Senior Security Assurance Specialist
- Hiring from
- United Arab Emirates
- Work type
- Remote
- Posted
508,864 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Location: United Arab Emirates (Remote)
Employment Type: Full-Time
Experience Level: Senior
Work Arrangement: Fully Remote
About UsWe are a globally focused organization committed to maintaining strong cybersecurity, technology risk management, regulatory compliance, and operational resilience across diverse digital environments. Our teams collaborate across Information Security, Technology, Engineering, Risk, Compliance, Internal Audit, Privacy, Procurement, and business functions to establish effective security controls and protect critical information and technology assets.
Our security assurance teams provide independent and risk-based oversight of security controls, assess technology environments against internal and external requirements, and help ensure that security practices are consistently designed, implemented, monitored, and improved.
The RoleWe are seeking an experienced Senior Security Assurance Specialist to lead security assurance assessments, control reviews, compliance validation, risk assessments, audit readiness, security testing oversight, and continuous-improvement activities across the organization's technology and information-security environment.
The ideal candidate will combine strong cybersecurity knowledge with assurance, governance, risk, audit, and control expertise to evaluate whether security controls are appropriately designed and operating effectively, identify gaps, coordinate remediation, and provide management with clear insight into the organization's security posture.
Key Responsibilities- Develop and implement security assurance strategies, methodologies, standards, procedures, and assessment frameworks.
- Establish risk-based security assurance programs aligned with organizational priorities and threat exposure.
- Conduct assessments of information-security controls across applications, infrastructure, networks, cloud environments, endpoints, data platforms, and business processes.
- Evaluate the design and operating effectiveness of cybersecurity controls.
- Perform security control assessments against internal policies, standards, procedures, and regulatory requirements.
- Assess security practices against recognized frameworks such as ISO 27001, NIST Cybersecurity Framework, CIS Controls, SOC 2, and applicable industry standards.
- Develop assessment plans, scopes, testing procedures, evidence requirements, and evaluation criteria.
- Coordinate security assurance reviews with control owners, technology teams, business stakeholders, and security functions.
- Review evidence to determine whether security controls are appropriately implemented and consistently operating.
- Identify control weaknesses, deficiencies, exceptions, and areas of non-compliance.
- Assess the potential business, operational, regulatory, and security impact of identified control gaps.
- Document findings with clear evidence, risk statements, root causes, and remediation recommendations.
- Assign risk ratings to security findings based on likelihood, impact, asset criticality, threat exposure, and control effectiveness.
- Track security findings and corrective actions through remediation and closure.
- Validate remediation activities and confirm that identified control weaknesses have been appropriately addressed.
- Conduct follow-up assurance testing to verify sustained control effectiveness.
- Support internal and external information-security audits.
- Coordinate audit preparation, evidence collection, control-owner responses, and remediation activities.
- Review audit findings and develop appropriate corrective and preventive actions.
- Support regulatory examinations and customer security assessments.
- Prepare responses to security questionnaires, due-diligence requests, and assurance inquiries from customers, partners, auditors, and other stakeholders.
- Evaluate third-party security controls and assurance documentation.
- Review third-party security assessments, SOC reports, ISO certifications, penetration-testing reports, and other independent assurance evidence.
- Identify security risks associated with suppliers, service providers, cloud providers, and strategic technology partners.
- Support third-party risk-management processes by assessing security controls and remediation commitments.
- Conduct security assessments during technology implementations, system changes, migrations, acquisitions, and major transformation initiatives.
- Participate in security architecture and design reviews to evaluate security requirements and control coverage.
- Assess security controls across cloud, SaaS, infrastructure-as-code, DevOps, CI/CD, containerized, and modern application environments.
- Review identity and access-management controls, including authentication, authorization, privileged access, access reviews, and account lifecycle management.
- Assess security monitoring, logging, alerting, incident-response, and threat-detection capabilities.
- Evaluate vulnerability-management, patch-management, configuration-management, and endpoint-security controls.
