Azure Security Assurance Consultant (Freelance)
Toro Solutions · London · posted 2 days ago
Occupation
2135Cyber security professionals
Going rate for this occupation: £48,500 · UK median pay £54,647
Home Office going rates from
Sponsorship
Sponsorship chance
Very low
- Not matched to a licence on the register
- Occupation is eligible for Skilled Worker
- Estimated salary is below the going rate
On the public records we hold, sponsorship for this role looks unlikely: not matched to a licence on the register, and occupation is eligible for Skilled Worker.
- The salary is an estimate from national earnings data, not the employer's figure.
Why
Sign in to see how you fit and draft a cover letter
We read this advert for what it asks, check each line against your CV and show you the evidence for every judgement.
Sign inFull advert
Contract Basis: This is a freelance contract role, estimated to require approximately 15 days of work over the next 6 months. The timing and allocation of days will be agreed in line with programme needs and design review milestones.
Role Purpose
The Azure Security Assurance Consultant will provide independent security assurance for a programme of work delivered by Toro to a banking client. The role will focus on reviewing emerging Azure architecture and feature-specific designs, challenging security assumptions, identifying risks and control gaps, and providing practical recommendations that can be addressed by the programme team.
The consultant will act as an independent security reviewer, helping the bank gain confidence that the proposed architecture, security controls and design decisions are appropriate for the sensitivity, complexity and criticality of the programme.
Key Responsibilities
Review high-level Azure architecture designs and feature-specific solution designs as they become available. Assess whether the proposed Azure architecture, security controls and integration patterns are appropriate for the programme’s business criticality, regulatory context and data sensitivity. Review security considerations across Azure hub-and-spoke architecture, network segmentation, firewalls, ingress and egress controls, identity and access management, logging, monitoring and connectivity with on-premises services. Challenge security assumptions, design decisions and control dependencies in a constructive and evidence-led manner. Identify gaps, risks, weaknesses, dependencies and areas requiring further clarification. Provide pragmatic, prioritised recommendations that can be implemented by the programme team. Support the bank in maintaining evidence of independent assurance, security decision-making and risk treatment. Contribute to clear security assurance outputs, including review notes, findings summaries, risk statements and recommendations. Help determine where later build assurance, configuration review, Infrastructure as Code review or security testing should be prioritised. Engage with architects, security stakeholders, infrastructure teams and programme stakeholders to discuss findings and agree appropriate next steps.
Required Experience
Strong experience in cloud security assurance, preferably within Microsoft Azure environments. Practical understanding of Azure architecture patterns, including hub-and-spoke networking, landing zones, firewalls, private endpoints, routing, DNS, identity and monitoring. Experience reviewing technical architecture designs and identifying security risks before implementation. Good understanding of security controls for regulated or business-critical environments. Experience assessing identity and access management, privileged access, network security, logging, monitoring and secure integration patterns. Ability to translate technical risks into clear, practical recommendations for project and security stakeholders. Experience working with financial services, banking, payments or other regulated environments would be highly beneficial. Familiarity with FCA, PRA, operational resilience, GDPR, ISO 27001 or similar control frameworks would be advantageous.
Information from public records, not immigration advice.