Security Control Assessment Specialist
Permanent - Full TimeJob Overview
We are seeking an experienced Security Control Assessment Specialist to independently test the design and operating effectiveness of Trading Technologies’ enterprise cybersecurity controls. This role plans and executes control assessments end to end, documents findings with clear supporting evidence, and partners with control owners and the TT Security team to design practical remediations. The role also contributes to the continuous improvement of the control environment itself, strengthening how controls are defined, evidenced and monitored, and automating control testing where possible.
Key Responsibilities
- Plan and execute independent tests of enterprise cybersecurity controls across TT’s technology estate, with a high degree of autonomy over scoping, methodology, sampling and scheduling.
- Assess both the design and the operating effectiveness of controls, combining evidence review and control owner walkthroughs with hands-on technical validation of configurations, logs, identity and access data, and cloud environments.
- Document findings clearly and defensibly, setting out the condition, criteria, cause, risk and impact, and rating them consistently against TT’s risk criteria.
- Partner with control owners and TT Security to design workable remediations, then validate closure through retesting rather than accepting assertion alone.
- Track findings and remediation plans through to closure, escalating overdue or inadequately addressed items where necessary.
- Build and maintain automated and continuous control monitoring so that control health is visible between formal assessment cycles.
- Contribute to the continuous improvement of the control framework itself, refining control definitions, testing procedures, evidence requirements and the annual assessment plan.
- Map the control environment to SOC 2, ISO 27001 and NIST frameworks, identifying gaps, duplication and opportunities to test once and satisfy multiple obligations.
- Manage relationships with internal stakeholders and control owners, setting expectations, communicating requirements clearly, and holding a firm, evidence-based position when findings are challenged.
- Support external audits and customer assessments by providing tested, reliable control evidence.
Skills, Knowledge and Expertise
Essential Skills & Experience
- 8 to 10 years of IT experience, including at least 5 years focused on information security.
- Professional certification required: CISM, CISSP, CISA, CRISC or equivalent.
- Demonstrable experience designing and executing security control tests and producing findings and workpapers that withstand audit scrutiny.
- Strong working knowledge of cybersecurity controls and frameworks, including SOC 2, ISO 27001, the NIST Cybersecurity Framework and NIST SP 800-53.
- Technical depth across identity and access management, cloud infrastructure (AWS certification is a plus), endpoint and network security, logging and monitoring, vulnerability management and secure development practices.
- Experience automating control testing or building continuous control monitoring, using scripting, queries, APIs or GRC platform automation.
- Familiarity with GRC platforms such as OneTrust, Vanta, Drata, ServiceNow IRM or similar.
- Exceptional spoken and written English, with the ability to explain technical requirements and findings clearly to both engineers and senior stakeholders.
- Confidence and diplomacy to challenge control owners constructively and to hold a position under pressure when the evidence supports it.
- Ability to work autonomously, manage a portfolio of concurrent assessments and deliver to deadline with minimal supervision.
- Strong attention to detail and follow-through.
Desirable Skills & Experience
- Experience in financial services, capital markets or another regulated industry is highly regarded.
Make Your Resume Now