Cyber Security Controls Tester (Assurance)
- Posted September 11, 2026
- £500 - £550 per day + Outside IR35
- Nottingham
- Contract
Cyber Security Controls Tester
Location: Fully Remote
Contract Length: 6 Months
Day Rate: Circa £550 per day (Outside IR35)
Security Clearance: Active SC Clearance required (must be current and verifiable)
About the Role
An established MSSP is seeking an experienced Cyber Security Controls Tester to support a large-scale security assurance programme. This is an excellent opportunity for a security professional with a strong controls testing, audit, risk, or assurance background to assess the effectiveness of security controls across complex environments.
Working closely with security architects, risk teams, and business stakeholders, you will provide independent assurance that security controls are appropriately designed, implemented, and operating effectively against recognised industry frameworks and standards.
Key Responsibilities
- Evaluate the effectiveness of technical, procedural, and physical security controls against documented security requirements and standards.
- Assess security controls against recognised frameworks including ISO 27001, NIST CSF, NIST 800-53, and CIS Controls.
- Review security documentation, including High-Level Designs (HLDs), Low-Level Designs (LLDs), policies, procedures, and controls catalogues.
- Assess network configurations, firewall rules, identity and access management controls, encryption controls, and endpoint security measures.
- Develop and agree test plans and testing scopes with security architects, risk teams, and relevant stakeholders.
- Apply recognised assurance methodologies, including walkthroughs, documentation reviews, sampling, evidence gathering, and technical verification.
- Produce detailed testing reports, findings, risk assessments, and remediation recommendations.
- Provide pragmatic guidance to improve security posture and address identified control weaknesses.
- Maintain accurate and auditable records of testing activities, findings, and corrective actions.
- Collaborate with risk and security architecture teams to ensure testing activities support wider governance, risk, and assurance objectives.
Required Skills & Experience
- Proven experience testing and assessing the effectiveness of security controls within complex enterprise environments.
- Strong knowledge of security frameworks including:
- ISO 27001
- NIST Cyber Security Framework (CSF)
- NIST 800-53
- CIS Controls
- Experience reviewing and testing:
- Network security controls
- Firewall configurations and rule sets
- Identity and Access Management (IAM)
- Encryption controls
- Endpoint security technologies
- Strong understanding of security assurance and control testing methodologies.
- Experience working with technical design documentation, including HLDs, LLDs, and controls catalogues.
- Knowledge of relevant legislation and regulatory requirements, including:
- GDPR
- PCI DSS
- ICO requirements
- Familiarity with HMG and NCSC security policies, standards, and guidance.
- Excellent analytical, investigative, and problem-solving skills.
- Strong stakeholder engagement and communication capabilities.
- Ability to produce clear, concise, and actionable assurance reports for both technical and non-technical audiences.
Desirable Certifications
One or more of the following certifications would be advantageous:
- CISA
- CRISC
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- CompTIA Security+
- Other security assurance, audit, or controls testing certifications
Reasonable Adjustments:
Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.
If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.
