Principal Analyst, Control Testing, Certification and Assurance (Director Level) in London
Principal Analyst, Control Testing, Certification and Assurance (Director Level)

Principal Analyst, Control Testing, Certification and Assurance (Director Level) in London

London Full-Time 80000 - 120000 £ / year (est.) No home office possible
M

At a Glance

  • Tasks: Lead and manage control testing and certification audits for security standards.
  • Company: Join Vocalink Limited's innovative Control Office team.
  • Benefits: Competitive salary, career growth, and a dynamic work environment.
  • Other info: Opportunity to mentor junior analysts and shape the future of assurance processes.
  • Why this job: Make a real impact in cybersecurity and compliance at a leading tech company.
  • Qualifications: Extensive experience with security frameworks and strong leadership skills required.

The predicted salary is between 80000 - 120000 £ per year.

The newly created 1st Line Control Office function within Vocalink Limited (VLL) is seeking a Principal Analyst (Director-level equivalent), to join the Control Testing, Certification and Assurance team. This senior technical role is for an experienced technical subject matter expert who will be responsible for leading and managing Certifications, Certification Audits, and other Assurance activities including conducting control testing to drive the retention of VLL's certifications across multiple frameworks and the delivery of assurance obligations to its customers and Regulators.

This position requires a deep and broad understanding of security and technology control frameworks, with hands-on experience across standards such as: ISO 27001, ISO 22301, PCI DSS, PCI PIN, SWIFT CSP, ISAE 3000 etc. The successful candidate must have proven expertise in analysing and assessing control design, implementation and operating effectiveness against these standards, ensuring compliance and identifying gaps. The role also involves end-to-end management of external audits, requiring strong coordination skills and experience in audit readiness and stakeholder engagement.

The role has a significant emphasis on PCI DSS, so the successful candidate must have extensive experience in understanding and testing against PCI DSS requirements, and managing all aspects of the PCI DSS external audit process.

Key Responsibilities
  • Leadership & Strategy: Lead and manage external audits for technical standards, e.g. PCI DSS and PCI PIN. Support the Vice President and Director of Certification and Assurance in the development and maintenance of the annual Control Testing, Certification and Assurance plan. Support and deputise for the Director of Certification and Assurance in the discharge of their responsibilities, as required. Provide strategic input into the evolution and continuous improvement of Certification and Assurance team processes and procedures.
  • Certification and Assurance Responsibilities: Maintain certification related documentation. Prepare and lead the organisation for annual certification audits. Lead the assessment and validation of controls and processes against a variety of security standards and obligations. Lead the team on the management of certifications, e.g., ISO27001, PCI DSS and assurance activities, e.g., ISAE3000. Conduct periodic testing of key and non-key controls in line with the Control Testing Methodology. Evaluate compliance with internal policies, standards, regulatory requirements, and customer obligations. Prepare and review control testing documentation, including test procedures, results, and identified gaps. Ensure timely escalation of control deficiencies and support remediation tracking. Create and quality-assure reports and team outputs.
  • Team Leadership, Collaboration & Stakeholder Engagement: Supervise and mentor junior team members (Senior Analysts and Managers), providing guidance on certification requirements, assurance requirements, testing execution and quality assurance. Support the team Director in delivering the Certification and Assurance plan. Maintain close working relationships with Control and Process Owners and Operators to operate certificate maintenance and assurance activities efficiently and effectively. Contribute to reporting for governance forums, including dashboards, thematic reviews, and trend analysis.
  • Governance & Continuous Improvement: Support the development and refinement of certification management, Assurance activities and control testing processes, standards, tools, and methodologies. Contribute to the maturity of the 3 Lines of Defence model and promote a culture of proactive risk management. Stay informed on emerging risks, regulatory changes, certification changes and industry best practices with a focus on cybersecurity risks.
Knowledge, Skills and Expertise (technical / role specific)
  • Strong understanding and experience of working with control frameworks and standards (e.g. ISO27001, NIST, CRI, or PCI DSS).
  • Strong understanding and experience of conducting security related audits/reviews and managing/coordinating external audits including certification audits.
  • Experience of resolving varied and complex certification and assurance issues.
  • Knowledge and experience of all areas of security and IT general controls across a variety of platforms and environments.
  • Proven experience in control testing or assurance within security in a regulated environment.
  • Strong investigative and analytical experience (e.g. enquiry, scanning, analysis, interviewing, testing), problem-solving, and decision-making skills.
  • Experience collaborating cross-functionally to identify and implement good practice security audit management and assurance processes.
  • Ability to assess control design and operating effectiveness in complex environments and to identify control gaps and improvement opportunities.
  • Excellent communication and stakeholder engagement skills.
  • Experience of managing and coaching junior team members.
  • Strong organisational skills with the ability to prioritise and manage multiple tasks.
Qualifications
  • Certifications such as ISO27001, CISA, CISM, CISSP, PCI SSC ISA, CRISC, or equivalent is desirable.
Preferred Skills & Attributes
  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, or a related field.
  • Experience engaging with senior leadership at the Executive level and above.
  • Proficiency in data analytics and Microsoft Office Suite (MS Word, MS Excel, MS Access and MS PowerPoint).
  • Self-starter with a continuous improvement mindset and a collaborative approach.
  • Experience creating presentations for business discussions and reporting.
  • Experience of Risk Management / GRC related technologies and toolsets.
  • Experience working in cross-functional large projects with dispersed teams.

