Senior Security Assurance Specialist
sas ventures- Posted 7 hours ago
- Be among the first 10 applicants
Job Description
Location: United Arab Emirates (Remote)
Employment Type: Full-Time
Experience Level: Senior
Work Arrangement: Fully Remote
About UsWe are a globally focused organization committed to maintaining secure, resilient, and trustworthy technology environments across diverse markets. Our teams work across Information Security, Technology, Risk, Compliance, Privacy, Engineering, Operations, and business functions to identify security risks, strengthen controls, and protect critical information and systems.
We combine security governance, technical assurance, risk management, compliance, architecture, and continuous monitoring to ensure that security requirements are embedded throughout the technology and business lifecycle.
The RoleWe are seeking an experienced Senior Security Assurance Specialist to lead security assurance activities covering technology controls, applications, infrastructure, cloud environments, third-party services, security processes, and information assets.
The ideal candidate will assess the effectiveness of security controls, coordinate assurance reviews, identify control gaps, evaluate security risks, support audits and certifications, track remediation, and provide independent insight into the organization's overall security posture.
Key Responsibilities- Develop and maintain security assurance strategies, methodologies, standards, procedures, and assessment frameworks.
- Establish security assurance plans aligned with organizational risk appetite, security objectives, and regulatory requirements.
- Conduct security control assessments across applications, infrastructure, cloud platforms, networks, endpoints, databases, and information systems.
- Evaluate the design and operating effectiveness of information-security controls.
- Review technical and organizational controls covering access management, authentication, encryption, logging, monitoring, vulnerability management, configuration, backup, incident response, and resilience.
- Perform security assurance reviews throughout the technology and system development lifecycle.
- Assess security requirements during solution design, development, implementation, change, and operational stages.
- Review security architecture and technical designs for alignment with approved security standards.
- Conduct security risk assessments and identify control weaknesses, gaps, dependencies, and residual risks.
- Develop risk-based assessment plans based on system criticality, data sensitivity, threat exposure, regulatory requirements, and business impact.
- Review security controls for critical and high-risk applications and infrastructure.
- Assess cloud security controls across relevant cloud services, platforms, workloads, and configurations.
- Evaluate security controls for SaaS, PaaS, IaaS, APIs, containers, and other modern technology environments.
- Review identity and access-management controls, including privileged access, role-based access, authentication, and access reviews.
- Assess segregation-of-duties controls and privileged-account governance.
- Review encryption, key-management, certificate-management, and data-protection controls.
- Assess security logging, monitoring, alerting, and security-event management capabilities.
- Review vulnerability-management, patch-management, configuration-management, and endpoint-security processes.
- Evaluate security incident-management and response controls.
- Assess business-continuity, disaster-recovery, backup, and technology-resilience controls from a security perspective.
- Review application-security practices, including secure development, code security, dependency management, and security testing.
- Assess DevSecOps controls and security integration within CI/CD pipelines.
- Coordinate security testing activities, including vulnerability assessments, penetration testing, configuration reviews, and technical assurance activities.
- Review security-testing results and verify that identified findings are appropriately risk-rated and remediated.
- Validate remediation evidence for security vulnerabilities and control deficiencies.
- Conduct follow-up reviews to confirm that corrective actions have been effectively implemented.
- Maintain a centralized register of security assurance findings, risks, remediation actions, owners, and due dates.
- Track overdue security findings and escalate material risks to appropriate stakeholders.
- Perform third-party and supplier security assurance assessments.
- Evaluate security controls implemented by cloud providers, managed-service providers, technology vendors, and strategic suppliers.
- Review supplier security questionnaires, independent assurance reports, certifications, penetration-testing summaries, and other evidence.
- Support third-party risk assessments and vendor onboarding from a security-assurance perspective.
- Coordinate security due diligence for new technology solutions, products, services, and strategic suppliers.
- Support internal and external security audits, regulatory assessments, and certification activities.
- Coordinate evidence collection for ISO 27001, SOC 2, PCI DSS, NIST, CIS, or other applicable assurance frameworks.
