IT – Cyber Security Controls Assessor

Finezi Inc.

Oakland (CA)

Hybrid

USD 90,000 - 125,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Client laptop provided
Flexible working hours

Job summary

A leading IT compliance firm is seeking a Cyber Security Controls Assessor to evaluate enterprise IT security against regulatory standards. The role is hybrid, requiring some onsite presence, and focuses on compliance reviews and security control assessments. Candidates should have a BA/BS degree and at least 3 years of IT experience, along with an active certification such as CISA or CISSP. Strong analytical, communication skills, and experience with security frameworks are essential.

Qualifications

  • 3+ years of IT experience, ideally in IT security or risk management.
  • Must hold at least one active certification like CISA or CISSP.
  • Utility industry experience preferred.
  • Ability to manage multiple assessments simultaneously.
  • Strong analytical and communication skills.

Responsibilities

  • Conduct thorough IT compliance reviews and control assessments.
  • Evaluate compliance with NIST and SOX regulations.
  • Provide remediation recommendations to address control gaps.
  • Identify control gaps, vulnerabilities, and risks.
  • Recommend sustainable remediation plans.
  • Partner with control owners to maintain updated documentation.
  • Support compliance leadership as needed.

Skills

Attention to detail
Analytical skills
Communication skills
Ability to manage multiple assessments

Education

BA/BS in Computer Science, Business, or equivalent

Tools

Excel

Job description

IT – Cyber Security Controls Assessor (Hybrid | Oakland, CA)
About the Role

We are seeking a detail-oriented Cyber Security Controls Assessor to support enterprise-wide IT compliance and security control assessments. This role focuses on evaluating General Computer Controls (GCCs) and ensuring compliance with regulatory and internal standards.

This is a hybrid position with expected onsite presence on a monthly basis (subject to change as needed).

  • Deep understanding of security frameworks and IT assessment processes
  • Strong attention to detail
  • Experience performing structured control assessments
  • Perform multi-platform IT control assessments (applications, databases, OS, middleware, monitoring tools, business processes)
  • Validate and interpret control evidence
  • Execute IT compliance reviews aligned with:
  • NIST SP800-53 / SP800-115
  • SOX
  • NERC CIP
  • Identify control gaps, vulnerabilities, and risks
  • Recommend sustainable remediation plans
  • Partner with control owners to maintain updated documentation
  • Support compliance leadership as needed
Qualifications

Required:

  • BA/BS in Computer Science, Business, or equivalent experience
  • 3+ years of IT experience (IT security or IT risk management preferred)
  • Experience with Excel (worksheets, formulas, reporting)
  • Ability to manage multiple assessments simultaneously
  • Strong analytical and communication skills

Must Have At Least One Active Certification:

  • CISA
  • CISSP
  • CRISC
  • CIA
  • CCNA
  • Utility industry background
  • Experience with SOX and/or NIST SP800-53
  • Familiarity with COBIT, ITIL frameworks
Additional Certifications (Nice to Have):
  • CISM
  • CEH
  • PMP
  • ITIL
  • CCNP / MCSE
  • General Computing Controls (GCCs)
  • IT risk & compliance assessment
  • Security frameworks & regulatory standards
  • Control gap analysis
  • Strong project management capabilities

💻 Client laptop will be provided (supplier laptop required temporarily if needed via Citrix access).

If you are a Bay Area-based IT Security professional with strong assessment and compliance experience, we would love to connect!

📩 Apply or reach out directly to learn more.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

Infobahn Softworld Inc • Oakland (CA)

Hybrid
USD 85,000 - 120,000
Cyber Security Controls Assessor
Cyber Security Controls Assessor

Heyer Expectations LLC • Oakland (CA)

On-site
USD 90,000 - 120,000
Hybrid Cyber Security Controls Auditor - IT Risk
Hybrid Cyber Security Controls Auditor - IT Risk

Heyer Expectations LLC • Oakland (CA)

On-site
USD 90,000 - 120,000
Cyber Security Controls Assessor – Hybrid (GCCs/SOX)
Cyber Security Controls Assessor – Hybrid (GCCs/SOX)

Finezi Inc. • Oakland (CA)

On-site
USD 90,000 - 125,000
Client laptop provided
Flexible working hours
Controls Consultant Associate
Controls Consultant Associate

Jobtailor • Pennsylvania

On-site
USD 60,000 - 90,000
CyberSecurity Specialist - GRC
CyberSecurity Specialist - GRC

ReqRoute,Inc • Phoenix (AZ)

Hybrid
USD 90,000 - 130,000
Security Control Assessor
Security Control Assessor

38North Security • Washington

Remote
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

Boston Government Services, LLC (BGS) • United States

Remote
USD 110,000 - 150,000
Health Insurance
Dental Insurance
Vision Insurance
+4
Security Control Assessor
Security Control Assessor

electro soft • Washington

On-site
USD 155,000 - 165,000
Cybersecurity Technology Architect V
Cybersecurity Technology Architect V

The Corporate • Oakland (CA)

Hybrid
USD 210,000 - 260,000