Security & Resilience Senior Consultant

3 weeks ago


England, UK, United Kingdom Nationwide Building Society Part time

Nationwide is the world’s largest building society and it’s an exciting time to join us, as we evolve to a new future that sees us accelerate delivery of value to our 16.3 million Members and engage our 18,000 colleagues around new ways of working.


We are looking for a (Senior) Security Consultant (dependant on skills and experience) to work in our Security Consultancy team. This role sits within our Security & Resilience function where our stated mission is ensure that, ‘with our colleagues, we make sure services, money and data are available and secure at all times’.


At Nationwide we offer hybrid working wherever possible. More rewarding relationships are supported through our hybrid approach, bringing colleagues together across our UK wide estate, whilst also supporting generous access to home working. We value our time in the office to solve problems, to learn, and to feel connected.


For this job you'll spend at least two days per week, or if part time you'll spend 40% of your working time, at one of our offices. If your application is successful, your hiring manager will provide further details on how this works. You can also find out more about our approach to hybrid working here.


What you'll be doing

As a Security Consultant you will be accountable for ensuring that services and change initiatives in the business areas you are aligned to are delivered in a secure and compliant manner. You’ll be working in a matrix manner with our business, change and delivery teams, supporting everything from small technology changes to major transformation programmes, driving implementation of our Security and Resilience strategies and policies in a positive and pragmatic manner which enables our colleagues to deliver their business objectives. To do this, you will be:

  • Conducting security risk assessments and providing recommendations on appropriate controls to ensure services and systems operate within risk appetite;
  • Assessing the impact of change initiatives and issuing appropriate security requirements to ensure compliance with security policy and standards;
  • Advising on the implementation of security control requirements, ensuring the design and approach of these both achieve the desired security outcome and are operationally viable;
  • Supporting change initiatives in navigating and utilising our central security services, including security monitoring, penetration testing and access management;
  • Assuring that security control requirements are met, in conjunction with our Application Security Testing team, through the project lifecycle;
  • Acting as the initial point of contact for all security and resilience related questions, queries, challenges and escalations for your aligned areas;

You will need to build strong relationships with colleagues across multiple areas, working collaboratively and proactively, to ensure Security & Resilience is effectively embedded in all projects and programmes.


About you

As a Security Consultant you will be a subject matter expert for IT Security and Information Security, with developed people skills. As a minimum you’ll:

  • Have experience in Security Consultancy role, or a related discipline e.g. Security Governance Risk and Control or Operations;
  • Have a relevant professional qualification (or be working towards certification), such as Security+ / Network+ / CISM / CISSP.
  • Have a developed understanding of risk and control methodologies and experience of practical risk assessment (ideally but not essentially in a security environment);
  • Have knowledge and understanding of relevant industry standards, frameworks and best practice, e.g. ISO / NIST / COBIT / COSO;
  • Be a resilient and highly motivated self-starter, with demonstratable robust judgement, decision making and creative problem-solving ability;
  • Be able to understand and assess the security elements of technical designs / solutions and have a proven ability to constructively challenge to deliver better business and security outcomes;
  • Have the ability to communicate complex risks / issues to technical and non-technical stakeholders to influence critical business decisions.

It would be nice if you also had:

  • Previous experience in working in UK Financial Services or similar highly regulated industry;
  • Knowledge / experience of PCI-DSS, including PCI-P qualification;
  • Knowledge / experience of Data privacy and GDPR;
  • Knowledge / experience of Operational Resilience and Business Continuity, including new regulatory requirements;
  • Knowledge / experience of cloud security (AWS/Azure), e.g. web components integration, containerisation (such Docker, Kubernetes, OpenShift) and APIs;
  • Knowledge / experience of threat modelling and threat assessment;
  • Experience working in an Agile or DevSecOps methodology/tools e.g GIT, Maven/Gradle, Jenkins, Nexus, Terraform, Ansible.

Our Customer First behaviours are all about putting customers and members at the heart of how we work together. You can strengthen your application by showing the behaviours that resonate with you, and how you might have already demonstrated these.

