Cyber Security Controls Tester (Contractor)

Cyberfort Group

United Kingdom

Remote

GBP 92,000 - 148,000

Part time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Cyberfort Group is seeking an experienced Cyber Security Controls Tester to support a large-scale assurance programme in a highly regulated environment. You will work remotely with security architects, risk teams and stakeholders to assure control design, implementation and operation, ensuring alignment with standards such as ISO 27001, NIST CSF and NIST 800-53.

Responsibilities include evaluating control effectiveness, drafting testing plans, evidence collection, and delivering remediation

Qualifications

  • Experience testing security controls in complex environments.
  • Knowledge of ISO27001, NIST CSF, NIST 800-53, CIS Controls.
  • Experience auditing/assurance against frameworks.
  • Experience reviewing network configurations, IAM, encryption, endpoint controls.
  • Familiarity with HLDs, LLDs, and Controls Catalogues.
  • Knowledge of GDPR, PCI DSS, ICO guidance.
  • Understanding UK government security policies (HMG, NCSC).
  • Ability to produce test plans and assurance reports.
  • Strong stakeholder management and communication.
  • Analytical and evidence-based approach.

Responsibilities

  • Evaluate security controls to meet standards in HLDs/LLDs and Controls Catalogues.
  • Test controls against ISO 27001, NIST CSF, NIST 800-53.
  • Review policies, network configs, firewall rules, IAM, encryption and endpoint controls.
  • Apply testing methodologies with documentation reviews and evidence-based assurance.
  • Define testing scope with risk teams and security architects.
  • Assess design and operating effectiveness of controls.
  • Provide remediation guidance for weaknesses.
  • Support improvements to policies and security controls.
  • Document testing activities, findings and remediation.
  • Produce assurance reports and present findings to stakeholders.

Skills

Security controls testing
ISO 27001
NIST CSF
NIST 800-53
CIS Controls
IAM controls
Encryption controls
Endpoint security
HLDs/LLDs
Stakeholder management
Policy review

Tools

Azure
AWS
GRC tools

Job description

Location: Fully Remote (UK)
Contract Type: Contract
Contract Length: Immediate start until February 2027
Security Clearance: Active SC Clearance required and must be verifiable

About the Opportunity

We are seeking an experienced Cyber Security Controls Tester to support a large-scale security assurance programme within a highly regulated environment. This is an excellent opportunity for a contractor with a strong background in security controls testing, assurance and risk management, particularly within central government or wider public sector environments.

Working remotely alongside security architects, risk teams and technical stakeholders, you will provide independent assurance over security controls, helping to ensure that controls are appropriately designed, implemented and operating effectively in line with recognised security standards and frameworks.

What You'll Be Doing
  • Evaluating the effectiveness of security controls within the identified environment to ensure they meet the standards defined within supporting documentation, including High-Level Designs (HLDs), Low-Level Designs (LLDs) and Controls Catalogues.

  • Testing controls against recognised security frameworks and standards, including ISO 27001, NIST CSF and NIST 800-53.

  • Reviewing policies, procedures, network configurations, firewall rules, identity and access management controls, and other technical and procedural security controls.

  • Applying recognised controls testing methodologies, including documentation reviews, walkthroughs, sampling and technical verification activities.

  • Agreeing testing scope and plans with stakeholders, risk teams and security architects to ensure assurance activity addresses key security concerns.

  • Assessing both the design effectiveness and operating effectiveness of implemented security controls.

  • Providing pragmatic remediation guidance and recommendations to address identified control weaknesses.

  • Supporting improvements to policies, processes and security controls to strengthen the overall security posture of services and environments.

  • Maintaining clear documentation of testing activities, evidence collected, findings and remediation recommendations.

  • Producing comprehensive assurance reports outlining security posture, findings, risks and recommendations.

  • Presenting findings to technical and non-technical stakeholders and agreeing remediation actions where required.

  • Working closely with risk and security architecture teams to ensure controls testing supports wider risk management and assurance objectives.

