Controls Consultant Associate

Jobtailor

Pennsylvania

On-site

USD 60,000 - 90,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a security-focused analyst to join our team in Pennsylvania. You will review IT processes and control documentation, conduct risk assessments, and provide outsourced information security advisory services.

Responsibilities include assisting in developing internal control policies, training junior staff, delivering client reports, and supporting business development activities. Travel is limited to <10%.

Qualifications

  • Bachelor's degree or equivalent in a related field.
  • Experience or training in information security controls is preferred.
  • Familiarity with PCI, NIST, ISO and CIS frameworks helpful.

Responsibilities

  • Provide control analysis for clients by reviewing and analyzing IT process and control documentation.
  • Conduct sample testing and information security risk assessments.
  • Provide outsourced information security advisory services.
  • Participate in BCP/DR/IR Table-Top exercises.
  • Support client services including risk assessments, controls-based assessments, and OISA or equivalent consulting services.
  • Assist in developing and implementing internal control policies and procedures.
  • Provide direction, train, and delegate work to interns as needed.
  • Write and deliver timely client reports.
  • Conduct client interviews to understand processes and controls and present observations.
  • Assist Seniors, Managers, and Directors with client relationships, practice management, and business development activities

Skills

Information Security Risk Assessment
Control Analysis
Network Penetration Testing
Vulnerability Scanning
Sample Testing
Client Reporting
Business Governance Concepts

Education

Bachelor's degree
Degree in Computer Science/Information Technology/Information Assurance

Tools

Microsoft Outlook
Microsoft Word
Microsoft Excel
Microsoft PowerPoint

Job description

Provide control analysis for clients by reviewing and analyzing IT process and control documentation
Conduct sample testing and information security risk assessments
Provide outsourced information security advisory services
Participate in BCP/DR/IR Table-Top exercises
Support client services including GCR, FAS, risk assessments, controls-based assessments, and OISA or equivalent consulting services
Assist in developing and implementing internal control policies and procedures
Provide direction, train, and delegate work to interns as needed
Write and deliver timely client reports
Conduct client interviews to understand processes and controls and present observations
Assist Seniors, Managers, and Directors with client relationships, practice management, and business development activities

Requirements
  • No experience required
  • 1 year of relevant experience preferred
  • Bachelor's degree required; combination of relevant experience, education, and training may be accepted in lieu of degree
  • Degree in Computer Science, Information Technology, Information Assurance, or related field preferred
  • No certifications or licenses required
  • CISA or equivalent certifications preferred, including GSEC, ECSA, SSCP, CompTIA certifications, CDPSE, CISSP or equivalent, CISM, and CRISC
  • Understanding of relevant control frameworks such as PCI, NIST, ISO, and CIS
  • Proficiency in regulatory methodologies for GLBA, FFIEC, HIPAA, and ACAT internal control programs
  • Knowledge of IT security concepts, security compliance standards, best practices, and procedures
  • Knowledge of general business governance concepts and procedures
  • Familiarity with network penetration testing, social engineering, and vulnerability scanning
  • Knowledge of regulatory guidelines related to internal controls
  • Proficiency in Microsoft Outlook and Office products, including Word, Excel, and PowerPoint
  • Ability to travel less than 10%
Core Competencies

Demonstrates expertise in information security risk assessments, control analysis, and compliance with regulatory frameworks. Proficient in developing internal control policies and delivering client reports while supporting business development activities.

Highest-signal resume keywords
  • Information Security Risk Assessment
  • Control Analysis
  • CISA or Equivalent Certification
  • Knowledge of PCI, NIST, ISO, and CIS Frameworks
  • Proficiency in Microsoft Office Products
ATS Optimization Keywords
Hard Skills
  • Information Security Risk Assessment
  • Control Analysis
  • Internal Control Policy Development
  • Network Penetration Testing
  • Vulnerability Scanning
  • Sample Testing
  • Client Reporting
  • Business Governance Concepts
Soft Skills
  • Client Relationship Management
  • Training and Delegation
  • Communication Skills
Certifications & Qualifications
  • CISA
  • GSEC
  • ECSA
  • SSCP
  • CompTIA Certifications
  • CDPSE
  • CISSP
  • CISM
  • CRISC
Industry Keywords
  • GLBA
  • FFIEC
  • HIPAA
  • ACAT
  • Security Compliance Standards
  • Control Frameworks
Tools & Technologies
  • Microsoft Outlook
  • Microsoft Word
  • Microsoft Excel
  • Microsoft PowerPoint
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Consultant, Financial Services IT Internal Audit
Senior Consultant, Financial Services IT Internal Audit

Jobtailor • Illinois

On-site
USD 95,000 - 130,000
Financial Services IT Internal Audit Manager
Financial Services IT Internal Audit Manager

Jobtailor • Illinois

On-site
USD 110,000 - 170,000
IT Audit, Cybersecurity, Risk Consultant – SOC Focus
IT Audit, Cybersecurity, Risk Consultant – SOC Focus

Jobtailor • Seattle (WA)

On-site
USD 85,000 - 105,000
Third Party Cyber Security Assessor
Third Party Cyber Security Assessor

Jobtailor • Colorado

On-site
USD 90,000 - 130,000
Senior IT Risk and Compliance Engineer
Senior IT Risk and Compliance Engineer

Jobtailor • Hartford (CT)

On-site
USD 120,000 - 180,000
Lead Specialist, General Audit
Lead Specialist, General Audit

Jobtailor • New Jersey

On-site
USD 90,000 - 130,000
Senior Technical Compliance Analyst
Senior Technical Compliance Analyst

Jobtailor • Kansas

On-site
USD 70,000 - 90,000
Cyber GRC Specialist
Cyber GRC Specialist

Jobtailor • Washington

On-site
USD 90,000 - 130,000
Senior IT Audit & GRC Lead (SOX & ITGC)
Senior IT Audit & GRC Lead (SOX & ITGC)

Jobtailor • Kentucky

On-site
USD 110,000 - 165,000
IT Audit Manager
IT Audit Manager

Jobtailor • Colorado

On-site
USD 110,000 - 150,000