Cynet Systems · 14 hours ago
Cyber Security Controls Assessor
Cynet Systems is seeking a Cyber Security Controls Assessor responsible for performing comprehensive IT and security control assessments across multiple platforms. This role involves evaluating control effectiveness, identifying risks, and supporting sustainable remediation to ensure compliance with regulatory standards and industry best practices.
EmploymentRecruitingStaffing Agency
Responsibilities
Perform multi-platform assessments across applications, databases, operating systems, middleware, monitoring tools, and business processes based on predefined test objectives and test plans
Perform retesting of controls remediated or updated due to previously identified deficiencies
Obtain, review, and interpret evidence to validate that controls are operating effectively
Execute and report on IT compliance assessments in alignment with industry best practices and regulatory standards such as NIST SP800-53, SP800-115, SOX, and NERC CIP
Review organizational IT policies, standards, and procedures to identify control points that mitigate business risk
Analyze test results and evidence to identify vulnerabilities, gaps, or control deficiencies and collaborate with stakeholders on remediation plans
Identify risks associated with control failures and support the identification of mitigating controls
Partner with control owners to ensure control documentation remains current and accurately reflects the control environment
Perform additional tasks as needed to ensure compliance commitments to customers are met
Support the Compliance Senior Manager or Manager as required
Qualification
Required
Bachelor's degree in Computer Science, Business, or equivalent professional experience
Minimum of 3 years of general IT experience, including IT security or IT risk management
Demonstrated experience using Microsoft Excel, including worksheets, workbooks, and formulas
Ability to manage multiple projects with competing priorities
At least one active and valid certification such as CCNA, CISA, CRISC, CIA, or CISSP
Experience performing IT compliance or security control assessments
Experience reviewing and interpreting control evidence and assessment results
Strong oral and written communication skills
Strong analytical and problem-solving abilities
Understanding of application, database, network, and system security
Knowledge of general computing controls (GCCs)
Ability to identify complex control gaps
Knowledge of auditing standards and frameworks such as COBIT and ITIL, and regulatory standards including SOX and NERC CIP
Excellent planning, organizational, and project management skills
Ability to multitask and work independently in a fast-paced environment
High attention to detail
Preferred
Utility industry experience
Big 4 consulting or audit experience
Experience with Sarbanes-Oxley or NIST SP800-53 security controls
Additional certifications such as CEH, ITIL, MCP/MCSE, CCNP, CISM, or PMP