> Markdown version of [/jobs/ext/3058912-assistant-manager-cybersecurity-controls-testing-analyst-global](https://www.wearedevelopers.com/jobs/ext/3058912-assistant-manager-cybersecurity-controls-testing-analyst-global). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Assistant Manager - Cybersecurity Controls Testing Analyst - Global - **Company:** Deloitte - **Location:** Milton Keynes, UK - **Contract:** Permanent contract - **Skills:** Automation of Tests, Cloud Computing, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Database Queries, Disk Controller, Microsoft Security Essentials, Kusto Query Language, EndPointSecurity, Microsoft InTune, CIS Benchmarks, Cyber Warfare, Qualys, Servicenow - **Published:** September 25, 2026 - **Apply:** https://apply.deloitte.co.uk/UKCareers/Login?jobId=25263 ## About the Role The ideal candidate will bring a combination of technical cyber security experience and GRC or compliance expertise. You will have hands-on experience in areas such as cyber operations, infrastructure, cloud, security engineering, or security administration, and the technical acumen to understand how controls are designed, implemented, and evidenced in practice. Experience supporting compliance, audit, controls assurance, or risk management activities is essential, along with the ability to assess whether technical controls effectively satisfy regulatory, policy, and industry-standard requirements., * Bachelor's degree in information systems, Computer Science, Cybersecurity, Engineering, or a related field. * Relevant certifications such as ISO 27001 Lead Auditor, CISA, CRISC, Security+, or similar are desirable * Proven professional experience in information security, IT risk management, internal audit, compliance, or controls testing roles. * Experience conducting compliance testing, audits, or control assessments against internal or external standards (e.g., ISO 27001, NIST, CIS Controls, SOC 2). * Working knowledge of automated control testing tools (e.g., Qualys, Tenable, Rapid7, or similar platforms). * Experience with GRC or ITSM platforms such as ServiceNow, Archer, MetricStream, or similar for control and remediation tracking. * Experience with Microsoft security tooling (e.g., Defender for Endpoint, Intune, Sentinel) and/or KQL query writing is advantageous. * Experience working in a large, global, matrixed organisation is an advantage. ## Description As a Cybersecurity Controls Testing Analyst, you will support DT's Controls Assurance Testing Programme by validating the design and operating effectiveness of security controls through a combination of automated and manual testing. Working closely with the Cyber Compliance Manager and technical stakeholders, you will help translate regulatory, policy, and industry-standard requirements into measurable controls, identify opportunities to automate testing through data and system integrations, and perform evidence-based assessments where automation is not feasible. You will also support the validation of remediation activities, helping drive control deficiencies through to closure and contributing to reporting and governance activities., * Support the execution of DT's Controls Assurance Testing Programme through a combination of automated and manual control testing activities. * Translate regulatory, policy, and industry standard requirements into measurable control objectives, helping define how compliance requirements should be implemented and evidenced within technology environments. * Partner with technical teams to understand the design and operation of security controls across identity, endpoint, network, infrastructure, cloud, and security operations domains. * Identify opportunities to automate control testing through integrations with security and technology platforms, leveraging system data wherever possible to support continuous assurance and reduce manual testing effort. * Develop and maintain automated testing logic, technical validation queries, control mappings, and evidence requirements to support repeatable and scalable testing activities. * Perform manual control effectiveness testing where automation is not feasible, including evidence collection, validation, sampling, and assessment against defined testing criteria. * Assess whether implemented controls meet the intent of applicable policies, standards, and compliance requirements, documenting findings and testing outcomes. * Validate remediation activities submitted by control owners, reviewing technical and procedural evidence to determine whether identified deficiencies have been effectively addressed. * Track control deficiencies and remediation activities through to closure, proactively engaging with stakeholders and escalating overdue actions where appropriate. * Maintain control testing documentation, findings, remediation records, and workflow activities within ServiceNow IRM. * Collaborate with DT Cyber Risk, IT Risk Management, Cyber Security, Engineering, and Operational teams to ensure control testing activities are technically accurate, well evidenced, and consistently executed. * Support the Compliance Manager in evolving and maturing the Controls Assurance Testing Programme, including the development of testing methodologies, automation capabilities, reporting, and quality standards. * Contribute to management reporting, KPI development, dashboard production, and assurance insights for compliance and risk stakeholders. * Stay current with emerging technologies, cyber security practices, control assurance methodologies, and relevant regulatory and industry standards. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) ## Related Articles - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)