Enable job alerts via email!

Principal Security Consultant

Marks & Spencer Plc

London

On-site

GBP 70,000 - 110,000

16 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is on the lookout for a Principal Security Consultant to spearhead security initiatives for their web platforms within an Azure cloud environment. This pivotal role involves crafting and executing security strategies, embedding security into the engineering lifecycle, and ensuring compliance with industry standards. The ideal candidate will have a robust understanding of web application security, experience with Akamai solutions, and a passion for driving security best practices across teams. Join a forward-thinking organization where your expertise will play a crucial role in safeguarding digital assets and enhancing security posture.

Qualifications

  • Expertise in securing web applications and APIs, with a focus on industry standards.
  • Strong knowledge of Azure security and experience with Akamai security solutions.

Responsibilities

  • Lead security strategy for web platforms, ensuring compliance with security frameworks.
  • Implement secure-by-design principles and manage Akamai security solutions.

Skills

Web Application Security

API Security

Akamai Security Solutions

Azure Security

DevSecOps Practices

Container Security

Threat Modeling

Stakeholder Engagement

Education

CISSP Certification

CISM Certification

AZ-500 Certification

Tools

Azure Sentinel

GitHub Actions

Terraform

Docker

Kubernetes

Job description

Summary

We are seeking a highly skilled Principal Security Consultant to lead the security strategy, implementation, and assessment of our web platforms in an Azure cloud environment. This role will be instrumental in securing web applications, APIs, cloud workloads, and CI/CD pipelines while ensuring alignment with industry best practices and compliance standards. The successful candidate will work closely with development, DevOps, and architecture teams to embed security within the engineering lifecycle.
Additionally, this role requires expertise in Akamai security solutions, ensuring that edge security, WAF policies, bot mitigation, and CDN configurations align with security best practices.

What you'll do

  • Lead and define security strategy for web platforms in Azure and Akamai environments, ensuring alignment with security frameworks (OWASP, CIS) and developing policies and guidelines.
  • Implement secure-by-design principles, lead threat modeling, and drive security testing (SAST, DAST, IaC) across the SDLC, while securing CI/CD pipelines and authentication mechanisms (Azure AD, OAuth).
  • Manage and optimize Akamai security solutions (WAF, Bot Manager, ASE), implementing zero-trust principles and tuning WAF rules to minimize false positives.
  • Enforce security controls in Azure (Defender for Cloud, NSGs) and guide secure IaC practices, container security, and monitoring using Azure Sentinel and SIEM tools.
  • Lead incident response, security investigations, and compliance with standards (GDPR, PCI-DSS, SOC 2), while mentoring teams and aligning security priorities with business goals.

Who you are

  • Strong expertise in securing web applications (OWASP Top 10, API security, web frameworks) and experience with Akamai security solutions (Kona Site Defender, Bot Manager, Edge DNS).
  • Deep knowledge of Azure security (Azure AD, Key Vault, Defender for Cloud, WAFs) and experience securing API gateways, microservices, and serverless functions (Azure Functions, API Management).
  • Proficiency in DevSecOps practices, tools (GitHub Actions), and IaC security (Terraform, ARM templates), with hands-on experience in security scanning (SAST, DAST, SCA, IAC).
  • Expertise in container security (Docker, Kubernetes, AKS), threat modeling (Microsoft Threat Modeling Tool), and understanding Zero Trust architecture and IAM best practices.
  • Strong stakeholder engagement skills, the ability to communicate security risks to technical and non-technical audiences, and experience leading security initiatives.
  • Preferred: Certifications (CISSP, CISM, AZ-500), experience with SIEM tools (Azure Sentinel, Splunk), and familiarity with secure coding practices and penetration testing.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Principal Security Consultant

Only for registered members

London

Hybrid

GBP 60,000 - 100,000

Today
Be an early applicant

Principal Security Consultant

Only for registered members

London

Hybrid

GBP 60,000 - 100,000

5 days ago
Be an early applicant

Principal Security Consultant

Only for registered members

London

Hybrid

GBP 50,000 - 90,000

19 days ago

Principal Security Consultant

Only for registered members

London

Hybrid

GBP 60,000 - 100,000

20 days ago

Principal Security Consultant

Only for registered members

London

Hybrid

GBP 60,000 - 100,000

21 days ago

Global Security and Business Continuity Manager

Only for registered members

Greater London

Remote

GBP 50,000 - 90,000

5 days ago
Be an early applicant

Security Assurance Coordinator

Only for registered members

London

Remote

GBP 80,000 - 100,000

9 days ago

Principal Nuclear Safety Consultant

Only for registered members

Greater London

Hybrid

GBP 60,000 - 75,000

3 days ago
Be an early applicant

Principal Safety Engineer

Only for registered members

London

Hybrid

GBP 95,000 - 95,000

3 days ago
Be an early applicant