
Platform Consultant, Multiple Levels
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in United Kingdom.
• Act as a reliable security consultant for engineering teams regarding secure architecture, platform design, and threat modeling.
• Lead and guide threat modeling sessions across various applications, platforms, and business areas.
• Integrate secure-by-design principles throughout the software delivery process, from discovery to production deployment.
• Define, communicate, and influence strategies for platform security and architectural choices.
• Create risk-based security recommendations that balance security needs, business goals, and developer experience.
• Collaborate with Security Operations and Product Security to enhance threat detection, breach modeling, and security resilience.
• Conduct architectural reviews, discovery workshops, and threat modeling engagements.
• Advocate for AI Security, API Security, SaaS Security, and initiatives related to threat modeling automation.
• Provide technical leadership, mentorship, and strategic insight across engineering and security teams.
• Legal authorization to work in the UK; Allstate does not offer sponsorship.
• At least 3 years of experience in software engineering, security engineering, solutions architecture, technical project management, solution design, or platform engineering in complex enterprise settings.
• Experience serving as a technical advisor, consultant, architect, or security partner, assisting engineering teams during design and implementation phases.
• Profound knowledge of threat modeling methodologies including STRIDE, Attack Trees, and Kill Chains.
• Experience in identifying, documenting, and mitigating security threats in cloud-native, distributed, API-driven, or enterprise applications.
• Familiarity with CI/CD, source control, automated testing, and Agile delivery practices.
• Working knowledge of OWASP Top 10, MITRE ATT&CK, NIST Cybersecurity Framework, OAuth 2.0, OpenID Connect, and SAML.
• Experience contributing to Security Operations, Incident Response, SOC, or breach modeling efforts.
• Proficiency in Java, JavaScript, Python, Go, Rust, or other contemporary programming languages.
• Experience designing and evaluating RESTful APIs and API-first architectures utilizing OpenAPI or Swagger.
• Experience embedding security controls and automated security testing in CI/CD pipelines.
• Experience leveraging AI, automation, and modern engineering tools for security purposes.
• Working knowledge of AWS, Azure, or GCP along with relevant security considerations.
• No direct management responsibilities; expected to provide technical leadership, mentorship, and strategic guidance.
• Competitive annual salary.
• Corporate bonus scheme.
• Pension scheme.
• Annual performance-related pay reviews.
• Life assurance and income protection.
• Flexible working options.
• Hybrid working arrangement.
• Private medical and dental insurance.
• Access to an employee assistance program.
• Discounted gym membership.
• Two paid volunteering days each year.
• Cycle to work scheme.
• Continuous Learning Hub.
• Tailored learning paths, certifications, and mentoring opportunities.
TIVITY GmbH
Lifelancer
BCD Travel
Sativa Voyages
Get handpicked remote jobs straight to your inbox weekly.