Current vacancies
Search by job title or keyword
Senior Web Application Security Consultant
About us
We’re The Very Group and we’re here to help families get more out of life. We know that our customers work hard for their families and have a lot to balance in their busy lives. That’s why we combine amazing brands and products with flexible payment options on Very.co.uk to help them say yes to the things they love. We’re just as passionate about helping our people get more out of life too, building careers with real growth, a sense of purpose, belonging and wellbeing.
About the role
We are looking for a Senior Web Application Security Consultantto join the Tech Ops Architecture team to deliver technical solutions that meet the organisation’s security policies and standards.
The Very Group are undertaking a number of exciting initiatives that will transform its online ecommerce platform.
An individual experienced in securing web applications and services is required to ensure the delivered technical solutions & associated operating models meet The Very Group’s security standards and polices.
This engagement will require the consultant to have experience of AWS including serverless deployments along with Agile delivery methodologies and possess excellent stakeholder communication skills.
High level deliverables will include:
- Production of Security Threat Models.
- Production of detailed security requirements.
- Security Risk Assessments.
- Technical Assurance Review.
- Scoping & facilitation of Penetration Tests.
- Production of security process documentation.
Key responsibilities
- To be a senior security subject matter expert for Tech Ops and the organisation.
- To be the Senior Consultant assigned to an individual business tribe.
- Act as a mentor to security consultants and security champions.
- Undertake Security Threat Modelling.
- Define Security Requirements
- Document Security Risk Assessments
- Scope & Facilitate Penetration Tests.
- Shape and develop the Information Security mindset of a Tribe, working with Security Champions to develop training & awareness, Security Metrics and improvement use cases.
- Undertaking professional development to maintain professional skills and knowledge essential to the position.
- Staying abreast with Information and Cyber Security trends, threats and legal & regulatory changes.
What you’ll bring
- Experience of securing web application services in cloud platforms.
- Deep understanding of AWS Services and experience of Serverless deployments
- Thorough understanding of OWASP Top 10
- Securing API services including a good working knowledge of OAuth 2,
- Application security lifecycle, including secure by design process.
- Experience in securing CI/CD pipelines
- Security testing tools knowledge
- Information Security and /or Information Technology industry qualification strongly preferred (such as CISSP or CISM).
- Experience of agile methods of working.
- Good understanding and experience of threat and risk modelling (STRIDE, DREAD).
- Good understanding and experience of the Secure Software Development Lifecycle.
Some of our benefits
- Flexible, hybrid working model
- Inclusive culture and environment, check out our Glassdoor reviews
- Flexible benefits allowance to suit your needs
- 30 days holiday + bank holidays
- Udemy learning platform
- Bonus potential (performance and business-related)
- Up to 25% discount on Very.co.uk
- Matched pension up to 6%
- More benefits can be found on our career site
How to apply
Please note that the talent acquisition team are managing this vacancy directly, and if successful in securing this role, you may be required to undertake a credit, CIFAS and CRB
What happens next?
Our talent acquisition team will be in touch if you’re successful so keep an eye on your emails! We’ll arrange a short call to learn more about you, as well as answer any questions you have. If it feels like we’re a good match, we’ll share your CV with the hiring manager to review. Our interview process is tailored to each role and can be in-person or held remotely.
You can expect a two-stage interview process for this position:
1st stage - An informal 30-minute video call with the hiring team to discuss your skills and relevant experience. This is a great opportunity to find out more about the role and to ask any questions you may have.
2nd Stage – A 90-minute formal interview where you can expect both competency and technical questions. This can be held either in-person or remotely.
As an inclusive employer please do let us know if you require any reasonable adjustments.
If you'd like to know more about our interviews, you can find out here.
Equal opportunities
We’re an equal opportunity employer and value diversity at our company. We do not discriminate based on race, religion, colour, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.