- Carry out Cyber Assurance initiatives independently while ensuring quality and timely delivery.
- Perform risk-based control testing across security domains using security frameworks (e.g., ISO 27001, NIST CSF, CIS) to determine control effectiveness and provide implementable recommendations.
- Review and validate evidence provided by Technology teams as part of control assurance activities, ensuring completeness and compliance with regulatory and industry standards.
- Collaborate with Security and Technology teams to drive remediation of identified control gaps and ensure implementation of cyber security safeguards to improve security posture across the organisation.
- Drive compliance programs such as GDPR, NIS2 and PCI DSS etc., including gap assessments, evidence reviews, and reporting.
- Drive reporting across different Cyber Assurance initiatives, including reporting to Security Leadership and Cyber/Technology governance committees.
- Identify, drive, and implement opportunities for process improvement across various initiatives within the Cyber Assurance team.
- Build strong relationships with the stakeholders and lead meetings with Technology and Business Process teams.
- Stay updated on evolving regulatory requirements and industry best practices and provide insights to management to continuously enhance the organisation’s assurance posture.
- Strong written, verbal communication and presentation skills, working with all levels of seniority and disciplines within the organisation.
- Able to build solid working relationships with internal and external stakeholders
- At least one professional qualification such as CompTIA Security+, CISSP, CISM, CRISC or equivalent.
- IT control testing, control assurance and IT risk management
- Experience of assessing security controls across a variety of technologies and products, recommending improvements where necessary