Security Design Consultant

Company: Lloyds Banking Group
Apply for the Security Design Consultant
Location: Edinburgh
Job Description:

Overview

Join Lloyds Banking Group as a Security Design Consultant within the Security Consultancy and Design team, helping to embed secure design across a broad change portfolio. You will develop secure solutions and produce Security Design documentation, translating threats into actionable risks for the business. You’ll deconstruct architectures, assess risks, and communicate complex concepts to technical and non-technical stakeholders. This role offers impact across a high-profile banking environment, contributing to the bank of the future and shaping security strategy.

Pay / Benefits

  • Generous pension contribution up to 15%
  • Annual performance-related bonus
  • Share schemes including free shares
  • Discounted shopping benefits
  • Generous holiday allowance with bank holidays
  • Wellbeing initiatives and parental leave policies

Responsibilities

  • Develop and design secure solutions with accompanying Security Design documentation
  • Deconstruct solution and network architectures to assess security posture
  • Identify threats and vulnerabilities, evaluate soundness using standard practices
  • Translate threats into risks and assist the business in assessing likelihood and impact
  • Communicate technical concepts to both technical and non-technical stakeholders
  • Produce and articulate Security Designs to project and business stakeholders
  • Weigh risks and benefits of competing security design options
  • Manage multiple challenging projects simultaneously

Key requirements

  • Ability to develop, design secure solutions and produce Security Design documents
  • Experience interpreting threats into risks and communicating them to stakeholders
  • Knowledge of threat modelling and industry practices (STRIDE, MITRE)
  • Familiarity with security standards (ISO 27000 series, PCI DSS, COBIT, NIST, OWASP)
  • Security certifications (CISSP / CISM / CCSP or equivalent) and/or technical security domain certifications (CEH / OSCP)
  • Experience with Public and/or Private cloud environments
  • Strong communication skills to bridge technical and non-technical audiences
  • Ability to balance risk/benefit across multiple projects
  • Effective communication with stakeholders
  • Cross-functional collaboration
  • Analytical thinking and problem solving
  • Security design and documentation
  • Threat modelling and risk assessment
  • Cloud environments (public/private)

…

Posted: October 1st, 2026