At a Glance
- Tasks: Join our team to execute control testing and enhance risk management practices.
- Company: Vocalink Limited, a critical national infrastructure company regulated by the Bank of England.
- Benefits: Competitive salary, professional development, and a chance to work in a dynamic environment.
- Other info: Collaborative culture with opportunities for career growth and continuous improvement.
- Why this job: Make a real impact on security controls that affect millions of transactions daily.
- Qualifications: Experience in control testing and risk management; certifications like CISA or ISO 27001 are a plus.
The predicted salary is between 45000 - 55000 £ per year.
Requirements
- Experience in control testing, or assurance, and risk management within security in a regulated environment.
- Good investigative and analytical experience (e.g. enquiry, scanning, analysis, interviewing, testing), problem-solving, and decision-making skills.
- Good understanding of control frameworks and standards (e.g., NIST, CRI, ISO and PCI-DSS).
- Ability to assess control design and operating effectiveness in complex environments and to identify control gaps and improvement opportunities.
- Good communication and stakeholder engagement skills.
- Professional certifications such as CISA, CRISC, ISO 27001 or equivalent is desirable.
- (Desirable) Bachelor’s degree in Information Technology, Computer Science, Cyber Security, or related field.
- (Desirable) Good knowledge of security controls and IT general controls across platforms such as UNIX, HP Nonstop, and Windows.
- (Desirable) Proficiency in Microsoft Office Suite (MS Word, MS Excel, MS Access and MS PowerPoint).
- (Desirable) Strong organisational skills with the ability to prioritise and manage multiple tasks.
- (Desirable) Self-starter with a continuous improvement mindset and a collaborative approach.
What the job involves
- The newly created Vocalink Control Office function is seeking a Senior Analyst within the 1st Line Control Testing team to support the delivery of control testing activities across Security control domains, within Vocalink Limited (VLL).
- VLL is a Bank of England regulated, Critical National Infrastructure (CNI) company that enables the payments of 90% of salaries, 70% of utility bills, most ATM transactions and every cheque cleared in the UK.
- This role plays a key part in embedding a strong control environment by executing control testing, identifying control gaps, and supporting continuous improvement in risk management practices.
- Support periodic testing of key and non-key controls in accordance with the Control Testing Methodology.
- Assess control design and operating effectiveness against internal policies, standards, regulatory requirements, and customer obligations.
- Timely collection of control testing evidence from relevant Control Owners to support scheduled testing activities.
- Prepare clear and accurate test documentation, including test procedures, execution results, and supporting evidence.
- Identify and document control deficiencies, ensuring timely escalation to the Manager and supporting remediation follow-up activities.
- Monitoring the control testing mailbox to ensure timely review and response to incoming queries and submissions.
- Work closely with 1st Line teams to obtain evidence, clarify control processes, and support accurate testing outcomes.
- Liaise with 2nd Line Security partners and Internal Audit as directed, ensuring transparency and alignment with control testing activities.
- Contribute to the preparation of management information, dashboards, and thematic analysis for governance forums.
- Support control owners by providing observations on control effectiveness and contributing to discussions on remediation approaches.
- Adhere to established control testing standards, procedures, and documentation requirements.
- Provide input on opportunities to streamline testing activities, improve efficiency, and enhance the consistency of outcomes.
- Maintain awareness of relevant regulatory requirements, emerging risks, and industry practices, particularly within the security domains.
- Contribute to strengthening the 3 Lines of Defence model by embedding robust and transparent testing practices.
- Abide by Mastercard’s security policies and practices.
- Ensure the confidentiality and integrity of the information being accessed.
- Report any suspected information security violation or breach.
- Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
Controls Testing Senior Analyst (1st Line Security) employer: Mastercard
Vocalink Limited offers an exceptional work environment for a Controls Testing Senior Analyst, where you will play a pivotal role in enhancing security controls within a critical national infrastructure setting. With a strong emphasis on employee growth, collaborative culture, and adherence to regulatory standards, Vocalink provides opportunities for continuous improvement and professional development, making it an ideal employer for those seeking meaningful contributions to the UK's payment systems.
StudySmarter Expert Advice🤫
We think this is how you could land Controls Testing Senior Analyst (1st Line Security)
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who works in security. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! If you’ve got experience in control testing or risk management, make sure to highlight that in conversations. Share specific examples of how you've identified control gaps or improved processes – it’ll make you stand out!
✨Tip Number 3
Don’t forget to follow up! After interviews or networking events, shoot a quick thank-you email. It shows you’re keen and keeps you fresh in their minds. Plus, it’s a great chance to reiterate your interest in the role.
✨Tip Number 4
Apply through our website! We’ve got loads of opportunities waiting for you. By applying directly, you can ensure your application gets the attention it deserves. Plus, it’s super easy to keep track of your applications!
We think you need these skills to ace Controls Testing Senior Analyst (1st Line Security)
Some tips for your application 🫡
Tailor Your CV:Make sure your CV reflects the skills and experiences that match the job description. Highlight your control testing experience and any relevant certifications like CISA or CRISC. We want to see how you fit into our world!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about security and how your background makes you a great fit for the role. Don’t forget to mention your problem-solving skills and ability to engage stakeholders.
Showcase Your Analytical Skills:In your application, give examples of your investigative and analytical experience. Whether it's through previous roles or projects, we love to see how you've tackled complex problems and identified control gaps in the past.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates. Plus, it shows you’re keen to join our team!
How to prepare for a job interview at Mastercard
✨Know Your Control Frameworks
Make sure you brush up on your knowledge of control frameworks like NIST, ISO, and PCI-DSS. Be ready to discuss how you've applied these standards in your previous roles, as this will show your understanding of the regulatory environment.
✨Show Off Your Analytical Skills
Prepare examples that highlight your investigative and analytical experience. Think about specific situations where you identified control gaps or improved processes, and be ready to explain your thought process during the interview.
✨Communicate Clearly
Since good communication is key for this role, practice articulating your thoughts clearly and concisely. Use the STAR method (Situation, Task, Action, Result) to structure your responses, especially when discussing past experiences.
✨Engage with Stakeholders
Demonstrate your stakeholder engagement skills by preparing to discuss how you've collaborated with different teams in the past. Highlight any experiences where you successfully liaised with control owners or worked alongside audit teams to achieve common goals.