WithSecure delivers offensive-driven cyber security to defend organisations, society and people from real-world attacks and build resilience into their approach. Our people are a mix of technical and creative experts - diverse, talented, and passionate - working tirelessly to help us advance the industry with new ways of thinking. They lead their own development, in and out of the office.
We are recruiting for an experienced Security Consultant, with experience in architecture, design reviews, threat modelling and risk modelling. Ideally, with some hands-on technical pentesting experience too. This position is specifically for integration with one of WithSecure's strategic clients.
The job/the details
We need a Consultant who is comfortable in both technical and architectural conversations. You should have plenty of hands-on experience to draw on and should have strong technical fundamentals, including networking, infrastructure & applications - both on-premise and in the cloud (including SaaS). Experience with major cloud providers (preferably AWS) and SDLC toolsets is essential, and solid experience with infrastructure-as-code solutions is a benefit too. You will also ideally have strong hands-on security skills, from conducting pentests and security assessments. You'll be comfortable finding impactful vulnerabilities and explaining to clients how to fix them.
But you should also be familiar with the other side of the fence - with how solutions are designed, implemented and maintained throughout their lifecycle. Ideally, this experience will be from large enterprise clients (likely while working as a consultant for them) and you will be used to working with disparate, global teams, across both applications and infrastructure, quickly summarising risks, and thinking pragmatically about true business impact. Good communication skills are a must.
You will be working as part of a client's security team, and offering offensive security-minded thoughts and input on key design decisions. This will include areas such as:
You should be able to quickly understand industry-standard and client-specific design patterns across the range of topics above - such as using common libraries, known-secure configurations, etc. Where no such standards exist, you should be involved in helping create them - defining what good looks like.
For this specific client project, you will have an 80% utilisation target, meaning that 20% of your time will be spent on some of the following:
WithSecure's consultants are passionate about what they do. They have a passion for computers, hacking, security and most importantly, solving problems. If this wasn't your job, it would be your hobby. This passion is demonstrated in the technical excellence put into every project at WithSecure Consulting.
You're not going to be told what to do all the time - we will support your progression, but it will be up to you. With an understanding of what is important to the business and our client, you will be given the opportunity to determine how your time is best spent. We are an output-driven business, this is to say that your output is what is ultimately important; we don't micromanage.
You will be working with the industry's top consultants. They are there to support you, provided that you demonstrate that you are doing your best.
Communication skills are as important as your technical abilities. The ability to write excellent reports and documentation is a necessity, however you should also be able to summarise their contents effectively. In addition to written communication skills, you are expected to have good verbal communication skills.
You will have the ability to explain complex technical issues to a wide range of audiences which often include senior business stakeholders.
Consulting is hard work, and pressure is high. WithSecure has high standards and high expectations of consultants. We work with some of the biggest and most interesting businesses in the world. This inevitably results in often stressful but particularly exciting and rewarding work.
An ideal candidate will have:
We're always considering motivated, proactive, problem-solvers at any level. So if you're keen on cyber security and want to make a start in the industry, please feel free to also apply and we can consider you for an Associate Security Consultant position.
We are committed to creating a diverse and inclusive workplace that values and respects all people, regardless of their background, identity, or experience. We believe that diversity and inclusion are essential for our success as a company and for our customers' satisfaction. We encourage applications from people of all backgrounds, abilities, and perspectives.
If you need any accommodations during the application or interview process, please let us know.