Live opening · Posted 11 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
The core responsibilities for the job include the following:
Cyber Security Posture Measurement and KPI Framework:
Define, maintain, and enhance the cybersecurity posture KPI framework covering all major security domains, including: Network security, endpoint security, identity and access management, cloud security, SOC and detection capabilities, data security, and end-to-end third-party identity and access controls
Ensure KPIs measure control effectiveness and risk reduction, not just tool deployment or activity.
Periodically review and recalibrate KPIs to align with: Risk appetite, threat landscape, Regulatory expectations.
Independent Control Testing and Validation:
Own the organization-wide control testing program for cybersecurity controls.
Plan and execute risk-based testing of security controls across all security tools, all security domains, and on-prem, cloud, and hybrid environments.
Validate:
Design effectiveness (Are controls designed correctly? ).
Operating effectiveness (Are controls working as intended? ).
Identify control gaps, weaknesses, and systemic issues.
Ensure control testing outcomes are repeatable, auditable, and defensible.
Cyber Risk and Scorecard Integration
Feed control testing results, KPI outcomes, and trends into the enterprise cyber risk scorecard.
Translate technical control effectiveness into risk language that senior leadership can understand.
Highlight high-risk areas, deteriorating control trends, and concentration of risk across domains
Support risk acceptance and treatment discussions with factual data.
Reporting and Executive Communication
Prepare periodic cyber posture reports for CISO, senior management, and risk and audit committees (as required):
Present concise insights on overall security posture, key weaknesses and exposures, progress on remediation, and maturity improvement.
Ensure reporting enables decision-making, not just awareness.
Audit and Regulatory Support:
Act as the primary infosec point for internal audits, external audits, and regulatory assessments related to control effectiveness.
Coordinate evidence collection for tested controls.
Validate remediation of audit findings before closure.
Ensure alignment between audit observations, control testing outcomes, and risk scorecard reporting.
Cross-Functional Collaboration:
Work closely with SOC teams (for detection and response controls), network, endpoint, and cloud security teams, and GRC and risk management teams
Maintain independence from operational execution while ensuring strong collaboration.
Challenge security teams constructively using data and evidence.
Process and Capability Maturity:
Continuously improve assurance and testing methodologies using industry standards such as NIST, CSF, ISO 27001/27002 and COBIT.
Dcloudautomation where feasible in KPI data collection, control testing evidence, reporting, and dashboards; mentor team members involved in assurance and testing activities (if applicable).
Requirements:
10+ years of experience in cybersecurity, with strong exposure to cybersecurity assurance, control testing, and risk and posture measurement.
Experience working in regulated or audit-heavy environments preferred.
Certifications: CISA, CISM, ISO 27001 LA/LI.
Experience
7-11 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.