Full-Time Information Security Control Assurance Manager
Experian is hiring a remote Full-Time Information Security Control Assurance Manager. The career level for this job opening is Manager and is accepting Ruddington, United Kingdom based applicants remotely. Read complete job description before applying.
Experian
Job Title
Posted
Career Level
Career Level
Locations Accepted
Share
Job Details
As an Information Security Control Assurance Manager, you will lead a team evaluating security controls across on-premise and cloud systems to ensure risk mitigation and regulatory compliance. You will guide and supervise the team in security control testing for design, implementation, and operational effectiveness.
You will operate in an agile environment, ensuring assessment quality via testing, automation, and collaboration with multiple partners. This UK-based, remote position reports to the Information Security Risk & Control Director.
Summary of Primary Responsibilities
- Oversee information security control testing following Experian's risk management framework.
- Oversee a team of security control testers assessing information systems, platforms, and operating procedures.
- Design repeatable testing methodologies, including automated cloud environment testing.
- Ensure well-planned control tests with risk identification, sampling, control selection, testing methods, and reporting criteria.
- Compile management reports, analyses, and presentations describing risks, controls, and deficiencies to multiple partners.
- Enhance testing program efficiency via measurable goals and standardized materials.
What your background is
- Experience managing IT audit or Information Security control assessment teams.
- Experience performing IT Audit or Information Security control assessments, with specific experience testing cloud security controls.
- Professional certifications such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, or equivalent.
- Knowledge of industry standards and frameworks: NIST 800-53, ISO 27001/27002, CIS Controls, COBIT.
- Experience using current automated and manual methods for evaluating security controls on-premise and in cloud environments.
- Knowledge of security controls provided by tools like Sailpoint, Rapid7, Wiz.io, MS Defender.
- Experience with cloud security controls in AWS and Azure environments.
- Experience using automation, data-driven testing techniques and generative AI to improve control assurance.
- Big 4 accounting experience.
- Experience creating queries and reports using RSA Archer and ServiceNow.
Benefits
- Great compensation and discretionary bonus plan
- Core benefits (pension, healthcare, sharesave scheme, and more)
- 25 days annual leave, 8 bank holidays, 3 volunteering days
- Additional annual leave purchase option