At a Glance
- Tasks: Lead certification audits and manage assurance activities to ensure compliance with security standards.
- Company: Join Vocalink Limited, a leader in secure payment solutions.
- Benefits: Competitive salary, professional development, and a dynamic work environment.
- Other info: Opportunity for career growth and collaboration with diverse teams.
- Why this job: Make a real impact on cybersecurity and help shape industry standards.
- Qualifications: Experience with security frameworks and strong analytical skills required.
The predicted salary is between 60000 - 75000 £ per year.
Main purpose of the role
The newly established 1st Line Control Office function within Vocalink Limited (VLL) is seeking a Manager to join the Control Testing, Certification and Assurance team. This role will be responsible for managing certifications, certification audits and other assurance activities, including conducting control testing to support the retention of VLL’s certifications across multiple frameworks and the delivery of assurance obligations. The position requires a broad understanding of security and technology control frameworks, with hands‑on experience across standards such as ISO27001, ISO22301, PCIDSS, PCIPIN, SWIFTCSP, ISAE3000, etc. The successful candidate must have proven expertise in analysing and assessing control design, implementation and operating effectiveness against at least one of these standards, ensuring compliance and identifying gaps. The role will also include coordinating and managing external audits to ensure smooth execution, therefore experience of this is required.
Key Responsibilities
- Maintain certification and assurance related documentation.
- Prepare the organisation for annual certification audits.
- Support the assessment and validation of controls and processes against a variety of security standards and obligations.
- Support the team in the management of VLL certifications, e.g. ISO27001 and PCIDSS.
- Support the team in the management of other assurance activities, e.g. ISAE3000.
- Conduct periodic testing of key and non‑key controls in line with the Control Testing Methodology.
- Evaluate compliance with internal policies, standards, regulatory requirements and customer obligations.
- Prepare and review control testing documentation, including test procedures, results, and identified gaps.
- Ensure timely escalation of control deficiencies and support remediation tracking.
- Create and quality‑assure reports and team outputs.
Team Leadership, Collaboration & Stakeholder Engagement
- Supervise and mentor junior team members (e.g. Senior Analysts), providing guidance on certification requirements, assurance requirements, testing execution and quality assurance.
- Support the Vice President and Director of Certification and Assurance in the development and maintenance of the annual Control Testing, Certification and Assurance plan.
- Build and maintain strong partnerships with Control and Process Owners and Operators to ensure efficient and effective execution of certification maintenance and assurance activities.
- Contribute to reporting for governance forums, including dashboards, thematic reviews, and trend analysis.
Governance & Continuous Improvement
- Support the development and refinement of certification management, assurance/control testing processes, standards, tools and methodologies.
- Contribute to the maturity of the 3‑Lines‑of‑Defence model and promote a culture of proactive risk management.
- Stay informed on emerging risks, regulatory changes, certification changes and industry best practices with a focus on cybersecurity risks.
Knowledge, Skills and Expertise
Experience
- Experience working with security‑related control frameworks and standards (e.g. ISO27001, NIST, CRI, or PCI‑DSS).
- Experience conducting security‑related audits/reviews and managing/co‑ordinating external audits including certification audits.
- Ability to assess control design and operating effectiveness in complex environments and to identify control gaps and improvement opportunities.
- Experience resolving certification and assurance issues.
- Knowledge and experience of all areas of security.
- Strong investigative and analytical experience (e.g. enquiry, scanning, analysis, interviewing, testing), problem‑solving and decision‑making skills.
- Experience collaborating cross‑functionally to identify and implement good practice security audit management and assurance processes.
- Excellent communication and stakeholder engagement skills.
Qualifications
- Certifications such as ISO27001 Lead Auditor, CISA, CISM, CISSP, PCISSCISA, CRISC, or equivalent are desirable.
Preferred Skills & Attributes
- Bachelor’s degree in Computer Science, Cyber Security, Information Technology or a related field.
- Good knowledge of security controls and IT general controls across a variety of technologies and environments.
- Proficiency in Microsoft Office Suite (MSWord, MSExcel, MSAccess and MSPowerPoint).
- Strong organisational skills with the ability to prioritise and manage multiple tasks.
- Self‑starter with a continuous improvement mindset and a collaborative approach.
- Experience creating presentations for business discussions and reporting.
- Experience of Risk Management / GRC related technologies and toolsets.
- Experience working in cross‑functional large projects with dispersed teams.
Manager, 1st Line Controls Testing, Certification and Assurance employer: Mastercard
Vocalink Limited offers an exceptional work environment for the Manager, 1st Line Controls Testing, Certification and Assurance role, fostering a culture of collaboration and continuous improvement. Employees benefit from comprehensive training opportunities, competitive remuneration, and a commitment to professional growth, all while working in a dynamic setting that prioritises cybersecurity and compliance excellence. Located in a vibrant area, VLL provides a unique chance to engage with industry-leading standards and frameworks, making it an ideal employer for those seeking meaningful and rewarding careers.
StudySmarter Expert Advice🤫
We think this is how you could land Manager, 1st Line Controls Testing, Certification and Assurance
✨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at events. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Tailor your answers to show how your experience with security frameworks aligns with their needs.
✨Tip Number 3
Practice makes perfect! Do mock interviews with friends or use online platforms to get comfortable discussing your skills and experiences related to control testing and assurance.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!
We think you need these skills to ace Manager, 1st Line Controls Testing, Certification and Assurance
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the role of Manager, 1st Line Controls Testing. Highlight your experience with security frameworks like ISO27001 and PCIDSS, and showcase any relevant certifications you hold. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about certification and assurance, and how your background makes you a perfect fit for our team. Don’t forget to mention any hands-on experience with audits and control testing.
Showcase Your Analytical Skills:In this role, analytical skills are key. When writing your application, include examples of how you've assessed control designs or identified gaps in compliance. We love seeing real-world applications of your expertise!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us that you’re keen on joining our team at StudySmarter!
How to prepare for a job interview at Mastercard
✨Know Your Standards
Make sure you have a solid understanding of the security and technology control frameworks mentioned in the job description, like ISO27001 and PCI-DSS. Brush up on your knowledge of these standards and be ready to discuss how you've applied them in past roles.
✨Prepare for Scenario Questions
Expect scenario-based questions that assess your ability to evaluate control design and effectiveness. Think of specific examples from your experience where you identified gaps or improved processes, and be ready to explain your thought process.
✨Showcase Your Leadership Skills
Since this role involves supervising and mentoring junior team members, be prepared to discuss your leadership style. Share examples of how you've guided teams in the past, especially in relation to certification and assurance activities.
✨Engage with Stakeholders
Demonstrate your excellent communication skills by discussing how you've built relationships with Control and Process Owners. Prepare to share instances where your stakeholder engagement led to successful outcomes in certification maintenance or assurance activities.