Cyber Security Controls Tester (Assurance)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
An established MSSP is seeking an experienced Cyber Security Controls Tester to support a large-scale security assurance programme. This is an excellent opportunity for a security professional with a strong controls testing, audit, risk, or assurance background to assess the effectiveness of security controls across complex environments.
Working closely with security architects, risk teams, and business stakeholders, you will provide independent assurance that security controls are appropriately designed, implemented, and operating effectively against recognised industry frameworks and standards., * Evaluate the effectiveness of technical, procedural, and physical security controls against documented security requirements and standards.
- Assess security controls against recognised frameworks including ISO 27001, NIST CSF, NIST 800-53, and CIS Controls.
- Review security documentation, including High-Level Designs (HLDs), Low-Level Designs (LLDs), policies, procedures, and controls catalogues.
- Assess network configurations, firewall rules, identity and access management controls, encryption controls, and endpoint security measures.
- Develop and agree test plans and testing scopes with security architects, risk teams, and relevant stakeholders.
- Apply recognised assurance methodologies, including walkthroughs, documentation reviews, sampling, evidence gathering, and technical verification.
- Produce detailed testing reports, findings, risk assessments, and remediation recommendations.
- Provide pragmatic guidance to improve security posture and address identified control weaknesses.
- Maintain accurate and auditable records of testing activities, findings, and corrective actions.
- Collaborate with risk and security architecture teams to ensure testing activities support wider governance, risk, and assurance objectives.
Requirements
- Proven experience testing and assessing the effectiveness of security controls within complex enterprise environments.
- Strong knowledge of security frameworks including:
- ISO 27001
- NIST Cyber Security Framework (CSF)
- NIST 800-53
- CIS Controls
- Experience reviewing and testing:
- Network security controls
- Firewall configurations and rule sets
- Identity and Access Management (IAM)
- Encryption controls
- Endpoint security technologies
- Strong understanding of security assurance and control testing methodologies.
- Experience working with technical design documentation, including HLDs, LLDs, and controls catalogues.
- Knowledge of relevant legislation and regulatory requirements, including:
- GDPR
- PCI DSS
- ICO requirements
- Familiarity with HMG and NCSC security policies, standards, and guidance.
- Excellent analytical, investigative, and problem-solving skills.
- Strong stakeholder engagement and communication capabilities.
- Ability to produce clear, concise, and actionable assurance reports for both technical and non-technical audiences.
Desirable Certifications
One or more of the following certifications would be advantageous:
- CISA
- CRISC
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- CompTIA Security+
- Other security assurance, audit, or controls testing certifications
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
IT Salaries in UK
Best Companies to work for in London: Top 25 Companies in 2023