Information Security Consultant (6 Month Contract)
- Contract Type Day Rate Contractor
- Closing Date 19 September, 2026
- Job Category Tech, Data and Digital
- Business Unit Information Security (UKTI)
- Location London, United Kingdom
- Posted on 20 August, 2026
The opportunity
This is a unique opportunity to work on an exciting transformation programme, influencing the security posture of critical Bank systems while collaborating closely with engineers, product managers, and business stakeholders. You’ll often operate independently of other security and privacy subject matter experts, so a broad and deep understanding of security and privacy domains is essential — from secure architecture and threat modelling to data protection and regulatory compliance
If you thrive on autonomy, love solving complex problems, and want to see the real-world impact of your work in a critical industry — this is the role for you.
Key responsibilities
- Problem Solving - You will develop a deep knowledge of your workstreams technology stack and business outcomes allowing you to not only identify security risks but identify and propose practical solutions to the team. This role is all about helping teams deliver securely not just calling out risks.
- Risk and Control Assessments – You will lead risk & control assessments using the Banks defined processes, covering supplier due diligence, privacy impact assessments and project security.
- Risk Management – You will support your workstream identify and articulate risks, steering them towards appropriate treatment plans, documenting mitigating controls and ensuring these are actions within agreed timeframes. You will operate in line with the Bank's Risk Management framework (including sub-frameworks) and relevant risk and compliance policies and procedures, ensuring appropriate and timely escalation of any concerns to your line manager.
- Advisory – You will provide specialist advice and interpretation of Information Security best practice and UK regulatory requirements to a range of different stakeholders as new products, processes and systems are developed. You will need to be aware of your own knowledge gaps and when & where to seek specialist input to solve a particular problem or query
- Subject Matter Expertise – You will develop a deep knowledge of the Banks secure change processes and procedures, shepherding your workstream through various assessments and approval gates
- Relationship Management – You will build deep, trust based relationships with key stakeholders within your delivery team such as developers, testers, product managers, delivery leads and tech leads. You will be an active member of the delivery team, attending daily stand-ups, PI planning sessions and working groups.
What we’re looking for
Research (by Harvard University) shows that women are particularly likely to second guess themselves and not apply - so if you are worried you don't meet all the criteria, get in touch anyhow and let us do the worrying…
- You are a skilled communicator, able to convey complex security issues to a wide audience, including non-technical colleagues.
- Hold or have the capability to attain appropriate external qualifications, such as Certified Information Systems Security Professional (CISSP).
- You love building strong interpersonal relationships across engineering, product, compliance, and business teams to foster a culture of shared security ownership.
- You are great at identifying information security risks and you enjoy finding creative solutions problems.
- You have a wide range of information security knowledge and, crucially, you are aware of your own knowledge gaps and able to seek support and guidance as required.
- You understand the intersection of Risk Management and Information Security and how these relate to each other in a Financial Service business (3LoD model)