Information Security Controls Specialist Senior
Information Security Controls Specialist Senior

Information Security Controls Specialist Senior

London Full-Time 43200 - 72000 £ / year (est.) No home office possible
E

At a Glance

  • Tasks: Test security controls in cloud and on-premise environments to protect Experian's assets.
  • Company: Join Experian, a global leader in information services, transforming data into opportunities.
  • Benefits: Enjoy flexible work options, medical insurance, performance bonuses, and education reimbursement.
  • Why this job: Be part of a culture that values diversity, innovation, and collaboration while making a real impact.
  • Qualifications: Bachelor's degree or equivalent experience with 5+ years in Information Security and IT Audit.
  • Other info: This is a permanent hybrid role based in Costa Rica; no relocation available.

The predicted salary is between 43200 - 72000 £ per year.

As a Senior Control Assurance Assessor, you'll test security controls both on-premise and in the cloud to ensure design implementation, safeguarding Experian's assets. You'll assess control design, performance, and compliance with standards and regulations, reporting to the Information Security Control Assurance Testing Manager. Identifying gaps, documenting findings, and recommending improvements to mitigate risks are important responsibilities. Using data-driven testing techniques and a defined methodology, you'll collaborate to ensure controls meet current risks and regulatory requirements.

Primary Responsibilities

  • Conduct security control assessments, using documented control activities (where they exist) and regulatory requirements.
  • Develop test plans, test cases, and procedures, applying data from security tools to capture evidence.
  • Use queries and dashboards to identify potential control failures as part of the control testing process.
  • Ensure the accuracy and timely completion of control testing, providing peer review.
  • Document findings, including root cause analysis and applicable recommendations for remediation.
  • Be the primary liaison with partners, delivering clear progress updates and results.
  • Contribute lessons learned by integrating partner feedback to improve the control testing program.

Experience and Skills

  • A bachelor's degree in computer science, management information systems, or a relevant field, or equivalent demonstrable experience.
  • 5+ years' of experience in Information Security or Information Technology.
  • 3+ years' experience performing IT Audit or security control testing.
  • Knowledge of internal audit methodologies, including risk assessment, execution, and reporting.
  • Proficiency in industry standards and frameworks (e.g., NIST 800-53, ISO 27001/27002).
  • Familiarity with privacy regulations (e.g., GDPR, CCPA) and breach notification laws.
  • Experience with sector-specific frameworks (e.g., HIPAA, PCI).

Technical Skills

  • Proficiency with security tools (SailPoint, Rapid7, Wiz.io, MS Defender, SIEM, vulnerability management, penetration testing).
  • Knowledge of cloud technologies (AWS, Azure).
  • Experience using generative AI (e.g., ChatGPT) for test strategies, reports, and communications.
  • Skills in automation and analytics tools (Excel, Tableau, Alteryx, or PowerBI).
  • Create queries and reports in RSA Archer and ServiceNow.
  • Familiarity with Kanban boards and Jira.

Desired Competencies

  • Understanding of cybersecurity principles and organizational requirements.
  • Experience applying governance, risk, and control principles.
  • Experience in automated and manual testing of security controls.
  • Experience facilitating meetings and conveying complex ideas.
  • Data collection, validation, analysis, and interpretation.
  • Experience researching and applying latest technologies.
  • Experience with Agile methodology.
  • Big 4 accounting experience.
  • Hold a professional certification such as CISA, CISM, CISSP, PCI QSA, ISO 27001 Lead Auditor, or equivalent.

This is a permanent hybrid role in Costa Rica. No relocation available.

Culture at Experian

Experian's culture, people, and environments are main differentiators. We take our people's agenda very seriously. We focus on what matters; diversity and inclusion, work/life balance, flexible work, development, engagement, collaboration, wellness, rewards & recognitions, volunteering... the list goes on! Our benefits include: Medical, life and dental insurance, Asociacion Solidarista, International Share Save Plan, Flex Work/Work from home, Paid time off, Annual Performance Bonus, Education Reimbursement, Family Bonding, Bereavement Leave, Referral Program, and more.

