Software Assurance & Governance Consultant (Contract)
Start Date: ASAP
Location: Brimpton, Berkshire (Onsite)
IR35: Outside
Rate: £550pd
Duration: 1 Week Initial Engagement
The Candidate:
Our client is seeking an experienced, independent specialist to carry out a one-week review of their software development and release pipeline. The purpose is to provide objective assurance that their controls for protecting confidential data — particularly the separation of data between different customers of a multi-tenant application — are operating effectively and reflect current good practice. The reviewer must be genuinely independent: with no prior involvement in the systems under review and no ongoing relationship with the delivery team.
Key Responsibilities:
- Assess the end-to-end pipeline: test planning, code review, automated testing in CI/CD, and release sign-off gates.
- Verify hands-on that automated controls work as intended — including automated / AI-assisted code review and automated regression tests — rather than reviewing documentation alone. This includes confirming that the test suite detects a deliberately re-introduced fault.
- Judge whether controls are genuinely effective or have become nominal through familiarity, and identify gaps a fresh outside perspective would surface.
- Report prioritised findings and recommendations to senior stakeholders.
Essential Skills & Experience:
- Secure software development background, with the ability to read a code diff and reason about the security consequences of changes — including the silent removal of access-control or permission logic.
- Strong SQL Server / T-SQL and experience with database unit-testing frameworks (e.g. tSQLt), sufficient to run or witness a fault-injection test.
- Understanding of multi-tenant / customer data-segregation architecture and its failure modes.
- Experience assessing CI/CD pipelines, release gating, and DevOps work-item traceability.
- Understanding of Claude AI within development workflows.
- A track record of independent process or control-effectiveness assurance reviews and clear reporting to senior audiences.
Desirable:
- Financial services or other regulated, data-sensitive sector experience. A recognised assurance or security credential (e.g. CISA, CISSP, CREST) or equivalent demonstrable experience.
- Implementation of ISO standards.
Deliverables:
- A written report with prioritised findings and recommendations, critical items clearly distinguished.
- Explicit confirmation of the outcome of the hands-on verification of the automated controls.
To apply for this Senior Software Assurance Consultant Contract job, please click the button below and submit your latest CV.
Curo Services endeavour to respond to all applications. However, this may not always be possible during periods of high volume. Thank you for your patience.
Curo Resourcing Ltd acts as an Employment Business for contract and temporary recruitment as well as an Employment Agency in relation to permanent vacancies.
Job Reference: RL8219
Current Vacancies
Cyber Security Consultant (Contract)
Pay: Competitive
Duration: 60 Days
Ref No: RL8224
Software Assurance & Governance Consultant (Contract)
Pay: £550pd
Duration: 1 Week
Ref No: RL8219
Software Team Manager
Pay: Competitive
Duration: Permanent
Ref No: RL8216
ServiceNow Service Mapping Specialist (Contract)
Pay: 414 p/d
Duration: 6 Months
Ref No: RL8214