Overview
As a Cyber Security Controls Specialist within the engineering team, you will lead the articulation and validation of security controls for audits and assessments. You translate technical controls into clear evidence and narratives, ensuring controls are well-documented, measurable, and continuously improved. You collaborate across teams to manage risk, support regulators and customers, and shape control design and operation. This role offers impact across audits, governance, and modernization of assurance processes in a global financial environment.
Pay / Benefits
- healthcare
- retirement planning
- paid volunteering days
- wellbeing initiatives
- hybrid/digital-first work arrangement
- diversity and inclusion initiatives
Responsibilities
- Control Testing & Validation: validate control effectiveness and drive improvements; ensure accurate documentation and measurable controls for audits
- Audit & Assessment: lead responses to audits and assessments with clear, technically accurate evidence
- Technical Translation: convert complex security concepts into plain language for auditors and risk managers
- Risk Management: identify, assess, record, and mitigate cyber risks through robust control design
- Continuous Improvement: identify gaps in controls and documentation and drive design and measurement improvements with control owners
Key requirements
- Audit & Controls experience in highly regulated global organisations
- Strong understanding of security technologies, threats, and frameworks; cloud knowledge
- Ability to guide first line of defence security engineering teams in evidence and controls
- Excellent communication skills to explain technical concepts to non-technical audiences
- Risk management knowledge and experience translating risk into actionable controls
- Experience with common GRC tooling platforms to capture risks and issues
- Preferred: automation of controls monitoring, analysis and evidence collection
- Certifications such as CISSP, CISA, CRISC or equivalent are desirable
- excellent communication
- ability to challenge assertions with facts
- collaboration across teams
- security technologies and frameworks
- cloud security concepts
- control evidencing and measurement
…
