We are seeking a Cyber Controls Specialist to support the design, implementation and ongoing improvement of cybersecurity controls... Read more
We are seeking a Cyber Controls Specialist to support the design, implementation and ongoing improvement of cybersecurity controls across a complex technology and business environment. The role will help ensure that security practices align with internal policies, recognised industry frameworks and applicable regulatory requirements. You will work closely with technology, risk, audit and business stakeholders to assess control effectiveness, identify weaknesses and coordinate practical remediation plans.
Key responsibilities include maintaining and reviewing the cybersecurity control framework; mapping controls to relevant standards and regulatory obligations; supporting risk and control self-assessments; and gathering evidence for internal and external assurance activities. You will monitor remediation actions, challenge control owners where appropriate and prepare clear reports on control performance, exceptions, trends and emerging risks. The role will also contribute to the development of security policies, procedures, standards and guidance, ensuring that documentation remains accurate, accessible and aligned with operational practices. Where required, you may support control testing across areas such as identity and access management, vulnerability management, security monitoring, incident response, data protection, third-party risk and operational resilience.
The successful candidate will have experience in cybersecurity governance, risk and controls, internal assurance or a related discipline, with a sound understanding of frameworks such as ISO 27001, NIST, COBIT or CIS Controls. You should be confident interpreting technical and business information, assessing evidence and translating complex security matters into concise recommendations for varied audiences. Strong analytical, organisational and communication skills are essential, along with the ability to manage multiple priorities and build effective relationships with stakeholders at all levels. Relevant professional certifications, such as CISA, CRISC, CISSP, ISO 27001 Lead Implementer or Lead Auditor, are desirable. A proactive, detail-oriented approach and a commitment to continuous improvement will be highly valued.
Read lessLondon, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria