About Claranet :
Founded at the beginning of the dot.Com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries.
At Claranet, we’re experienced in implementing progressive technology solutions which help our customers solve their epic business challenges. We’re committed to understanding their problems, delivering answers quickly, and making a lasting impact to their business.
We are agile, focused and experienced in business modernisation. Our approach helps customers make genuine, significant shifts in their business strategy, to deliver financial savings, boost innovation, and create a resilient business. We continually invest in our people and the latest technologies, so our customers get peace of mind knowing that they have access to the best talent and services.
In the UK we have over 500 staff working in London, Gloucester, Warrington, Bristol, and Leeds, or as homeworkers. In India we have 130 Staff working for International Projects.
Working For Claranet
We offer an extensive benefits package, inclusive of a matching contribution provident fund, Gratuity, Flexible tax saving benefits, healthcare, attractive insurance benefits.
Claranet is one of the 10 founding members of TC4RE (Technology Community for Racial Equality). Being a part of a group of leading UK technology organisations, we are dedicated to building a more diverse and inclusive workforce.
Our Vision
- Our vision is to become the most trusted technology solutions partner;
renowned for being the best and brightest, having lasting impact with our customers and delivering exceptional returns to our stakeholders.
Position Summary
The Sr. Security Consultant (Cloud Security) has responsibility for everything from client projects to development work and training, dealing with large corporate penetration testing. With a focus on large-scale corporate penetration testing, this role demands both technical excellence and strong client engagement skills. The consultant is passionate about uncovering vulnerabilities and translating findings into actionable improvements, while building strong relationships through clear communication and exceptional customer service.
Our team is growing, and we need inspiring people to join us and help us to continue to build a world leading cyber security operation whilst benefiting from the opportunity to fulfil their potential. Based in India, this work will lead on penetration testing and have the opportunity to work on projects with worldwide clients and will form part of our global team of penetration testers who share research, tooling, experience and collaborate freely on projects. As a respected training provider and the leading provider of training at Black Hat conferences, our penetration testers also have the option of developing training skills and delivering security training, to both private customers, at our own events, and at leading international conferences.
Objectives and Key Results
The Sr. Security Consultant (Cloud Security) is part of the Consultancy Team and represents a trusted advisor and subject matter expert in cybersecurity.
The key objectives will be to :
Develop the Cloud Security training content emphasizing mainly Azure / AWS / GCPDeliver high-quality penetration testing and configuration reviews across various cloud technologies such as AWS / Azure / GCPProvide expert guidance and recommendations to clients for improving their security postureMentor and support junior consultants, helping to grow the team’s overall capabilities
Essential Roles & Responsibilities
Develop standard operating procedures and conduct comprehensive training sessions for each technology, ensuring a thorough understanding and adherence to best practicesA candidate should be willing to deliver the Cloud Security training in various conference remotely or on-siteConduct research and provide new ideas of the training content, as per the market or latest vulnerabilities or misconfigurationsCreating comprehensive training materials, including presentations, labs, and documentationStaying updated with the latest trends and developments in cloud securityCustomizing content to align with industry best practices and specific client needsContinuously improving and expanding training resourcesPerform cloud penetration testing to identify vulnerabilities or misconfiguration in the client environmentDevelop documentation, and a knowledge base to be used by penetration tester to conduct review, security assessmentsDevelop and implement the security solution for the current cloud deployment NSS hasDevelop standard operating procedures and training for each technologyArchitect and continuously improve security technology stack, process and procedures, support model and cross-function interactions utilizing automation where possibleDevelop and report Cloud security coverage metricsDefine procedures to validate the effectiveness of the design, deployment, and management of security controls that aim to maintain confidentiality, integrity, and availability of Cloud networks and technology platformsConduct research to stay up to date with the latest advancements in generative AI, machine learning, and deep learning techniques and identify opportunities to integrate them into our products and servicesConduct thorough reviews and assessments of the utilization of Cloud security tooling, ensuring optimal performance and alignment with security objectives.Additional Requirements :
Conduct comprehensive penetration tests on various systems, applications, and networks to identify vulnerabilities and weaknessesPrepare detailed reports of findings, including risk assessments and remediation recommendations, tailored to technical and non-technical stakeholdersStay updated with the latest cybersecurity threats and trends and apply this knowledge to enhance testing methodologiesPossessing relevant industry certifications, such as Offensive Security Certified Professional (OSCP) or CREST certification, would be advantageousKey Skills & Requirements
A bachelor’s degree in Cybersecurity, International Security Architecture, or related field;or equivalent work experience in a converged security program
4-7 years of hands-on experience, preferably with at least one major cloud provider such as GCP, Azure, or AWS2+ years of client-facing consulting work experience performing penetration testingExperience with Infrastructure as code (Vagrant, Docker, Ansible, Chef, Terraform, or similar)A deep understanding of industry standards and best practices in Cloud security, including familiarity with CSA CCM, CIS, NIST benchmarks, and moreExcellent communication skills (written and verbal) with an ability to explain complex topics in a clear and concise manner to both technical and non-technical audiencesBasics to intermediate development and scripting skills in at least one programming languageProven experience in cloud security, including hands-on implementation and managementExceptional communication and presentation skillsStrong organizational and time-management abilitiesPassion for sharing knowledge and facilitating learningProfessional certifications in cloud security (e.G., AWS Certified Security - Specialist, Azure Security Engineer)Technical knowledge of Kubernetes and Docker technologies and associated security requirements (Kubernetes, Docker, etc.)Should have at least one associate-level cloud certification, such as AWS Solutions Architect GCP Associate Cloud Engineer, as a testament to specialized knowledge and expertiseExperience Requirement :
Candidates must have 4+ years of penetration testing experienceGitHub Profile : Possession of a GitHub profile showcasing the development of tools to address cloud-related challenges is preferredCertifications (Nice to Have) :
AWS Certified Security – SpecialtyAWS Certified Solutions Architect AssociateAZ-500 : Microsoft Azure Security TechnologiesAZ-104 : Microsoft Azure Administrator