Rodeo
Get started

HCLTech

Cyber Security Specialist – Security Connector

London
Posted about 14 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Role Overview

As a Cyber Security Specialist – Security Connector, you will operate as a critical strategic liaison (the "Connector") bridging the gap between core cybersecurity engineering teams, enterprise governance, and business lines within the banking ecosystem. You will be responsible for translating high-level enterprise security standards into actionable implementation patterns for cutting-edge architectures like cloud environments, microservices, and AI integrations.

This role ensures that fast-moving product applications remain compliant with UK financial regulations while maintaining a resilient, proactive stance against emerging threat vectors.

Location: London, UK
Engagement Type: Contract (Inside IR35) / Permanent

Primary Roles & Responsibilities

Security Architecture Liaison & Enablement ("The Connector")

  • Act as the dedicated security consultant to business product lines, application developers, and DevOps teams, accelerating safe project delivery.
  • Embed enterprise security domains—including Endpoints, Network security, Cryptography, and Identity & Access Management (IAM)—directly into emerging engineering streams.
  • Guide technical squads on implementing secure contemporary architectures, safely handling RESTful APIs and containerised microservices.

Threat Modelling & Proactive Risk Management

  • Maintain an up-to-date stance on the evolving financial service threat landscape.
  • Lead collaborative Threat Modelling workshops using structured frameworks such as STRIDE and MITRE ATT&CK to systematically uncover architectural vulnerabilities before production deployment.
  • Formulate clear risk-mitigation strategies that balance agility with strict data-integrity requirements.

Strategic Infrastructure & Enterprise Scaling

  • Assure secure engineering standards during the migration and scaling of bank platforms across any major Public Cloud environments (AWS, Azure, or GCP).
  • Design and implement technical guardrails that enforce "Secure-by-Design" principles automatically within cloud infrastructure pipelines (Infrastructure as Code).

Regulatory & Compliance Frameworks

A core focus of this role is embedding security controls that ensure absolute alignment with UK and international financial services regulations. You will design architectures that satisfy:

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

  • DORA (Digital Operational Resilience Act): Ensure all applications and third-party integrations support rigorous ICT risk management, incident reporting, and operational resilience testing capabilities.
  • FCA & PRA Guidelines: Align system architectures with the Financial Conduct Authority and Prudential Regulation Authority handbooks on operational resilience (specifically SYSC 15.1 and FG16/5 for cloud outsourcing).
  • UK GDPR & Data Privacy: Oversee the strict isolation and encryption of Personally Identifiable Information (PII) and financial records at rest and in transit.
  • Industry Standards: Map security templates against established global models including PCI DSS (v4.0), ISO 27001, NIST SP 800-53, OWASP Top 10, and COBIT.

Technical Stack & Ecosystem Tooling

The candidate will actively utilize, integrate, or govern the following technologies across the secure software development lifecycle (SSDLC):

  • Cloud Infrastructure (Any Platform): AWS (IAM, CloudTrail, GuardDuty), Microsoft Azure (Microsoft Defender for Cloud, Entra ID), or Google Cloud Platform (GCP Security Command Center).
  • Infrastructure as Code (IaC) & Security: Terraform, Ansible, or CloudFormation alongside static analysis tools like Checkov, TFLint, or Terrascan.
  • Containerization & Orchestration: Docker and Kubernetes (K8s) security solutions (e.g., Aqua Security, Prisma Cloud, or Sysdig).
  • Application Security (SAST/DAST/SCA): Integrations with automated vulnerability platforms like Snyk, SonarQube, Veracode, or Checkmarx.
  • Identity & Access Management (IAM): OAuth 2.0, OIDC, SAML, and enterprise solutions like Ping Identity, Okta, or CyberArk.
  • CI/CD Automation & Observability: Jenkins, GitHub Actions, or GitLab CI integrated with logging clusters like Splunk, Datadog, or ELK Stack.

Secondary Roles & Responsibilities

Operational Research & Incident Advisory

  • Evaluate threat intelligence data and primary risk trends to continuously recommend security enhancements to the platform's security stack.
  • Support incident readiness functions by acting as the domain subject matter expert (SME) during technical forensic review or security post-mortems.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Stakeholder Management & Documentation

  • Develop and deliver transparent security playbooks and design blueprints that reduce security friction for technical teams.
  • Translate complex risk items into plain, metric-backed summaries for non-technical senior executives and client-facing business partners.

Key Skills & Qualifications

Experience Requirements

  • 5+ years of dedicated professional experience in Cyber Security Engineering, Information Security Architecture, or DevSecOps contexts.
  • Proven track record of working within the banking or highly-regulated financial services sector in the UK.
  • Demonstrable history of driving secure engineering deliverables across multi-functional development squads.

Technical Knowledge

  • Enterprise Tech & Architectures: Deep technical familiarity with cloud security fundamentals, container security, and API gateway design paradigms.
  • Core Security Expertise: Demonstrable history managing core enterprise domains (specifically public-key cryptography, TLS configurations, network zoning, and microsegmentation).
  • Framework Mastery: Confident hands-on experience utilizing STRIDE or MITRE ATT&CK concepts in real-world software lifecycles.

Professional Certifications

  • Security Management: At least one active certification such as CISSP, CISM, CCSP, or equivalent baseline credential.
  • Technical Domains: Valued additions include technical certifications like CEH, OSCP, or cloud-specific security credentials (e.g., AWS Certified Security, Microsoft Certified: Azure Security Engineer).

Person Specification

  • Exceptional client-facing, communication, and cross-functional negotiation skills.
  • Proven capability to build consensus and drive resolution when engineering speed conflicts with security policy.
  • High professional integrity, adaptability, and resilience inside highly regulated environments.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this