- Assess data-protection controls covering encryption, key management, data classification, retention, backup, and secure disposal.
- Review security incident-management processes and evaluate lessons learned and corrective actions.
- Assess business-continuity, disaster-recovery, and technology-resilience controls from an information-security perspective.
- Review security policies, standards, procedures, control descriptions, and governance documentation.
- Identify inconsistencies between documented requirements and actual security practices.
- Maintain security-control matrices, risk-and-control registers, assessment records, evidence repositories, and remediation trackers.
- Develop security assurance dashboards and management reporting.
- Monitor key security-control performance indicators and identify emerging assurance risks.
- Analyze recurring control deficiencies and identify systemic causes.
- Recommend improvements to security governance, control design, monitoring, and operational processes.
- Support the development and maintenance of security control frameworks and assurance methodologies.
- Establish consistent assessment criteria and quality standards across security assurance activities.
- Evaluate the effectiveness of security policies and standards through control testing and operational evidence.
- Support risk assessments for new technologies, applications, suppliers, and business initiatives.
- Provide security assurance input into procurement, vendor selection, and contract-security requirements.
- Collaborate with Compliance, Enterprise Risk, Internal Audit, Privacy, Legal, and business teams on security-related assurance matters.
- Provide guidance to control owners on evidence requirements, remediation expectations, and security-control effectiveness.
- Conduct workshops and awareness sessions to improve control-owner understanding of security assurance requirements.
- Maintain awareness of emerging cybersecurity threats, regulatory developments, assurance practices, and security frameworks.
- Evaluate emerging security technologies and assurance approaches to improve assessment efficiency and coverage.
- Identify opportunities to automate evidence collection, control monitoring, assessment workflows, and assurance reporting.
- Support implementation and optimization of governance, risk, and compliance platforms.
- Prepare executive-level reports summarizing security-control effectiveness, major risks, audit findings, remediation progress, and assurance trends.
- Provide management with practical recommendations to strengthen cybersecurity resilience and reduce technology risk.
- Security assurance assessment completion
- Security-control assessment coverage
- Control testing completion rate
- Control effectiveness rate
- Security control deficiency rate
- High-risk finding identification
- Critical finding remediation rate
- Security finding closure rate
- Average remediation time
- High-risk finding aging
- Repeat finding rate
- Remediation validation completion
- Corrective-action effectiveness
- Audit finding closure rate
- Audit readiness
- Audit evidence submission timeliness
- Regulatory assessment readiness
- Security questionnaire response timeliness
- Third-party security assessment completion
- Third-party finding remediation rate
- Supplier security-risk reduction
- Security-control compliance rate
- Policy compliance rate
- Security exception management effectiveness
- Risk assessment completion
- Security assessment turnaround time
- Assessment evidence quality
- Evidence completeness
- Control-owner response rate
- Security assurance reporting timeliness
- Security dashboard accuracy
- Control-monitoring coverage
- Automated evidence-collection rate
- Assurance workflow automation
- Recurring control-deficiency reduction
- Security risk reduction achieved
- Security framework compliance
- Security testing quality
- Stakeholder satisfaction
- Security remediation effectiveness
- Assurance program cost efficiency
- Continuous-improvement initiatives completed
- Management reporting effectiveness
The successful candidate should have strong experience in security assurance, cybersecurity governance, information-security risk, security compliance, IT audit, security controls, or technology risk, preferably within complex enterprise, financial-services, technology, telecommunications, professional-services, or highly regulated environments.
The candidate should demonstrate:
- Strong understanding of cybersecurity governance, risk, compliance, and assurance principles.
- Proven experience performing information-security control assessments and assurance reviews.
- Strong knowledge of security-control design, implementation, testing, and operating effectiveness.
- Experience assessing controls across applications, infrastructure, networks, cloud, identity, data, and technology operations.
- Strong knowledge of security frameworks such as ISO 27001, NIST, CIS Controls, SOC 2, or equivalent standards.