  • Say it straight - This is about being honest and direct with good intent and saying what needs to be said in the room. It’s also about being clear, precise, and using language that we and, importantly, our customers and members can understand.
  • Push for better - This is about aiming high and constantly looking for better in how we work together and serve our customers and members.
  • Get it done - This is about prioritising what will have the greatest impact, being decisive and taking accountability for delivering on the end-to-end outcome.

We know applying for jobs can sometimes feel like you’re sending an application into a black hole. We review each application individually. So, it’s a good idea to call out your most relevant experience on your application to give yourself the best chance.


The extras you'll get

There are all sorts of employee benefits available at Nationwide, including:

  • A personal pension – if you put in 7% of your salary, we’ll top up by a further 16%
  • Up to 2 days of paid volunteering a year
  • Life assurance worth 8x your salary
  • A great selection of additional benefits through our salary sacrifice scheme
  • Gympass – Access to a range of free and paid options for health and wellness.
  • Access to an annual performance related bonus
  • Access to training to help you develop and progress your career
  • 25 days holiday pro rata


  • England,, UK, United Kingdom CornerStone - Risk, Cyber & Security Full time

    CornerStone is a leading independent Security Risk Consultancy, and we are now looking for a Technical Security Consultant to join our award-winning team in a UK-wide and Europe capacity. We are seeking an individual who enjoys working in a fast-paced, collaborative environment that is built upon innovation, teamwork, taking ownership, and supporting each...


  • England,, UK, United Kingdom Concept Full time

    Our client in the Fire & Security sector is expanding and urgently seeks a dynamic Security Consultant. This field-based role is crucial for driving sales and fostering client relationships within a defined geographical area.Company:Join one of the largest security companies in the UK, a global Group with 53,000 employees in nearly 2,800 locations worldwide....


  • England,, UK, United Kingdom Concept Full time

    Our client in the Fire & Security sector is expanding and urgently seeks a dynamic Security Consultant. This field-based role is crucial for driving sales and fostering client relationships within a defined geographical area.Company:Join one of the largest security companies in the UK, a global Group with 53,000 employees in nearly 2,800 locations worldwide....


  • England,, UK, United Kingdom Computacenter Full time

    About the teamAs a Senior DevSecOps Consultant, you will deliver post sales technical consultancy for our clients. This includes the implementation and configuration of complex, large scale deployment solutions and designing solutions for products within recognised area of expertise.What you’ll doProvide high level consultancy role within specialist area...


  • England,, UK, United Kingdom CornerStone - Risk, Cyber & Security Full time

    CornerStone is a leading independent Security Risk Consultancy, and we are now looking for a Security Project Manager with a security background and 5 years of experience to join our established award-winning team. We are seeking an individual who is looking to share their extensive skills and knowledge to support the team in a UK-wide and Europe capacity....


  • England,, UK, United Kingdom Experis UK Full time

    Cyber Security Consultant (SC Cleared)We are on the lookout for an SC Cleared Cyber Security Consultant to join our client who is a global tech giant with a variety of important customers, who are looking for a high-level Security Consultant to mitigate security issues. You will be identifying, analysing and managing complex security incidents in their...


  • England,, UK, United Kingdom Experis UK Full time

    Cyber Security Consultant (SC Cleared)We are on the lookout for an SC Cleared Cyber Security Consultant to join our client who is a global tech giant with a variety of important customers, who are looking for a high-level Security Consultant to mitigate security issues. You will be identifying, analysing and managing complex security incidents in their...


  • England,, UK, United Kingdom Synapri Full time

    SSPM Consultant - Inside IR35 Contract - Hybrid WorkingSynapri are currently seeking an experienced SSPM Consultant for a consultancy representing a leading client in the financial sector. This role will focus on assisting in the strategic design, implementation, and ongoing optimisation of Security Monitoring Project initiatives.This is a hybrid working,...


  • England,, UK, United Kingdom Nationwide Building Society Part time

    It's easy to misunderstand what Nationwide is like. Why? Because we're not like a bank. We're not like other financial services companies either. As a Senior Security Engineer here, you'll sit within CTO, assisting a wide range of delivery teams in engineering secure solutions and protecting our member's money and data.We believe security...


