Staff Security Engineer (Control Assurance)
Core
Independent verification and effectiveness evaluation of Security, Privacy, AI Governance, and Compliance controls as the Second Line of Defense.
Role type
Staff Security Engineer (Control Assurance)
Builds
Enterprise-wide Controls Assurance Program, automated control monitoring systems, and integrated governance frameworks.
Domain
E-commerce, Information Security, GRC, AI Governance
Deliverable
production ML models | dashboards & analysis | infrastructure
Required skills
Control testing and validation, policy compliance verification, risk analysis, control maturity measurement, global framework mapping (NIST, ISO), data-driven verification logic design, API-based data collection, IAM/Cloud/Endpoint/Infrastructure system understanding, cross-functional collaboration with Security Engineering and Legal.
Preferred skills
ISO27001/NIST/SOC2/PCI DSS/GDPR framework experience, CISA/CISM/CRISC/CISSP certifications, Python/SQL/Power BI/Tableau data analysis, control monitoring program building, security engineering operations experience, GRC solution usage.
Technologies
NIST CSF, ISO 27001, NIST SP 800-53, SOC2, PCI DSS, GDPR, CCPA, Python, SQL, Power BI, Tableau, IAM, Cloud, Endpoint, Infrastructure
Responsibilities
Establish and operate the enterprise Controls Assurance Program; perform control testing and evidence collection; verify compliance with policies, standards, and regulations; analyze control gaps and recommend improvements; verify implementation results and residual risks; design and define requirements for automated control monitoring systems; collaborate with development teams to implement control monitoring functions; define control metrics and KPIs/KRIs; analyze risk trends and recurring control issues; map and tailor global security frameworks to the organization.
Seniority
Staff, hands-on IC with strategic oversight