Experience: 2+ Years
Role: Security Controls
Job Overview
We are looking for a Security Controls professional with strong experience in cybersecurity control assessment, control validation, risk assessment, and security assurance. The role will focus on evaluating the design and effectiveness of security controls across enterprise technology environments and identifying control gaps, risks, and remediation opportunities.
The ideal candidate should have strong technical knowledge of Cryptography, PKI, TLS, DLP, Network Security, and Endpoint Security, along with experience in security assessments, governance, compliance, and control validation.
Key Responsibilities
- Perform security control assessments and validation across enterprise applications, infrastructure, cloud platforms, APIs, and technology environments.
- Evaluate the design and operating effectiveness of cybersecurity controls.
- Identify control gaps, security weaknesses, risks, and opportunities for improvement.
- Conduct risk-based security reviews and cybersecurity risk assessments.
- Assess security controls across key domains including:
- Cryptography & PKI
- TLS / SSL
- Certificate Management
- Data Loss Prevention (DLP)
- Network Security
- Endpoint Security
- Review security configurations and validate adherence to organizational security standards.
- Assess controls related to authentication, authorization, encryption, logging, monitoring, vulnerability management, and data protection.
- Conduct security reviews across applications, APIs, cloud platforms, infrastructure, and modern technology environments.
- Assess cloud security controls across AWS and/or Azure environments.
- Perform security architecture and secure-by-design assessments to identify security gaps.
- Conduct threat modeling, attack surface analysis, and security risk assessments where required.
- Review findings from vulnerability assessments, penetration testing, third-party assessments, and security reviews.
- Validate remediation activities through control re-testing and security verification.
- Develop risk-based recommendations and remediation plans for identified control gaps.
- Support security governance, compliance, audit readiness, and regulatory assessments.
- Prepare security control assessment reports, risk summaries, and management-level reporting.
- Define and track security metrics, KRIs, KPIs, and control effectiveness measures.
- Collaborate with Cybersecurity, Technology, Risk, Compliance, Architecture, Engineering, and Business teams.
- Support continuous improvement of security control frameworks, assessment methodologies, and validation processes.
Required Skills & Experience
- 2+ years of experience in Cybersecurity, Security Controls, Security Assurance, Cyber Risk, IT Risk, Information Security, or a related domain.
- Strong hands-on experience in Security Control Assessment, Control Testing, Control Validation, or Control Effectiveness Reviews.
- Strong technical understanding of:
- Cryptography
- PKI
- TLS / SSL
- Certificate Management
- DLP / Data Loss Prevention
- Network Security
- Endpoint Security
- Experience performing security risk assessments and identifying control gaps.
- Experience assessing security controls across applications, infrastructure, cloud, APIs, and platforms.
- Strong understanding of AWS and/or Azure security controls.
- Knowledge of security frameworks and standards such as NIST CSF, ISO 27001, CIS Controls, OWASP, and MITRE ATT&CK.
- Experience with security configuration reviews and control validation.
- Understanding of identity security, authentication, authorization, encryption, vulnerability management, and security monitoring.
- Experience supporting audit, compliance, governance, and regulatory-driven security assessments.
- Strong analytical, documentation, reporting, and stakeholder management skills.
- Ability to communicate technical security risks and recommendations to both technical and senior management stakeholders.
Good to Have
- Experience with security automation, scripting, data integration, log analysis, or security data pipelines.
- Exposure to penetration testing, red teaming, purple teaming, or adversary simulation.
- Experience with cloud-native and container security.
- Experience in highly regulated industries such as Banking, Financial Services, Insurance, Healthcare, or Government.
- Consulting or advisory experience.
Preferred Certifications
- CISSP
- CISM
- CISA
- CRISC
- CCSP
- CCSK
- Other relevant cybersecurity/security certifications
Education
Bachelors or Masters degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline.