Share this job
Security Control Assurance Lead 3609144
Charlotte, North Carolina, United States
Apply for this job

Be Part Of A High-Performing Team

Join a cybersecurity organization transforming the way technology risk and control assurance are managed across core systems and digital environments. The team is moving away from manual, point-in-time compliance exercises toward a more engineering-driven model where controls can be codified, integrated, automatically tested, and continuously monitored.

This position sits at the intersection of cybersecurity engineering, GRC, data protection, and control assurance. It is an opportunity to build the technical foundation that allows security assurance to operate as a live signal rather than an annual audit exercise.

What's In Store For You

  • Hybrid Charlotte opportunity with approximately three days onsite each week.
  • Initial six-month engagement with potential for long-term conversion.
  • Significant ownership over GRC engineering and continuous-assurance capabilities.
  • Opportunity to build control-as-code, policy-as-code, automated evidence collection, and continuous controls monitoring capabilities.
  • Direct partnership with cybersecurity, engineering, IT, Data Governance, Legal, and other business stakeholders.
  • Opportunity to materially reduce manual control-testing effort while strengthening visibility into cybersecurity and data risk.

How You Will Make An Impact

  • Design and mature a risk-based security control assurance program across critical systems and technology environments.
  • Engineer automated control testing and evidence-collection capabilities using scripting, APIs, integrations, and security/GRC platforms.
  • Establish continuous controls monitoring so failures and control deviations surface closer to real time.
  • Develop repeatable technical testing procedures for security, privacy, and data-protection controls.
  • Evaluate controls against frameworks and regulations including NIST CSF, ISO 27001, CCPA/CPRA, and GDPR.
  • Connect security, IT, cloud, data, and GRC platforms to centralize control evidence, findings, and remediation information.
  • Continuously assess controls involving access management, encryption, DLP, retention, logging, and sensitive-data protection.
  • Automate deficiency intake, ownership assignment, remediation workflows, and control-health reporting.
  • Partner with engineering teams to incorporate security-control validation into CI/CD pipelines, change management, and SDLC processes.
  • Define metrics around control coverage, automation percentage, failures, remediation time, and overall control effectiveness.

Do You Have the Expertise to Lead in Security Control Assurance Engineering?

  • 8+ years of experience across cybersecurity assurance, security engineering, GRC, security controls, or closely related disciplines.
  • Demonstrated hands-on experience automating security-control testing and/or evidence collection.
  • Working scripting or programming capability using Python, Rust, Ruby, or a comparable language.
  • Hands-on experience connecting enterprise or security platforms through APIs.
  • Experience with GRC platforms and/or continuous controls monitoring technologies.
  • Practical knowledge of control-as-code and policy-as-code concepts.
  • Applied experience with NIST CSF and ISO 27001.
  • Understanding of CCPA/CPRA, GDPR, and related data-protection requirements.
  • Familiarity with AWS and/or GCP security, logging, monitoring, or native control services.
  • Strong understanding of security controls around identity/access, encryption, DLP, retention, and sensitive data.
  • Ability to communicate effectively with cybersecurity engineers, technology teams, governance stakeholders, Legal, and senior leadership.
  • Bachelor's degree in Computer Science, Engineering, Information Security, or a related discipline.
  • CISSP, CISA, CISM, CRISC, or similar security/risk certification strongly preferred.
Apply for this job