Assistant Manager - Cybersecurity Controls Testing Analyst – Global

Deloitte (UK)

Alabama

Hybrid

USD 86,000 - 119,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Deloitte UK seeks a Cybersecurity Controls Testing Analyst to support the Controls Assurance Testing Programme by validating the design and operating effectiveness of security controls across identity, endpoint, network, infrastructure, cloud, and security operations.

You will translate regulatory requirements into measurable control objectives and collaborate with technical teams to ensure robust evidence and testing coverage.

Qualifications

  • Bachelor’s degree in information systems, Computer Science, Cybersecurity, Engineering, or a related field.
  • Certifications such as ISO 27001 Lead Auditor, CISA, CRISC, Security+ are desirable.
  • Proven experience in information security, IT risk, audits, compliance, or controls testing.
  • Experience with regulatory standards (ISO 27001, NIST, CIS, SOC 2) and automated control testing tools.
  • Knowledge of ServiceNow or similar ITSM/GRC platforms for tracking control and remediation.

Responsibilities

  • Support the Controls Assurance Testing Programme with automated and manual testing.
  • Translate regulatory requirements into measurable control objectives for technology enviroments.
  • Collaborate with technical teams across identity, endpoints, networks, cloud and security operations.
  • Develop automated testing logic and evidence requirements for repeatable testing.
  • Validate remediation activities and track deficiencies through closure.

Skills

Cybersecurity experience
GRC / compliance knowledge
Controls testing experience
Regulatory / policy understanding

Education

Bachelor's degree in information systems, Computer Science, Cybersecurity, Engineering, or related
ISO 27001 Lead Auditor
CISA
CRISC
Security+

Tools

Qualys
Tenable
Rapid7
ServiceNow
Archer
MetricStream
Defender for Endpoint
Intune
Sentinel
KQL

Job description

Birmingham, Cambridge, Manchester, Milton Keynes, Reading

Business Line

Enabling Functions

Job Type

Permanent / FTC

Date published

23-Sep-2026

25263

Connect to your Industry

Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.

Connect to your career at Deloitte

Deloitte drives progress. Using our vast range of expertise, we help our clients' become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.

What brings us all together at Deloitte?It’show we approach the thousands of decisions we make everyday. How we behave, our beliefs and our attitudes. In other words: our values. Whatever we do, whereverwe arein the world, welead the way,serve with integrity, take care of each other ,fosterinclusion, andcollaborate for measurable impact. These five shared values lead every decision wemake and action we take, guiding us to deliver impact how and where it mattersmost .

Connect to your opportunity

As a Cybersecurity Controls Testing Analyst, you will support DT's Controls Assurance Testing Programme by validating the design and operating effectiveness of security controls through a combination of automated and manual testing. Working closely with the Cyber Compliance Manager and technical stakeholders, you will help translate regulatory, policy, and industry-standard requirements into measurable controls, identify opportunities to automate testing through data and system integrations, and perform evidence-based assessments where automation is not feasible. You will also support the validation of remediation activities, helping drive control deficiencies through to closure and contributing to reporting and governance activities.

The ideal candidate will bring a combination of technical cyber security experience and GRC or compliance expertise. You will have hands-on experience in areas such as cyber operations, infrastructure, cloud, security engineering, or security administration, and the technical acumen to understand how controls are designed, implemented, and evidenced in practice. Experience supporting compliance, audit, controls assurance, or risk management activities is essential, along with the ability to assess whether technical controls effectively satisfy regulatory, policy, and industry-standard requirements.

Key Responsibilities
  • Support the execution of DT's Controls Assurance Testing Programme through a combination of automated and manual control testing activities.
  • Translate regulatory, policy, and industry standard requirements into measurable control objectives, helping define how compliance requirements should be implemented and evidenced within technology environments.
  • Partner with technical teams to understand the design and operation of security controls across identity, endpoint, network, infrastructure, cloud, and security operations domains.
  • Identify opportunities to automate control testing through integrations with security and technology platforms, leveraging system data wherever possible to support continuous assurance and reduce manual testing effort.
  • Develop and maintain automated testing logic, technical validation queries, control mappings, and evidence requirements to support repeatable and scalable testing activities.
  • Perform manual control effectiveness testing where automation is not feasible, including evidence collection, validation, sampling, and assessment against defined testing criteria.
  • Assess whether implemented controls meet the intent of applicable policies, standards, and compliance requirements, documenting findings and testing outcomes.
  • Validate remediation activities submitted by control owners, reviewing technical and procedural evidence to determine whether identified deficiencies have been effectively addressed.
  • Track control deficiencies and remediation activities through to closure, proactively engaging with stakeholders and escalating overdue actions where appropriate.
  • Maintain control testing documentation, findings, remediation records, and workflow activities within ServiceNow IRM.
  • Collaborate with DT Cyber Risk, IT Risk Management, Cyber Security, Engineering, and Operational teams to ensure control testing activities are technically accurate, well evidenced, and consistently executed.
  • Support the Compliance Manager in evolving and maturing the Controls Assurance Testing Programme, including the development of testing methodologies, automation capabilities, reporting, and quality standards.
  • Contribute to management reporting, KPI development, dashboard production, and assurance insights for compliance and risk stakeholders.
  • Stay current with emerging technologies, cyber security practices, control assurance methodologies, and relevant regulatory and industry standards.
Connect to your skills and professional experience

Do you possess the following?

