
Platform Consultant – Multiple Levels
Posted Sep 28

Posted Sep 28
This is a fully remote position, open to applicants in United Kingdom.
• Act as a reliable security consultant for engineering teams, focusing on secure architecture, platform design, and threat modeling.
• Lead and conduct threat modeling sessions across various applications, platforms, and business sectors.
• Integrate secure-by-design principles throughout the software delivery process, from initial discovery to production deployment.
• Define, articulate, and promote platform security strategies and architectural choices.
• Create risk-based security recommendations that balance security needs, business goals, and developer experience.
• Work in collaboration with Security Operations and Product Security teams on threat detection, breach modeling, and enhancing security resilience.
• Facilitate architectural reviews, discovery workshops, and threat modeling activities.
• Advocate for initiatives related to AI Security, API Security, SaaS Security, and the automation of threat modeling.
• Offer technical leadership, mentorship, and strategic direction across engineering and security teams.
• Legal authorization to work in the UK; Allstate is not offering sponsorship.
• At least 3 years of experience in software engineering, security engineering, solutions architecture, technical project management, solution design, or platform engineering roles within complex enterprise environments.
• Experience serving as a technical advisor, consultant, architect, or security partner, assisting engineering teams during design and implementation phases.
• In-depth knowledge of threat modeling methodologies such as STRIDE, Attack Trees, Kill Chains, or similar risk assessment frameworks.
• Proven experience in identifying, documenting, and addressing security threats in cloud-native, distributed, API-driven, or enterprise applications.
• Hands-on experience with CI/CD, source control, automated testing, and Agile delivery methodologies.
• Proficient understanding of OWASP Top 10, MITRE ATT&CK, NIST Cybersecurity Framework, OAuth 2.0, OpenID Connect, and SAML.
• Experience in supporting Security Operations, Incident Response, SOC, or breach modeling efforts.
• Familiarity with Java, JavaScript, Python, Go, Rust, or other contemporary programming languages.
• Experience in designing and reviewing RESTful APIs and API-first architectures utilizing OpenAPI or Swagger.
• Experience in integrating security controls and automated security testing within CI/CD pipelines.
• Knowledge of applying AI, automation, and modern engineering tools to improve security efficiency and productivity, with exposure to AI, SaaS, and API security.
• Basic understanding of AWS, Azure, or GCP along with relevant security considerations.
• Corporate bonus scheme.
• Pension scheme.
• Annual performance-related pay reviews.
• Life assurance and income protection.
• Flexible working options.
• Hybrid working model.
• Private medical and dental insurance.
• Access to an employee assistance program.
• Discounted gym membership.
• Two paid volunteering days each year.
• Cycle to work scheme.
• Continuous Learning Hub with customized learning paths, certifications, and mentoring opportunities.
Get handpicked remote jobs straight to your inbox weekly.