Principal Analyst, Control Testing, Certification and Assurance (Director Level) in London employer: Mastercard

Vocalink Limited offers an exceptional work environment for the Principal Analyst role, fostering a culture of collaboration and continuous improvement. Employees benefit from comprehensive professional development opportunities, competitive compensation, and a commitment to maintaining high standards in security and compliance. Located in a dynamic sector, VLL empowers its team members to lead impactful projects while ensuring a supportive atmosphere that values innovation and excellence.
M

Contact Detail:

Mastercard Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Principal Analyst, Control Testing, Certification and Assurance (Director Level) in London

✨Tip Number 1

Network like a pro! Reach out to your connections in the industry, especially those who work at Vocalink or similar companies. A friendly chat can sometimes lead to insider info about job openings or even a referral.

✨Tip Number 2

Prepare for interviews by brushing up on your knowledge of PCI DSS and other relevant frameworks. We recommend creating a cheat sheet with key points and examples from your experience that showcase your expertise.

✨Tip Number 3

Showcase your leadership skills! Be ready to discuss how you've mentored others or led teams in past roles. This is crucial for a director-level position, so have some solid examples at the ready.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team.

We think you need these skills to ace Principal Analyst, Control Testing, Certification and Assurance (Director Level) in London

ISO 27001
PCI DSS
PCI PIN
ISAE 3000
Control Testing
Audit Management
Stakeholder Engagement
Analytical Skills
Problem-Solving Skills
Communication Skills
Team Leadership
Regulatory Compliance
Data Analytics
Continuous Improvement Mindset
Risk Management

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the role of Principal Analyst. Highlight your experience with control frameworks like PCI DSS and ISO 27001, and showcase any relevant certifications. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're the perfect fit for our Control Testing, Certification and Assurance team. Share specific examples of your past experiences that relate to the job description.

Showcase Your Leadership Skills: Since this is a director-level position, don’t forget to highlight your leadership experience. Talk about how you've mentored junior team members or led successful audit processes in the past. We love seeing strong leadership qualities!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you're keen on joining our team at StudySmarter!

How to prepare for a job interview at Mastercard

✨Know Your Standards Inside Out

Make sure you have a solid grasp of the key control frameworks mentioned in the job description, especially PCI DSS. Brush up on the requirements and be ready to discuss your hands-on experience with these standards during the interview.

✨Showcase Your Leadership Skills

As this role involves leading audits and mentoring junior team members, prepare examples that highlight your leadership experience. Think about times when you've successfully managed a team or led a project, and be ready to share those stories.

✨Prepare for Technical Questions

Expect technical questions related to control testing and assurance activities. Review your past experiences with security audits and be prepared to explain how you assessed control design and effectiveness. Use specific examples to demonstrate your expertise.

✨Engage with Stakeholders

Since stakeholder engagement is crucial for this role, think of instances where you've effectively communicated with various stakeholders. Be ready to discuss how you maintained relationships and ensured smooth collaboration across teams.

Principal Analyst, Control Testing, Certification and Assurance (Director Level) in London
Mastercard
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>