  • Bachelor’s degree in information systems, Computer Science, Cybersecurity, Engineering, or a related field.
  • Relevant certifications such as ISO 27001 Lead Auditor, CISA, CRISC, Security+, or similar are desirable
  • Proven professional experience in information security, IT risk management, internal audit, compliance, or controls testing roles.
  • Experience conducting compliance testing, audits, or control assessments against internal or external standards (e.g., ISO 27001, NIST, CIS Controls, SOC 2).
  • Working knowledge of automated control testing tools (e.g., Qualys, Tenable, Rapid7, or similar platforms).
  • Experience with GRC or ITSM platforms such as ServiceNow, Archer, MetricStream, or similar for control and remediation tracking.
  • Experience with Microsoft security tooling (e.g., Defender for Endpoint, Intune, Sentinel) and/or KQL query writing is advantageous.
  • Experience working in a large, global, matrixed organisation is an advantage.
Connect to your business -Enabling Functions

Collaboration is central to everything we do at Deloitte. From IT to HR, marketing and more, our teams help to support the wider business in everything they do. Bringing your individual skills and specialist knowledge, you can make a far-reaching impact. Come join us.

Personal independence

Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to a number of audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints (e.g., in relation to any financial interests and employment relationships). This can mean that you and your "Immediate Family Members" are not permitted to hold certain financial interests (shares, funds, bonds etc.) with audit clients of the firm, and also prohibitions on certain employment relationships (e.g., you are not permitted to hold a secondary employment role with SEC audit clients of the firm whilst being employed by the firm). The recruitment team will provide further detail as you progress through the recruitment process or you can contact the Independence team upon request.

Connect with your colleagues

"Everyone at Deloitte builds relationships with their peers and puts in effort to get to know one another, making the work more enjoyable." – Deloitte Employee

Our hybrid working policy

You’ll be based in one of our UK offices with hybrid working.

At Deloitte we understand the importance of balancing your career alongside your home life.That’s why we’ll support you to work flexibly through our hybrid working policy. Depending on the requirements of your role, you’ll have the opportunity to work in your local office, virtual collaboration spaces, client sites and remotely. You’ll get the chance to meet face to face when needed, while you collaborate and learn from colleagues, share your experiences, and build the relationships that will fuel your career and prioritise your wellbeing. Please check with your recruiter for the specific working requirements that may apply for your role.

Our commitment to you

Making an impact is more than just what we do: it’s why we’re here. So we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.

We want you. The true you. Your own strengths, perspective and personality. So we’re nurturing a culture where everyone belongs, feels supported and heard, and is empowered to make a valuable, personal contribution. You can be sure we’ll take your wellbeing seriously, too. Because it’s only when you’re comfortable and at your best that you can make the kind of impact you, and we, live for.

Your expertise is our capability, so we’ll make sure it never stops growing. Whether it’s from the complex work you do, or the people you collaborate with, you’ll learn every day. Through world-class development, you’ll gain invaluable technical and personal skills. Whatever your level, you’ll learn how to lead.

Connect to your next step

A career at Deloitte is an opportunity to develop in any direction you choose. Join us and you’ll experience a purpose you can believe in and an impact you can see. You’ll be free to bring your true self to work every day. And you’ll never stop growing, whatever your level .

Discover more reasons to connect with us, our people and purpose-driven culture at deloitte.co.uk/careers

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Consultant, Technology Implementation, Third Party Management, Extended Enterprise, Cyber
Senior Consultant, Technology Implementation, Third Party Management, Extended Enterprise, Cyber

Deloitte (UK) • Alabama

Hybrid
USD 95,000 - 135,000
Hybrid working London/Manchester
Cloud Engineer, Forensic & Financial Crime Technology Advisory and Data Analytics
Cloud Engineer, Forensic & Financial Crime Technology Advisory and Data Analytics

Deloitte (UK) • Alabama

Hybrid
USD 119,000 - 185,000
Manager, Digital Regulation Assurance
Manager, Digital Regulation Assurance

Deloitte (UK) • Alabama

Hybrid
USD 106,000 - 146,000
Senior Analyst, Client Due Diligence (CDD), Quality, Risk and Security Services
Senior Analyst, Client Due Diligence (CDD), Quality, Risk and Security Services

Deloitte (UK) • Alabama

Hybrid
USD 60,000 - 86,000
AI Engineer, Forensic & Financial Crime Technology Advisory and Data Analytics
AI Engineer, Forensic & Financial Crime Technology Advisory and Data Analytics

Deloitte (UK) • Alabama

Hybrid
USD 119,000 - 172,000
Hybrid work model
Professional development
Global Tax & Legal - Project and Program Manager
Global Tax & Legal - Project and Program Manager

Deloitte (UK) • Alabama

Hybrid
USD 53,000 - 86,000
Manager - Platform Engineer, Deloitte Digital
Manager - Platform Engineer, Deloitte Digital

Deloitte (UK) • Alabama

Hybrid
USD 79,000 - 146,000
Assistant Director, Financial Due Diligence, Financial Services
Assistant Director, Financial Due Diligence, Financial Services

Deloitte (UK) • Alabama

Hybrid
USD 73,000 - 113,000
Hybrid working policy
Travel opportunities
Digital Marketing Consultant/Senior Consultant, Deloitte Digital
Digital Marketing Consultant/Senior Consultant, Deloitte Digital

Deloitte (UK) • Alabama

Hybrid
USD 95,000 - 140,000
Manager, Technology Sourcing & Procurement, Technology Sourcing and Commercial Management (TSCM), Technology Strategy and Transformation
Manager, Technology Sourcing & Procurement, Technology Sourcing and Commercial Management (TSCM), Technology Strategy and Transformation

Deloitte (UK) • Alabama

Hybrid
USD 86,000 - 119,000
Hybrid working