What We're Looking For

You will be a detail-oriented cyber security professional with experience assessing and validating security controls across complex technical environments. You'll be comfortable engaging with both technical and business stakeholders and have the ability to provide clear, evidence-based assurance and practical recommendations.

Essential Skills & Experience
  • Demonstrable experience testing and evaluating the effectiveness of technical, procedural and physical security controls within complex environments.

  • Strong working knowledge of security control frameworks including ISO 27001, NIST CSF, NIST 800-53 and CIS Controls.

  • Experience conducting controls testing, assurance or audit activities against recognised security frameworks.

  • Hands-on experience reviewing and testing:

    • Network configurations

    • Firewall rulesets

    • Identity and Access Management (IAM) controls

    • Encryption controls

    • Endpoint security controls

  • Familiarity with security design and controls documentation including HLDs, LLDs and Controls Catalogues.

  • Experience applying recognised testing methodologies, including documentation reviews, walkthroughs, sampling and evidence-based assurance activities.

  • Strong understanding of relevant legislation and compliance requirements, including GDPR, PCI DSS and ICO guidance.

  • Working knowledge of HMG and NCSC security policies, standards and guidance.

  • Ability to produce clear, well-structured test plans, assurance reports and remediation recommendations.

  • Strong stakeholder management and communication skills, with experience engaging risk teams, security architects and business stakeholders.

  • Strong analytical and problem-solving skills, with a methodical approach to identifying, evidencing and reporting security control weaknesses.

Desirable Skills & Certifications
  • CISA certification.

  • ISO 27001 Lead Auditor or Lead Implementer certification.

  • CRISC certification.

  • CompTIA Security+ or similar security assurance-related certification.

  • Experience working within central government or public sector environments.

  • Experience supporting governance, risk and compliance (GRC) programmes.

  • Exposure to cloud security assurance across Azure and AWS environments.

  • Experience supporting IT Health Checks (ITHCs), penetration testing exercises or security accreditation activities.

Please note: Active SC Clearance is a mandatory requirement for this role and must be current and capable of being validated.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Controls Tester (Contractor)
Cyber Security Controls Tester (Contractor)

Cyberfort • Stone Cross

On-site
GBP 65,000 - 90,000
Cyber Security Controls Tester (Assurance)
Cyber Security Controls Tester (Assurance)

Sanderson Government & Defence • City Of London

On-site
GBP 140,000 - 160,000
Remote Cyber Security Controls Tester - SC Cleared
Remote Cyber Security Controls Tester - SC Cleared

Cyberfort • Stone Cross

On-site
GBP 65,000 - 90,000
Security Tester | Contract (12 Months+) | SC Clearance Required (Active/Lapsed) | Inside IR35
Security Tester | Contract (12 Months+) | SC Clearance Required (Active/Lapsed) | Inside IR35

WeDoTech • West of England

On-site
GBP 92,000 - 129,000
Security Architect (Contractor) Cyber Security Consultant
Security Architect (Contractor) Cyber Security Consultant

Cyberfort Group • United Kingdom

Remote
GBP 111,000 - 185,000
Remote Cyber Security Controls Tester - SC Cleared
Remote Cyber Security Controls Tester - SC Cleared

Cyberfort Group • United Kingdom

Remote
GBP 92,000 - 148,000
Cyber Security Risk Consultant
Cyber Security Risk Consultant

Sanderson Government & Defence • United Kingdom

Remote
GBP 70,000 - 100,000
Remote Cyber Security Controls Tester — Assurance Expert
Remote Cyber Security Controls Tester — Assurance Expert

Sanderson Government & Defence • City Of London

On-site
GBP 140,000 - 160,000
Cyber Security Consultant
Cyber Security Consultant

Investigo • England

Hybrid
GBP 60,000 - 80,000
Structured career development
Support for certifications like CISSP, ISO27001
Mentoring and regular reviews
Cyber Security Consultant
Cyber Security Consultant

Xcede Recruitment Solutions • Greater London

Hybrid
GBP 70,000 - 100,000