Cyber Security Controls Tester (Assurance)

Sanderson Recruitment Plc
London, UK
10 days ago
Apply on www.securityclearedjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£130,000.0 - £143,000.0
Working hours
Regular working hours

Tech stack

CompTIA Security+ Cyber Security Software Design Documents High-Level Architecture Identity and Access Management Network Security Network Configuration and Change Management PCI Data Security Standards CIS Benchmarks Firewall Services Module

Job description

An established MSSP is seeking an experienced Cyber Security Controls Tester to support a large-scale security assurance programme. This is an excellent opportunity for a security professional with a strong controls testing, audit, risk, or assurance background to assess the effectiveness of security controls across complex environments.

Working closely with security architects, risk teams, and business stakeholders, you will provide independent assurance that security controls are appropriately designed, implemented, and operating effectively against recognised industry frameworks and standards., * Evaluate the effectiveness of technical, procedural, and physical security controls against documented security requirements and standards.

  • Assess security controls against recognised frameworks including ISO 27001, NIST CSF, NIST 800-53, and CIS Controls.
  • Review security documentation, including High-Level Designs (HLDs), Low-Level Designs (LLDs), policies, procedures, and controls catalogues.
  • Assess network configurations, firewall rules, identity and access management controls, encryption controls, and endpoint security measures.
  • Develop and agree test plans and testing scopes with security architects, risk teams, and relevant stakeholders.
  • Apply recognised assurance methodologies, including walkthroughs, documentation reviews, sampling, evidence gathering, and technical verification.
  • Produce detailed testing reports, findings, risk assessments, and remediation recommendations.
  • Provide pragmatic guidance to improve security posture and address identified control weaknesses.
  • Maintain accurate and auditable records of testing activities, findings, and corrective actions.
  • Collaborate with risk and security architecture teams to ensure testing activities support wider governance, risk, and assurance objectives.

Requirements

  • Proven experience testing and assessing the effectiveness of security controls within complex enterprise environments.
  • Strong knowledge of security frameworks including:
  • ISO 27001
  • NIST Cyber Security Framework (CSF)
  • NIST 800-53
  • CIS Controls
  • Experience reviewing and testing:
  • Network security controls
  • Firewall configurations and rule sets
  • Identity and Access Management (IAM)
  • Encryption controls
  • Endpoint security technologies
  • Strong understanding of security assurance and control testing methodologies.
  • Experience working with technical design documentation, including HLDs, LLDs, and controls catalogues.
  • Knowledge of relevant legislation and regulatory requirements, including:
  • GDPR
  • PCI DSS
  • ICO requirements
  • Familiarity with HMG and NCSC security policies, standards, and guidance.
  • Excellent analytical, investigative, and problem-solving skills.
  • Strong stakeholder engagement and communication capabilities.
  • Ability to produce clear, concise, and actionable assurance reports for both technical and non-technical audiences.

Desirable Certifications

One or more of the following certifications would be advantageous:

  • CISA
  • CRISC
  • ISO 27001 Lead Auditor
  • ISO 27001 Lead Implementer
  • CompTIA Security+
  • Other security assurance, audit, or controls testing certifications

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.securityclearedjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · World Congress 2022

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

Videos

See all

Related articles

See all