Lead Security Control Assessor
Lead Security Control Assessor

Lead Security Control Assessor

Nottingham Full-Time 43200 - 72000 £ / year (est.) No home office possible
G

At a Glance

  • Tasks: Lead assessments of security controls in cloud and on-premise environments.
  • Company: Join a dynamic team focused on cybersecurity excellence and innovation.
  • Benefits: Enjoy flexible working options, professional development opportunities, and a collaborative culture.
  • Why this job: Make a real impact by enhancing security measures and ensuring compliance across systems.
  • Qualifications: Bachelor's degree in relevant field and 8+ years in IT Audit or Security assessments required.
  • Other info: Experience with automation and cloud security tools is a plus.

The predicted salary is between 43200 - 72000 £ per year.

As a Lead Security Control Assessor, you will be responsible for leading the assessment and evaluation of security controls across systems and processes both on-premise and in the cloud, to ensure they effectively mitigate risks and comply with regulatory and industry standards. You will oversee and conduct security control testing, to verify the design, implementation, and operational effectiveness of controls. In this role, you will work in an agile environment, ensuring the quality of security assessments through thorough testing, automation, and collaboration with cross-functional teams and various stakeholders.

Summary of Primary Responsibilities

  • Design and deliver repeatable testing methodologies to support control assurance testing, including automated testing steps for cloud environments.
  • Ensure control tests are well-planned, including risk identification, sampling, selection of controls, testing methods, and reporting criteria.
  • Lead control testing teams to perform design and operating effectiveness testing of information security controls, including fieldwork, testing, and reporting activities.
  • Provide quality assurance for control testing documentation produced during testing, ensuring accurate and timely completion of all required control testing documentation.
  • Identify and document control deficiencies, including root causes, risk descriptions, consistent issue ratings, and recommendations for improvement.
  • Create and present reports of control testing findings to stakeholders, socialising any findings effectively.
  • Serve as the primary contact with business stakeholders for the controls tests you lead, ensuring the quality of control testing engagements and stakeholder communications, including regular status updates.
  • Contribute to the efficiency of the control testing program by ensuring KPIs are measurable, that testing materials are standardised.

Requirements:

  • A bachelor's degree in computer science, management information systems, relevant field, or equivalent demonstrable experience.
  • 3+ years' experience leading a team of control assessors.
  • 8+ years of experience performing IT Audit or Information Security control assessments, with specific experience in testing cloud security controls.
  • Professional certification such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, or equivalent.
  • Knowledge of industry standards and frameworks such as NIST 800-53, ISO 27001/27002, CIS Controls, COBIT.
  • Experience with current automated and manual industry methods for evaluating security controls on Perm and in cloud environments.
  • Capable of communicating complex information in an organised manner, both verbally and in writing.
  • Skilled in utilising stakeholder feedback to improve existing processes and future engagements.
  • Strong relationship management skills, demonstrating commitment to delivering quality results.

Technical Skills

  • Knowledge of security controls provided by tools such as Sailpoint, Rapid7, Wiz.io, MS Defender a plus.
  • Experience with cloud security controls within environments such as AWS and Azure.
  • Experience leveraging automation, data driven testing techniques and generative AI to gain efficiency in control assurance.
  • Experience creating queries and reports using RSA Archer and Service-Now.
  • Familiarity with Kanban boards and Jira.

Desired Competencies:

  • Big 4 accounting experience preferred.
  • Strong knowledge of cybersecurity principles and organisational requirements relevant to confidentiality, integrity, availability, authentication, and non-repudiation.
  • Ability to apply security governance, risk, and control principles.
  • Proficiency in automation and data analytics tools (e.g., Excel, Tableau, Alteryx, and Power-BI).
  • Ability to apply critical reading/thinking skills to identify systemic issues from analysing testing data.
  • Ability to facilitate small to medium sized group meetings and communicate complex ideas.
  • Agile working methodology experience.

Lead Security Control Assessor employer: GCS

As a Lead Security Control Assessor at our company, you will thrive in a dynamic and collaborative work culture that prioritises innovation and employee growth. We offer competitive benefits, including professional development opportunities and a commitment to work-life balance, all within a vibrant location that fosters creativity and teamwork. Join us to make a meaningful impact while advancing your career in the ever-evolving field of information security.
G

Contact Detail:

GCS Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Lead Security Control Assessor

✨Tip Number 1

Familiarise yourself with the specific security frameworks mentioned in the job description, such as NIST 800-53 and ISO 27001. Understanding these standards will not only help you in interviews but also demonstrate your commitment to the role.

✨Tip Number 2

Showcase your experience with cloud security controls, particularly in AWS and Azure. Be prepared to discuss specific projects where you've implemented or assessed these controls, as this will highlight your relevant expertise.

✨Tip Number 3

Emphasise your leadership skills by preparing examples of how you've successfully led teams in control assessments. Highlight any methodologies you've developed or improved, especially those that involve automation and data-driven testing techniques.

✨Tip Number 4

Network with professionals in the cybersecurity field, especially those with Big 4 accounting experience. Engaging with industry peers can provide insights into the role and may even lead to referrals, increasing your chances of landing the job.

We think you need these skills to ace Lead Security Control Assessor

Security Control Assessment
Cloud Security Testing
Risk Identification and Management
Control Testing Methodologies
Quality Assurance
Documentation Skills
Root Cause Analysis
Stakeholder Communication
Team Leadership
Agile Methodology
Data-Driven Testing Techniques
Automation Skills
Knowledge of NIST 800-53
Familiarity with ISO 27001/27002
Experience with AWS and Azure
Proficiency in Data Analytics Tools
Relationship Management
Critical Thinking Skills
Experience with Jira and Kanban Boards

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in IT Audit and Information Security control assessments. Emphasise your leadership skills and any specific projects related to cloud security controls.

Craft a Strong Cover Letter: In your cover letter, explain why you are passionate about security control assessment. Mention your familiarity with industry standards like NIST 800-53 and how your experience aligns with the job requirements.

Showcase Technical Skills: Clearly outline your technical skills related to security tools and cloud environments. If you have experience with automation and data analytics tools, make sure to include that as well.

Prepare for Interviews: Be ready to discuss your approach to leading control testing teams and how you ensure quality assurance in documentation. Prepare examples of how you've used stakeholder feedback to improve processes.

How to prepare for a job interview at GCS

✨Showcase Your Technical Expertise

Make sure to highlight your experience with security controls, especially in cloud environments like AWS and Azure. Be prepared to discuss specific tools you've used, such as Sailpoint or Rapid7, and how they contributed to your previous roles.

✨Demonstrate Leadership Skills

As a Lead Security Control Assessor, you'll be leading teams. Share examples of how you've successfully managed teams in the past, focusing on your approach to collaboration and communication with stakeholders.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you identified control deficiencies and how you addressed them, including the root causes and your recommendations for improvement.

✨Familiarise Yourself with Industry Standards

Brush up on key frameworks like NIST 800-53 and ISO 27001. Be ready to discuss how these standards influence your testing methodologies and how you ensure compliance in your assessments.

Lead Security Control Assessor
GCS
G
  • Lead Security Control Assessor

    Nottingham
    Full-Time
    43200 - 72000 £ / year (est.)

    Application deadline: 2027-07-16

  • G

    GCS

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>