Security Control Assessment Specialist
Summary
An experienced information security professional who independently plans and executes tests of enterprise cybersecurity controls at Trading Technologies, documents defensible findings, drives remediations to closure, and builds automated/continuous control monitoring. Core work spans SOC 2, ISO 27001, NIST frameworks, GRC platforms, and hands-on validation of IAM, cloud (AWS), logging and network
- Plan and execute independent tests of enterprise cybersecurity controls across TT’s technology estate, with a high degree of autonomy over scoping, methodology, sampling and scheduling.
- Assess both the design and the operating effectiveness of controls, combining evidence review and control owner walkthroughs with hands-on technical validation of configurations, logs, identity and access data, and cloud environments.
- Document findings clearly and defensibly, setting out the condition, criteria, cause, risk and impact, and rating them consistently against TT’s risk criteria.
- Partner with control owners and TT Security to design workable remediations, then validate closure through retesting rather than accepting assertion alone.
- Track findings and remediation plans through to closure, escalating overdue or inadequately addressed items where necessary.
- Build and maintain automated and continuous control monitoring so that control health is visible between formal assessment cycles.
- Contribute to the continuous improvement of the control framework itself, refining control definitions, testing procedures, evidence requirements and the annual assessment plan.
- Map the control environment to SOC 2, ISO 27001 and NIST frameworks, identifying gaps, duplication and opportunities to test once and satisfy multiple obligations.
- Manage relationships with internal stakeholders and control owners, setting expectations, communicating requirements clearly, and holding a firm, evidence-based position when findings are challenged.
- Support external audits and customer assessments by providing tested, reliable control evidence.
- 8 to 10 years of IT experience, including at least 5 years focused on information security.
- Professional certification required: CISM, CISSP, CISA, CRISC or equivalent.
- Demonstrable experience designing and executing security control tests and producing findings and workpapers that withstand audit scrutiny.
- Strong working knowledge of cybersecurity controls and frameworks, including SOC 2, ISO 27001, the NIST Cybersecurity Framework and NIST SP 800-53.
- Technical depth across identity and access management, cloud infrastructure (AWS certification is a plus), endpoint and network security, logging and monitoring, vulnerability management and secure development practices.
- Experience automating control testing or building continuous control monitoring, using scripting, queries, APIs or GRC platform automation.
- Familiarity with GRC platforms such as OneTrust, Vanta, Drata, ServiceNow IRM or similar.
- Exceptional spoken and written English, with the ability to explain technical requirements and findings clearly to both engineers and senior stakeholders.
- Confidence and diplomacy to challenge control owners constructively and to hold a position under pressure when the evidence supports it.
- Ability to work autonomously, manage a portfolio of concurrent assessments and deliver to deadline with minimal supervision.
- Strong attention to detail and follow-through.
- Experience in financial services, capital markets or another regulated industry is highly regarded.
- Health & Financial Security:
- Medical, Dental, and Vision coverage
- Time Off & Flexibility:
- Enjoy the best of both worlds: the energy and collaboration of in-person work, combined with the convenience and focus of remote days. This is a hybrid position requiring three days of in-office collaboration per week, with the flexibility to work remotely for the remaining two days. Our hybrid model is designed to balance individual flexibility with the benefits of in-person collaboration, enhanced team cohesion, spontaneous innovation, hands-on mentorship opportunities and strengthens our company culture.
- 21 days of Paid Time Off (PTO) per year, with the option to roll over unused days.
- One dedicated day per year for volunteering.
- Two professional development days per year to allow uninterrupted professional development.
- An additional PTO day is added during milestone anniversary years.
- Robust paid holiday schedule with early dismissal.
- Generous parental leave for all parents (including adoptive parents).
- Work-Life Support & Resources:
- Budget for tech accessories, including monitors, headphones, keyboards, and other office equipment.
- Milestone anniversary bonuses.
- Wellness & Lifestyle Perks:
- Subsidy contributions toward gym memberships and health/wellness initiatives.
- Our Culture:
- Forward-thinking, culture-based organization with collaborative teams that promote diversity and inclusion.
Trading Technologies (TT) is an equal-opportunity employer. Equal employment has been, and continues to be, a required practice at the Company. Trading Technologies’ practice of equal employment opportunity is to recruit, hire, train, promote, and base all employment decisions on ability rather than race, color, religion, national origin, sex/gender orientation, age, disability, sexual orientation, genetic information, parental status, veteran, or any other protected status. Additionally, TT participates in the E-Verify Program for US offices.
