architecture and design of secure, scalable, and resilient cyber security solutions.
- Collaborate with technology and engineering teams to ensure secure integration of systems, platforms, and services.
- Identify security weaknesses and provide practical recommendations for remediation.
- Stay informed about emerging threats, attack techniques, vulnerabilities, and defensive technologies.
- Research and evaluate innovative cyber security technologies and methodologies.
- Produce clear and detailed technical reports and communicate security findings to both technical and non-technical stakeholders.
- Contribute to knowledge sharing, mentoring, and continuous improvement within the cyber security function.
Requirements
Experience
- Minimum 5 years' experience in penetration testing, ethical hacking, offensive security, or a closely related cyber security discipline.
- Strong hands-on experience conducting security assessments across complex technology environments.
- Experience with security assurance and Security-by-Design principles.
- Practical experience identifying, exploiting, assessing, and remediating vulnerabilities.
Certifications
One or more of the following certifications would be highly advantageous:
- OSCP
- CEH
- CISSP
- CISA
Technical Skills
Strong knowledge and practical experience in:
- Penetration testing and ethical hacking methodologies.
- Kali Linux and offensive security tooling.
- Burp Suite, Metasploit, Nessus, and similar security testing tools.
- Network and infrastructure security.
- Web application and API security.
- Cloud security.
- Mobile application security.
- Threat modelling and security risk assessment.
- Secure architecture and security-by-design principles.
- TCP/IP, DNS, HTTP/S, SSL/TLS, and common network protocols.
- Common application and infrastructure vulnerabilities, including SQL injection, XSS, CSRF, buffer overflows, and related attack techniques.
- Scripting or programming using languages such as Python, Bash, Ruby, PowerShell, or JavaScript.
Key Competencies
- Strong analytical and problem-solving abilities.
- Excellent technical investigation skills.
- Methodical and detail-oriented approach to security testing.
- Strong written and verbal communication skills.
- Ability to translate complex technical vulnerabilities into clear business risks and recommendations.
- Strong report-writing and presentation capabilities.
- Ability to collaborate effectively with technical and non-technical stakeholders.
- Passion for continuous learning and staying ahead of emerging cyber threats.
Why This Opportunity?
This role offers the opportunity to work at the intersection of offensive security, cyber assurance, security architecture, and technology risk within a fast-paced digital environment.
You will have the opportunity to influence how security is embedded into technology solutions from the earliest stages while helping strengthen the organisation's overall cyber resilience.