Experian is proud to be an Equal Opportunity and Affirmative Action employer. Our goal is to create a successful, inclusive and diverse team where people love their work and love working together. We believe that diversity, equity and inclusion is necessary to our purpose of creating a better tomorrow.

Information Security Controls Specialist Senior employer: Experian Group

Experian is an exceptional employer, offering a vibrant work culture that prioritises diversity, inclusion, and employee well-being. With a strong focus on professional development and flexible working arrangements in the beautiful setting of Costa Rica, employees enjoy comprehensive benefits including medical insurance, performance bonuses, and education reimbursement. Join us to be part of a globally recognised company that values innovation and collaboration, empowering you to make a meaningful impact in the field of information security.
E

Contact Detail:

Experian Group Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Controls Specialist Senior

✨Tip Number 1

Familiarise yourself with the specific security tools mentioned in the job description, such as SailPoint and Rapid7. Having hands-on experience or even a basic understanding of these tools can set you apart during discussions.

✨Tip Number 2

Brush up on your knowledge of industry standards and frameworks like NIST 800-53 and ISO 27001. Being able to discuss how you've applied these standards in past roles will demonstrate your expertise and relevance for the position.

✨Tip Number 3

Prepare to discuss your experience with both automated and manual testing of security controls. Be ready to share specific examples of how you've identified gaps and recommended improvements in previous roles.

✨Tip Number 4

Showcase your ability to communicate complex ideas clearly. Since you'll be liaising with partners, practice explaining technical concepts in simple terms, which will highlight your communication skills during the interview process.

We think you need these skills to ace Information Security Controls Specialist Senior

Information Security
IT Audit
Security Control Testing
Risk Assessment
Regulatory Compliance
NIST 800-53
ISO 27001/27002
GDPR
Cloud Technologies (AWS, Azure)
Security Tools (SailPoint, Rapid7, MS Defender, SIEM)
Data Analysis
Automation Tools (Excel, Tableau, Alteryx, PowerBI)
Query Creation in RSA Archer and ServiceNow
Agile Methodology
Professional Certifications (CISA, CISM, CISSP, PCI QSA)

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in Information Security and IT Audit. Emphasise your familiarity with industry standards like NIST 800-53 and ISO 27001, as well as any specific tools you've used, such as SailPoint or Rapid7.

Craft a Strong Cover Letter: In your cover letter, express your passion for cybersecurity and detail how your skills align with the responsibilities of the role. Mention your experience in conducting security control assessments and your ability to document findings and recommend improvements.

Showcase Technical Skills: Highlight your proficiency with security tools and cloud technologies in your application. If you have experience using generative AI for test strategies or reports, be sure to include that as it aligns with the job requirements.

Demonstrate Soft Skills: Since the role involves liaising with partners and conveying complex ideas, mention any experience you have in facilitating meetings or collaborating with teams. This will show that you can communicate effectively and work well in a team environment.

How to prepare for a job interview at Experian Group

✨Understand the Role Thoroughly

Before the interview, make sure you have a solid grasp of the responsibilities and requirements of the Information Security Controls Specialist Senior position. Familiarise yourself with security control assessments, compliance standards, and the specific tools mentioned in the job description.

✨Prepare for Technical Questions

Expect to be asked about your experience with security tools and frameworks like NIST 800-53 and ISO 27001. Brush up on your knowledge of cloud technologies and data-driven testing techniques, as these will likely come up during the interview.

✨Showcase Your Problem-Solving Skills

Be ready to discuss past experiences where you've identified gaps in security controls and how you recommended improvements. Use specific examples to demonstrate your analytical skills and ability to mitigate risks effectively.

✨Communicate Clearly and Confidently

As a liaison with partners, clear communication is key. Practice articulating complex ideas simply and confidently. This will not only help you during the interview but also show that you can effectively collaborate with others in the role.

Information Security Controls Specialist Senior
Experian Group
E
  • Information Security Controls Specialist Senior

    London
    Full-Time
    43200 - 72000 £ / year (est.)

    Application deadline: 2027-05-14

  • E

    Experian Group

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>