TQUSI0928_5945 - Security Professional – FEC Workflow Management (FEC Tech)

Job Type: Contract

Work Mode: Hybrid (3 Days from office)

About the Role


We are looking for a Security Professional to serve as the security focal point within the FEC Workflow Management Area. You will drive a secure-by-design culture, ensuring security, resilience, fraud prevention, and compliance are embedded throughout the software delivery lifecycle.

Working closely with Engineering, Architecture, Risk, Security, and Product teams, you will help design, build, and operate secure solutions that meet internal standards and external regulatory requirements.


Key Responsibilities


Security Leadership

  • Act as the primary security contact for the FEC Workflow Management Area.
  • Promote security awareness, ownership, and secure-by-design practices.
  • Represent the area in security forums, governance bodies, and Security Champion communities.
  • Advise engineering, architecture, risk, and business stakeholders on security matters.

Secure Solution Delivery

  • Embed security throughout the SDLC, from requirements to production.
  • Define security requirements and acceptance criteria.
  • Facilitate threat modelling and architecture reviews.
  • Promote secure coding practices and security-focused code reviews.
  • Integrate security testing (SAST, DAST, SCA) into CI/CD pipelines.
  • Ensure effective monitoring, logging, resilience, and disaster recovery controls.

Risk, Vulnerability & Incident Management

  • Lead vulnerability reviews and remediation activities.
  • Support penetration testing and security assessments.
  • Investigate and respond to security incidents and fraud-related threats.
  • Drive reduction of recurring vulnerabilities and technical security debt.

Governance, Compliance & Reporting

  • Ensure compliance with internal policies and external regulations.
  • Support audits, risk assessments, and control reviews.
  • Maintain security documentation and evidence.
  • Track and report security posture, KPIs, risks, and remediation progress.

Security Enablement

  • Deliver training, workshops, and coaching on secure development practices.
  • Share lessons learned and promote continuous security improvement.
  • Support adoption of CISO, Stable & Secure by Design, and DevSecOps practices.

What You'll Bring


Experience


Essential

  • 3-5 years' experience in Cyber Security, Security Engineering, DevOps, Software Engineering, or IT Risk Management.
  • Experience in Agile and DevOps environments.
  • Strong stakeholder management and cross-functional collaboration skills.
  • Experience with vulnerability management and security controls.

Preferred

  • Banking, financial services, fraud prevention, sanctions, or other regulated environments.
  • Cloud security experience (Microsoft Azure preferred).
  • DevSecOps, penetration testing, audit, and security assessment experience.
  • Experience with Pega and/or Pega Cloud security.

Education & Certifications

  • Bachelor's degree in Computer Science, Cyber Security, Information Security, IT, or Engineering (or equivalent experience).

Preferred Certifications

  • Security+, AZ-900, SC-900, PenTest+, GISF
  • CISSP, CISM, CEH, CCSP, Microsoft Security Certifications, GIAC

Technical Knowledge

  • Secure SDLC / DevSecOps
  • OWASP Top 10 & Threat Modelling
  • Identity & Access Management (IAM)
  • Authentication, Authorisation, Encryption & Key Management
  • Vulnerability Management & Security Monitoring
  • Azure Cloud Security
  • Zero Trust & Defence-in-Depth
  • Network Security & Security Automation
  • Cloud Architecture & Security and SaaS Solutions
  • Pega / Pega Cloud knowledge is a plus
  • Operational Resilience 


Want To
WORK FOR YOU?

GET THE QUOTE

Want To
WORK WITH US?

CAREER