- Maintain security-control mappings against relevant standards, policies, regulations, and contractual requirements.
- Monitor changes to security standards, regulations, contractual obligations, and industry practices.
- Assess the impact of new requirements on existing security controls and assurance programs.
- Prepare security assurance reports, control-assessment summaries, risk analyses, and executive dashboards.
- Provide management with clear reporting on security-control effectiveness, open findings, remediation progress, and emerging risks.
- Develop security assurance metrics and key risk indicators.
- Analyze recurring control deficiencies and identify systemic security weaknesses.
- Recommend improvements to security processes, controls, governance, and operating practices.
- Support security policy and standard development by providing control and assurance requirements.
- Participate in security governance committees, risk reviews, architecture forums, and technology oversight meetings.
- Work closely with Information Security, IT, Engineering, Cloud, Infrastructure, Privacy, Compliance, Internal Audit, and Risk teams.
- Challenge control owners constructively and independently while maintaining effective stakeholder relationships.
- Ensure security assurance activities are appropriately documented, repeatable, evidence-based, and risk-focused.
- Maintain assessment workpapers, control evidence, testing results, risk evaluations, and remediation records.
- Support security awareness of control owners by explaining security requirements, findings, and remediation expectations.
- Identify opportunities to automate security-control testing, evidence collection, monitoring, and assurance reporting.
- Evaluate security-assurance tooling, continuous-control-monitoring capabilities, and automated compliance technologies.
- Contribute to security transformation, governance, risk, and compliance technology initiatives.
- Support development of continuous security assurance and control-monitoring capabilities.
- Provide technical guidance and mentorship to junior security assurance professionals.
- Promote a culture of accountability, security ownership, continuous improvement, and risk-based decision-making.
- Security control assessment completion
- Security control effectiveness
- Control testing accuracy
- Security assurance plan completion
- High-risk finding identification
- Critical finding identification and escalation
- Security finding remediation rate
- Overdue finding rate
- Average remediation time
- Remediation verification completion
- Repeat finding rate
- Residual security risk reduction
- Security risk assessment completion
- Application security assessment coverage
- Cloud security assessment coverage
- Infrastructure security assessment coverage
- Third-party security assessment completion
- Supplier security-risk remediation
- Privileged-access control effectiveness
- Access-review completion
- Vulnerability remediation compliance
- Patch-management compliance
- Security configuration compliance
- Security logging and monitoring control effectiveness
- Incident-response control effectiveness
- Backup and recovery control compliance
- Security testing completion
- Penetration-testing finding closure
- Audit finding resolution
- Audit readiness
- Certification compliance
- ISO 27001 control effectiveness
- SOC 2 control effectiveness
- Security policy compliance
- Security evidence quality
- Assessment cycle time
- Assurance reporting timeliness
- Security risk reporting accuracy
- Continuous-control-monitoring coverage
- Automated assurance adoption
- Security assurance process efficiency
- Stakeholder satisfaction
- Assurance-related audit findings
- Security governance improvement completion
The successful candidate should have strong experience in information-security assurance, cybersecurity governance, security risk, IT audit, security compliance, technology risk, or security controls, preferably within a complex, regulated, multinational, cloud-enabled, or technology-intensive environment.
The candidate should demonstrate:
- Strong understanding of information-security governance, risk, and assurance principles.
- Proven experience assessing the design and effectiveness of security controls.
- Strong knowledge of security frameworks such as ISO 27001, NIST CSF, CIS Controls, SOC 2, COBIT, or equivalent standards.
- Experience conducting security-control assessments and risk-based assurance reviews.
- Strong understanding of identity and access management, privileged access, authentication, and authorization controls.
- Knowledge of vulnerability management, patch management, security configuration, and endpoint-security controls.
- Strong understanding of cloud security across major cloud-service models.
- Experience assessing application security, secure development, APIs, and DevSecOps controls.
More Info
Key Skills
authentication and authorization controls
privileged access
security configuration
DevSecOps controls
secure development
endpoint-security controls
cybersecurity governance