  • England,, UK, United Kingdom Computacenter Full time

    About the teamAs a CNAP Senior Consultant, you will deliver post sales technical consultancy for our clients. This includes the implementation and configuration of complex, large scale deployment solutions and designing solutions for products within recognised area of expertise.What you’ll doProvide high level consultancy role within specialist area to...


  • England,, UK, United Kingdom Computacenter Full time

    Life on the teamWe are seeking a highly skilled and motivated Security and Backup Consultant to join our Data & AI Consultancy Practice within Computacenter. The role will primarily be based remotely but may involve UK wide travel.The successful candidate will report directly to the Practice Leader, joining an already healthy sized team, but due to pipeline...

  • Security Consultant

    12 hours ago


    England,, UK, United Kingdom Computer Network Defence Ltd Full time

    Role: Security Consultant (Penetration Testing) Type: PermanentLocation: Remote with regular travel (c50% travel)Clearance: eligible for SCHow about an opportunity to work with a company that genuinely punches above it’s weight? Feel like it’d be a good move to work with a company that does work to make a big difference? Tired of the endless assignment...


  • England, London, UK, United Kingdom Jameson Legal. Full time

    Senior Solution Consultant, US/UKA leading, global software provider is looking to hire a senior solution consultant on a permanent basis. This role can be based in the US or UK and the main purpose will be to drive prospect engagements and be accountable for all product and technical evaluations within a sales territory.Main Responsibilities:Shaping and...


  • England,, UK, United Kingdom Tria Full time

    Senior IT Security AnalystUp to £60,000Hybrid – 2 days per week at either the London, Weymouth, or Newcastle officesWe are representing a leading B2C retailer who are in the process of modernising their technology estate, with significant investment in IT.As the Senior IT Security Analyst, you will report to the Head of Information Security, whilst...


  • England,, UK, United Kingdom TRIA Full time

    Senior IT Security AnalystUp to £60,000Hybrid – 2 days per week at either the London, Weymouth, or Newcastle officesWe are representing a leading B2C retailer who are in the process of modernising their technology estate, with significant investment in IT.As the Senior IT Security Analyst, you will report to the Head of Information Security, whilst...


  • England,, UK, United Kingdom GIOS Technology Full time

    We are Hiring for Telecom Cloud Security (Zscaler / ZTNA) Technical Delivery / Security Policy / ConsultantLocation : Hybrid -across multiple locationsWorks with the Lead Solution Architect to guarantee all functional and non-functional requirements are addressed in the Zscaler implementation.Collaborates with the Enterprise Architect to ensure the design...

  • Senior Consultant

    3 weeks ago


    England,, UK, United Kingdom Stealth iT Recruitment Full time

    Location: London / Manchester / Glasgow (hybrid working arrangements, typically 2 days per week in the office).Employment Type: Permanent.Salary: up to £70,000 dependent on experience, plus bonus and other benefits.The Opportunity:You'll be joining the Analytics and AI Advisory team within a leading consultancy. In this role, you'll be collaborating...


  • England,, UK, United Kingdom Wave Talent Full time

    AppSec Security EngineerLocation: Remote (Europe-based)Role: Senior Application Security Engineer (AppSec)Up to €130K Plus Equity Options (At a company that was valued at over a billion last year? Yes please!)About Us: Join our client's dynamic Security Team as a crucial member of their Application Security (AppSec) team.A B2B AI company That have...


  • England,, UK, United Kingdom Russell Tobin Full time

    FULLY REMOTE - UP TO £80,000 PLUS BONUSI have partnered with a leading Professional Services business in finding them an experienced Senior Pensions Consultant.This role will be fully remote.Job Description:What will you deliver?Develop excellent relationships with client portfolio and understand their needs and objectivesMakes a significant personal...


  • England,, UK, United Kingdom Russell Tobin Full time

    FULLY REMOTE - UP TO £80,000 PLUS BONUSI have partnered with a leading Professional Services business in finding them an experienced Senior Pensions Consultant.This role will be fully remote.Job Description:What will you deliver?Develop excellent relationships with client portfolio and understand their needs and objectivesMakes a significant personal...