Overview
As an Information Security Consultant, you will play a vital role in a technical programme aimed at enhancing secure data integration within UK policing environments. Working with a collaborative team of solution architects, software engineers, and data specialists, you will ensure that security and information governance requirements are integral to the technical architecture from the outset, rather than being an afterthought. Your expertise will support the initiative in achieving a consistent framework for exchanging authorized operational information across organizations while maintaining local control of source systems.
Responsibilities
- Own the security and information-governance workstream across the programme.
- Develop and maintain the threat model and security architecture.
- Translate policing information-governance requirements into practical technical controls.
- Advise on authentication, authorisation, policy enforcement and identity-context propagation.
- Define security requirements for local data integration services, APIs and service-to-service communication.
- Support DPIA, information-governance and data-processing assessments.
- Assess controls around OFFICIAL and OFFICIAL-SENSITIVE policing information.
- Ensure security considerations are reflected in test scenarios and acceptance criteria.
Requirements
- Significant experience in security architecture, information assurance or information governance within UK government or policing.
- Current SC and NPPV3 clearance.
- Strong understanding of policing or law-enforcement data handling.
- Experience designing security controls around APIs, distributed systems or data-integration platforms.
- Practical understanding of authentication, authorisation, role/policy-based access and identity federation.
- Proficiency in threat modelling and security risk assessment.
- Experience with UK GDPR, Data Protection Act requirements and law-enforcement processing.
- Familiarity with Azure, Kubernetes and API-management environments.