Cybersecurity Control Testing & CRI Maturity Assessor - AVP
Core
Execute independent control testing, CRI Profile maturity assessments, and SDLC security control validation across on-premises and cloud environments for a global financial group.
Role type
Senior IC cybersecurity control testing and assurance specialist
Builds
Validated security controls, maturity ratings, and risk assessments for cloud and on-prem infrastructure
Domain
Financial services / Cybersecurity Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Control design and operating effectiveness testing, CRI Profile maturity assessment, third-party/vendor risk assessment, SDLC security control validation, regulatory compliance knowledge (FFIEC, Basel, GDPR), evidence-based audit procedures
Preferred skills
Prior audit/assurance experience, cloud native services knowledge, NIST/CIS/ISO standards mapping
Technologies
Cloud platforms, CI/CD pipelines, SAST/DAST tools, vulnerability scanners, identity platforms, network infrastructure
Responsibilities
Plan and scope control testing engagements; Test control design and operating effectiveness across identity, network, endpoint, and data protection domains; Perform CRI Profile maturity assessments and gap analysis; Conduct third-party/vendor cybersecurity assessments; Validate SDLC controls including secure design, threat modeling, and change management; Produce assessment documentation and risk reports; Re-test remediated controls to validate closure
Seniority
Senior, hands-on IC
