Senior Security Control Assurance Lead (Cloud & Risk)

Axiom-Path

Charlotte (NC)

Hybrid

USD 90,000 - 120,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Axiom-Path is seeking a cybersecurity professional in Charlotte, NC, to lead a risk-based security control assurance program. This hybrid role requires collaboration across various teams to mature the security control processes and embed them into cloud systems.

Ideal candidates will have over 8 years in cybersecurity and direct experience in control assurance, with strong knowledge of NIST CSF and cloud environments. Join a dynamic team at a pivotal stage of growth!

Qualifications

  • 8+ years of experience in cybersecurity, IT risk, internal audit, or related work.
  • 3+ years of experience in security control assurance or technology control validation.
  • Strong knowledge of risk-to-control mapping and control testing methodologies.

Responsibilities

  • Build and execute a risk-based security control assurance program.
  • Map risks to controls and validate control effectiveness.
  • Develop repeatable testing and monitoring practices.

Skills

Technical security control assurance
Risk-based control testing
NIST CSF
Control validation
Cloud security (AWS/GCP)
Data protection controls

Education

Bachelor’s degree in Computer Science, Information Security, or related field

Job description

Be Part Of A High-Performing Team:

Join a growing cybersecurity organization within a cloud-first business where security assurance, data protection, and control maturity are critical to enterprise resilience. This team is strengthening its cybersecurity and control governance foundation by aligning controls to NIST, improving risk-to-control mapping, and moving beyond point-in-time evidence collection toward continuous assurance and meaningful control effectiveness testing. The environment is collaborative and cross-functional, requiring close partnership with engineering, product, data, legal, compliance, accounting, finance, and core systems teams.

What's In Store For You:

This is an opportunity to help mature a security control assurance program at a pivotal stage. The role offers the ability to shape how controls are tested, reported, automated, and embedded into cloud, engineering, and business workflows. The position is hybrid in Charlotte, NC, with three days onsite per week. Initial engagement is expected to be six months with potential for contract-to-hire conversion.

How You Will Make An Impact

  • Build, refine, and execute a risk-based security control assurance program across cloud-first enterprise systems.
  • Map risks to controls and validate whether controls are designed and operating effectively.
  • Move control assurance beyond point-in-time evidence gathering by developing repeatable testing, reporting, and monitoring practices.
  • Test IT general controls, security controls, data protection controls, and enterprise / financial controls where applicable.
  • Evaluate controls aligned to NIST CSF, NIST 800-53, PCI DSS, CCPA, CPRA, GDPR, and related state or federal requirements.
  • Partner with development, engineering, data, infrastructure, legal, compliance, accounting, and finance teams to improve control design and control adoption.
  • Assess controls tied to customer and financial data, including access, storage, transmission, retention, encryption, and DLP.
  • Support audit readiness, external audit requests, evidence collection, and regulatory review activities.
  • Develop monthly operational control status reporting and support quarterly or biannual full control testing cycles.
  • Help refine existing control documentation, tooling, and testing processes.

Do you bring proven success in technical security control assurance and risk-based control testing?

  • 8+ years of experience in cybersecurity, IT risk, internal audit, technology assurance, security governance, or related work.
  • 3+ years of direct experience in security control assurance, control testing, or technology control validation.
  • Strong knowledge of risk-to-control mapping and control testing methodologies, including design effectiveness and operating effectiveness testing.
  • Hands-on experience with NIST CSF and NIST 800-53.
  • Experience testing ITGCs, security controls, cloud controls, data protection controls, and enterprise controls.
  • Cloud environment experience; AWS and/or GCP exposure is strongly preferred.
  • Strong understanding of data risk involving customer data, financial data, access controls, encryption, DLP, retention, and secure data handling.
  • Ability to work with engineering and development teams to understand technical control requirements and practical implementation options.
  • Experience supporting audit readiness, evidence requests, control deficiency tracking, and remediation reporting.
  • Ability to translate technical control gaps into business-relevant risk language for leadership.
  • Bachelor’s degree in Computer Science, Information Security, Business Administration, or a related field.
  • Certifications such as CISSP, CISA, CISM, or CRISC are preferred but not required.
  • Utility-sector or highly regulated industry experience is a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assurance Lead #3609144
Security Control Assurance Lead #3609144

Axiom-Path • Charlotte (NC)

On-site
USD 90,000 - 120,000
Senior Lead Control Management Officer – Cloud Platform
Senior Lead Control Management Officer – Cloud Platform

Jobtailor • Arizona

On-site
USD 120,000 - 150,000
Cyber Security Controls Assessor
Cyber Security Controls Assessor

Heyer Expectations LLC • Oakland (CA)

On-site
USD 90,000 - 120,000
Tech Risk & Controls Lead
Tech Risk & Controls Lead

JPMorgan Chase & Co. • New York (NY)

On-site
USD 150,000 - 190,000
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Executive Director, Head of Tech Cyber Data First Line Testing
Executive Director, Head of Tech Cyber Data First Line Testing

SMBC • Charlotte (NC)

On-site
USD 180,000 - 240,000
Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Bank of America • Town of Vermont (WI)

On-site
USD 85,000 - 115,000
Tech Risk & Controls Lead - Continuous Controls Monitoring
Tech Risk & Controls Lead - Continuous Controls Monitoring

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 120,000 - 180,000
Information Security Assurance Analyst I
Information Security Assurance Analyst I

tsys • Alpharetta (GA)

On-site
USD 130,000 - 190,000
Business Control Manager – Technology Risk & Regulatory Lead
Business Control Manager – Technology Risk & Regulatory Lead

Jobtailor • Pennington (NJ)

On-site
USD 120,000 - 180,000