Assistant Manager – Cybersecurity Controls Testing Analyst – Global

Company: Deloitte
Apply for the Assistant Manager – Cybersecurity Controls Testing Analyst – Global
Location: Manchester
Job Description:

Overview

In this role, you validate the design and operating effectiveness of security controls as part of the Controls Assurance Testing Programme, using a mix of automated and manual testing. You translate regulatory and policy requirements into measurable control objectives and drive evidence-based assessments. You collaborate with risk, security, engineering, and operations teams to ensure controls are well evidenced and remediation is effective. You contribute to reporting, governance, and ongoing improvement of testing methodologies in a hybrid, global environment.

Pay / Benefits

  • hybrid working policy
  • global, matrixed organisation
  • focus on wellbeing and development
  • world-class development and learning opportunities
  • purpose-driven culture
  • employee support and inclusion

Responsibilities

  • Execute automated and manual control testing within Deloitte’s Controls Assurance Testing Programme
  • Translate regulatory, policy, and industry requirements into measurable control objectives
  • Collaborate with technical teams to understand control design and operation across identity, endpoints, network, and cloud
  • Identify automation opportunities using platform integrations and data to support continuous assurance
  • Develop and maintain automated testing logic, queries, control mappings, and evidence requirements
  • Perform manual testing where automation is not feasible and collect evidence
  • Assess whether controls meet policy and standard intents and document findings
  • Validate remediation activities and track deficiencies through to closure
  • Maintain testing documentation and remediation records in ServiceNow IRM
  • Collaborate with Cyber Risk, IT Risk, Cyber Security, Engineering, and Operational teams to ensure accuracy and consistency
  • Support evolution of testing methodologies, reporting, and quality standards
  • Contribute to KPI development, dashboards, and assurance insights
  • Stay current with emerging technologies and regulatory standards

Key requirements

  • Bachelor’s degree in information systems, Computer Science, Cybersecurity, Engineering, or related field
  • Relevant certifications such as ISO 27001 Lead Auditor, CISA, CRISC, Security+ or similar desirable
  • Proven experience in information security, IT risk management, compliance, or controls testing
  • Experience conducting compliance testing or control assessments against standards (ISO 27001, NIST, CIS Controls, SOC 2)
  • Knowledge of automated control testing tools (e.g., Qualys, Tenable, Rapid7)
  • Experience with GRC/ITSM platforms (ServiceNow, Archer, MetricStream) for control/remediation tracking
  • Experience with Microsoft security tooling (Defender for Endpoint, Intune, Sentinel) and/or KQL is advantageous
  • Experience in a large, global, matrixed organisation is a plus
  • Collaboration and teamwork
  • Strong analytical and problem-solving abilities
  • Attention to detail and evidence-based approach
  • Qualys
  • Tenable
  • Rapid7

…

Posted: October 1st, 2026