Contract Basis: This is a freelance contract role, estimated to require approximately 15 days of work over the next 6 months. The timing and allocation of days will be agreed in line with programme needs and design review milestones.
Role Purpose
The Azure Security Assurance Consultant will provide independent security assurance for a programme of work delivered by Toro to a banking client. The role will focus on reviewing emerging Azure architecture and feature-specific designs, challenging security assumptions, identifying risks and control gaps, and providing practical recommendations that can be addressed by the programme team.
The consultant will act as an independent security reviewer, helping the bank gain confidence that the proposed architecture, security controls and design decisions are appropriate for the sensitivity, complexity and criticality of the programme.
Key Responsibilities
Review high-level Azure architecture designs and feature-specific solution designs as they become available.
Assess whether the proposed Azure architecture, security controls and integration patterns are appropriate for the programme’s business criticality, regulatory context and data sensitivity.
Review security considerations across Azure hub-and-spoke architecture, network segmentation, firewalls, ingress and egress controls, identity and access management, logging, monitoring and connectivity with on-premises services.
Challenge security assumptions, design decisions and control dependencies in a constructive and evidence-led manner.
Identify gaps, risks, weaknesses, dependencies and areas requiring further clarification.
Provide pragmatic, prioritised recommendations that can be implemented by the programme team.
Support the bank in maintaining evidence of independent assurance, security decision-making and risk treatment.
Contribute to clear security assurance outputs, including review notes, findings summaries, risk statements and recommendations.
Help determine where later build assurance, configuration review, Infrastructure as Code review or security testing should be prioritised.
Engage with architects, security stakeholders, infrastructure teams and programme stakeholders to discuss findings and agree appropriate next steps.
Required Experience
Strong experience in cloud security assurance, preferably within Microsoft Azure environments.
Practical understanding of Azure architecture patterns, including hub-and-spoke networking, landing zones, firewalls, private endpoints, routing, DNS, identity and monitoring.
Experience reviewing technical architecture designs and identifying security risks before implementation.
Good understanding of security controls for regulated or business-critical environments.
Experience assessing identity and access management, privileged access, network security, logging, monitoring and secure integration patterns.
Ability to translate technical risks into clear, practical recommendations for project and security stakeholders.
Experience working with financial services, banking, payments or other regulated environments would be highly beneficial.
Familiarity with FCA, PRA, operational resilience, GDPR, ISO 27001 or similar control frameworks would be advantageous.
Required Skills and Attributes
Strong analytical and critical-thinking skills.
Ability to provide constructive security challenge without slowing delivery unnecessarily.
Clear written communication skills, including the ability to produce concise findings and recommendations.
Strong stakeholder engagement skills, with the ability to work with architects, engineers, security teams and programme leads.
Practical, proportionate and risk-based approach to security assurance.
Ability to work flexibly as designs evolve and programme priorities change.
Comfortable operating independently with limited supervision.
Commercial awareness and ability to focus effort where it provides the greatest assurance value.
Desirable Certifications
Microsoft Certified: Azure Security Engineer Associate
Microsoft Certified: Azure Solutions Architect Expert
ISO 27001 Lead Auditor or Lead Implementer
SABSA, TOGAF or similar architecture-related qualification
Neutral 2–4 sentence summary of what working at this company is like, drawn from public reviews and press coverage. Tone, collaboration style, pace, benefits highlights.