TRCI-26-05289
Security Architecture Liaison / DevSecOps Security Consultant (Banking, Cloud & Containers)
Contract security consultant to partner with product lines, application developers, and DevOps teams in a UK banking/regulatory environment. The role focuses on embedding enterprise security domains (endpoints, network, cryptography, IAM) into modern engineering streams, running threat modelling (STRIDE/MITRE ATT&CK), and implementing secure-by-design guardrails for cloud migrations using IaC. Strong hands-on knowledge across cloud security (AWS/Azure/GCP), containerized microservices and REST APIs, SSDLC tooling (SAST/DAST/SCA), and compliance mapping to DORA, FCA/PRA, UK GDPR, PCI DSS, ISO 27001, NIST, OWASP, and COBIT is required, along with at least one active security certification (e.g., CISSP/CISM/CCSP).
Position summary
- Location
- United Kingdom
- Workplace
- Hybrid
- Employment
- Contract
- Experience
- Minimum 5 years and Maximum 7 years
Role overview
Why This Role Matters.
Contract security consultant to partner with product lines, application developers, and DevOps teams in a UK banking/regulatory environment. The role focuses on embedding enterprise security domains (endpoints, network, cryptography, IAM) into modern engineering streams, running threat modelling (STRIDE/MITRE ATT&CK), and implementing secure-by-design guardrails for cloud migrations using IaC. Strong hands-on knowledge across cloud security (AWS/Azure/GCP), containerized microservices and REST APIs, SSDLC tooling (SAST/DAST/SCA), and compliance mapping to DORA, FCA/PRA, UK GDPR, PCI DSS, ISO 27001, NIST, OWASP, and COBIT is required, along with at least one active security certification (e.g., CISSP/CISM/CCSP).
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Embed enterprise security domains —including Endpoints, Network security, Cryptography, and Identity & Access Management (IAM)—directly into emerging engineering streams.
Guide technical squads on implementing secure contemporary architectures, safely handling RESTful APIs and containerized microservices.
Maintain an up-to-date stance on the evolving financial service threat landscape.
Lead collaborative Threat Modelling workshops using structured frameworks such as STRIDE and MITRE ATT&CK to systematically uncover architectural vulnerabilities before production deployment.
Formulate clear risk-mitigation strategies that balance agility with strict data-integrity requirements.
Assure secure engineering standards during the migration and scaling of bank platforms across any major Public Cloud environments (AWS, Azure, or GCP).
Design and implement technical guardrails that enforce "Secure-by-Design" principles automatically within cloud infrastructure pipelines (Infrastructure as Code).
DORA (Digital Operational Resilience Act): Ensure all applications and third-party integrations support rigorous ICT risk management, incident reporting, and operational resilience testing capabilities.
FCA & PRA Guidelines: Align system architectures with the Financial Conduct Authority and Prudential Regulation Authority handbooks on operational resilience (specifically SYSC 15.1 and FG16/5 for cloud outsourcing).
UK GDPR & Data Privacy: Oversee the strict isolation and encryption of Personally Identifiable Information (PII) and financial records at rest and in transit.
Industry Standards: Map security templates against established global models including PCI DSS (v4.0), ISO 27001, NIST SP 800-53, OWASP Top 10, and COBIT.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
AWS
AWS IAM
CloudTrail
GuardDuty
Azure
Microsoft Defender for Cloud
Entra ID
GCP
Security Command Center
Terraform
Ansible
CloudFormation
Checkov
TFLint
Terrascan
Docker
Kubernetes
K8s security
Aqua Security
Prisma Cloud
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
5+ years in cyber security engineering, information security architecture, or DevSecOps
Experience in UK banking or highly regulated financial services
Security architecture consulting/liaison with product, engineering, and DevOps teams
Threat modelling workshops using STRIDE and/or MITRE ATT&CK
Cloud security fundamentals in at least one major cloud (AWS or Azure or GCP)
Secure-by-design guardrails in cloud infrastructure pipelines (IaC)
Infrastructure as Code security (e.g., Terraform/CloudFormation/Ansible plus scanning)
Container security for Docker and Kubernetes (K8s)
Securing RESTful APIs and microservices architectures
Identity & Access Management (IAM) including OAuth 2.0, OIDC, SAML
Cryptography fundamentals: PKI/public-key cryptography and TLS configuration
Network security concepts: zoning and microsegmentation
Regulatory/compliance alignment: DORA, FCA/PRA operational resilience, UK GDPR, and mapping to standards (PCI DSS v4.0, ISO 27001, NIST SP 800-53, OWASP Top 10, COBIT)
At least one active certification: CISSP or CISM or CCSP (or equivalent)
Preferred
Nice to Have
Cloud-native security services (AWS CloudTrail/GuardDuty/IAM; Azure Defender for Cloud/Entra ID; GCP Security Command Center)
IaC static analysis tools (Checkov, TFLint, Terrascan)
Container security platforms (Aqua Security, Prisma Cloud, Sysdig)
AppSec tooling integrations (Snyk, SonarQube, Veracode, Checkmarx)
CI/CD tooling (Jenkins, GitHub Actions, GitLab CI)
Observability/logging platforms (Splunk, Datadog, ELK Stack)
Incident readiness support, forensics/post-mortems as SME
Threat intelligence evaluation and security enhancement recommendations
Additional certifications (CEH, OSCP, AWS Certified Security, Microsoft Certified: Azure Security Engineer)
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Security Architecture Liaison / DevSecOps Security Consultant (Banking, Cloud & Containers)
One page, about two minutes. We only ask for what we actually need to have a first conversation.