Information Security Assurance Expert
Core
Perform in-depth assurance activities, evaluate and maintain information security risk posture, and drive consistency in control design, testing, and audit readiness for Avaloq's services and platforms.
Role type
Information Security Assurance Expert (IC)
Builds
Security control frameworks, risk assessment processes, and audit readiness for financial services platforms
Domain
Financial technology / Information Security / Risk Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ISO 27005 risk assessment, technical and organizational control determination, regulatory requirement mapping, audit preparation and evidence collection, security control framework knowledge (ISO 27001, NIST CSF, SOC2), infrastructure and cloud technology understanding, automated testing of security controls
Preferred skills
Automation and scripting for assurance activities, experience with ISO 27001 LA/LI, CRISC, CISA, CISM, or CISSP certifications
Technologies
ISO 27001, NIST CSF, SOC2, CCM, OSPAR, ISO 27005
Responsibilities
Determine and document Technical IT security controls mapped to internal frameworks; Perform asset-based information security risk assessments; Identify and assess residual risks; Track and translate legal/regulatory requirements into actionable obligations; Execute repeatable and automated testing of security control effectiveness; Lead or support audit preparation and response activities
Seniority
Mid-Senior, hands-on IC