Security Assurance Specialist (Ref: 198074)

Forsyth Barnes

Deutschland

Hybrid

EUR 90,000 - 120,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Forsyth Barnes is seeking a Security Assurance Specialist to provide independent oversight of information security controls across a retail, distribution and marketing environment in Dubai. The role verifies design, implementation and evidence, translating findings into clear conclusions for risk owners and governance.

You will work with technical teams and GRC colleagues to substantiate remediation, assess residual risk and help move remediation from project-based to ongoing business-as-usual

Qualifications

  • Experience in information security assurance and IT risk.
  • Ability to assess whether security controls are suitably designed, implemented and operating as intended.
  • Familiarity with ISO/IEC 27001 and NIST CSF concepts.
  • Strong analytical and written communication skills.

Responsibilities

  • Develop risk-based assurance plans for priority controls and readiness milestones.
  • Review control design against policies, standards and assurance frameworks.
  • Test implementation and operating effectiveness when history exists.
  • Record auditable working papers linking risks, controls, actions, evidence and conclusions.
  • Escalate material deficiencies through governance channels.
  • Contribute assurance input to consolidated security reporting and risk dashboards.
  • Assess controls across identity management, vulnerability management, network security and resilience.

Skills

Information security
IT risk
GRC
Risk assessment
Analytical skills
Written communication
Independence
Stakeholder engagement

Education

CISA
CISM
CISSP
CRISC
ISO/IEC 27001 Lead Auditor

Job description

Job Description

The Security Assurance Specialist will provide structured, independent oversight of information security controls across a diverse retail, distribution and marketing environment. The role will examine whether controls are appropriately designed, implemented and supported by reliable evidence, then translate findings into clear conclusions for risk owners and governance stakeholders.


Success in this position means bringing consistency and challenge to remediation assessment while keeping recommendations practical and proportionate to risk. Working across technical teams, business stakeholders and GRC colleagues, you will help validate corrective actions, assess residual exposure and strengthen the organisation’s transition from project-based remediation into repeatable business-as-usual assurance.


Based in Dubai, the role will contribute to assessments covering security governance, technology controls and operational safeguards. Your work will support readiness activity, improve traceability between risks and controls, and provide senior stakeholders with dependable insight into the state of security assurance.



Key Responsibilities


  • Develop risk-based assurance plans covering priority security controls, remediation commitments and readiness milestones.

  • Review control design against internal policies, standards, risk expectations and applicable assurance frameworks.

  • Test implementation and operating effectiveness where sufficient operating history is available.

  • Examine evidence for accuracy, completeness, relevance, ownership and alignment to the control being assessed.

  • Record structured working papers and maintain an auditable link between risks, controls, actions, evidence and conclusions.

  • Challenge incomplete, outdated or inconclusive submissions and define the additional evidence required.

  • Issue concise assurance findings that distinguish control gaps, evidence weaknesses and residual-risk considerations.

  • Engage action owners constructively while preserving the independence and objectivity of assurance activity.

  • Reassess corrected controls and confirm whether remediation addresses the underlying weakness rather than only the immediate symptom.

  • Escalate material, recurring or systemic deficiencies through the appropriate governance channels.

  • Contribute assurance input to consolidated security reporting, risk dashboards and management updates.

  • Assess control areas including identity and access management, privileged access, segregation of duties, vulnerability management, network security and operational resilience.

  • Review relevant safeguards for supplier security, data protection, security operations and technology change activity.

  • Support security readiness assessments during hypercare, transformation releases and other significant implementation phases.

  • Apply recognised practices from ISO/IEC 27001:2022, NIST CSF and internal information security requirements consistently.

  • Coordinate with GRC, security, technology and business teams to embed a sustainable business-as-usual assurance model.



Requirements


  • Several years of experience in information security assurance, technology risk, IT audit, internal controls or GRC.

  • Demonstrated ability to assess whether security controls are suitably designed, implemented and operating as intended.

  • Strong working knowledge of risk-based assurance principles and control testing methodologies.

  • Practical understanding of ISO/IEC 27001 and NIST Cybersecurity Framework concepts.

  • Experience evaluating technical and governance evidence and forming balanced, well-supported conclusions.

  • Knowledge of identity and access management, privileged access, segregation of duties, vulnerability management, network protection, resilience, supplier risk, data protection and security operations.

  • Ability to work effectively with control owners, engineers, auditors, risk professionals and senior stakeholders.

  • Excellent analytical skills, professional judgement and written communication capability.

  • Confidence working independently, organising multiple assessments and maintaining accurate assurance records.

  • Experience supporting ERP, SAP or complex technology transformation programmes would be advantageous.

  • Exposure to retail, distribution, marketing services or other multi-site, customer-facing operating environments would be beneficial.

  • Relevant certification such as CISA, CISM, CISSP, CRISC, ISO/IEC 27001 Lead Auditor or Lead Implementer is preferred.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber security consulting services expert (all gernders)
Cyber security consulting services expert (all gernders)

Merck Gruppe • Darmstadt

On-site
USD 70,069 - 116,782
Senior Analyst IT Governance, Risk & Compliance
Senior Analyst IT Governance, Risk & Compliance

Mekdam Technical Services • Germany

On-site
EUR 90,000 - 120,000
Cyber Security Specialist
Cyber Security Specialist

NDT Global • Blankenloch

Remote
EUR 80,000 - 120,000
Cybersecurity System Engineer / Technical Expert
Cybersecurity System Engineer / Technical Expert

NeuVerge-Tron GmbH • München

On-site
EUR 90,000 - 130,000
Manager Interne Kontrollsysteme (IKS) und Assurance (m/w/d)
Manager Interne Kontrollsysteme (IKS) und Assurance (m/w/d)

SmartRecruiters, Inc. • Köln

On-site
EUR 90,000 - 130,000
Security Assurance Specialist , AWS Compliance and Security Assurance EMEA
Security Assurance Specialist , AWS Compliance and Security Assurance EMEA

Amazon Web Services (AWS) • Berlin

On-site
EUR 90,000 - 150,000
Director of Cyber Defense / Security Engineering Lead / Threat Operations Director
Director of Cyber Defense / Security Engineering Lead / Threat Operations Director

Unity - Inovações Disruptivas • Germany

On-site
EUR 120,000 - 170,000
Information Security Manager
Information Security Manager

MAM Gruppe Limited • Hamburg

On-site
EUR 70,000 - 110,000
Security Assurance Solutions Architect, AWS Security Assurance Services
Security Assurance Solutions Architect, AWS Security Assurance Services

Amazon Web Services (AWS) • München

On-site
EUR 95,000 - 140,000
Senior IT Security Consultant (m/f/d) new
Senior IT Security Consultant (m/f/d) new

beON consult GmbH • Kiel

On-site
EUR 60,000 - 90,000
Attractive financial compensation
Comprehensive development opportunities
Healthy work-life balance
+2