Cyberfort
Cyber Security Controls Tester (Contractor)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Location: Fully Remote (UK)
Contract Type: Contract
Contract Length: Immediate start until February 2027
Security Clearance: Active SC Clearance required and must be verifiable
About The Opportunity
We are seeking an experienced Cyber Security Controls Tester to support a large-scale security assurance programme within a highly regulated environment. This is an excellent opportunity for a contractor with a strong background in security controls testing, assurance and risk management, particularly within central government or wider public sector environments.
Working remotely alongside security architects, risk teams and technical stakeholders, you will provide independent assurance over security controls, helping to ensure that controls are appropriately designed, implemented and operating effectively in line with recognised security standards and frameworks.
What You'll Be Doing
- Evaluating the effectiveness of security controls within the identified environment to ensure they meet the standards defined within supporting documentation, including High-Level Designs (HLDs), Low-Level Designs (LLDs) and Controls Catalogues.
- Testing controls against recognised security frameworks and standards, including ISO 27001, NIST CSF and NIST 800-53.
- Reviewing policies, procedures, network configurations, firewall rules, identity and access management controls, and other technical and procedural security controls.
- Applying recognised controls testing methodologies, including documentation reviews, walkthroughs, sampling and technical verification activities.
- Agreeing testing scope and plans with stakeholders, risk teams and security architects to ensure assurance activity addresses key security concerns.
- Assessing both the design effectiveness and operating effectiveness of implemented security controls.
- Providing pragmatic remediation guidance and recommendations to address identified control weaknesses.
- Supporting improvements to policies, processes and security controls to strengthen the overall security posture of services and environments.
- Maintaining clear documentation of testing activities, evidence collected, findings and remediation recommendations.
- Producing comprehensive assurance reports outlining security posture, findings, risks and recommendations.
- Presenting findings to technical and non-technical stakeholders and agreeing remediation actions where required.
- Working closely with risk and security architecture teams to ensure controls testing supports wider risk management and assurance objectives.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What We're Looking For
You will be a detail-oriented cyber security professional with experience assessing and validating security controls across complex technical environments. You'll be comfortable engaging with both technical and business stakeholders and have the ability to provide clear, evidence-based assurance and practical recommendations.
Essential Skills & Experience
- Demonstrable experience testing and evaluating the effectiveness of technical, procedural and physical security controls within complex environments.
- Strong working knowledge of security control frameworks including ISO 27001, NIST CSF, NIST 800-53 and CIS Controls.
- Experience conducting controls testing, assurance or audit activities against recognised security frameworks.
- Hands-on experience reviewing and testing:
- Network configurations
- Firewall rulesets
- Identity and Access Management (IAM) controls
- Encryption controls
- Endpoint security controls
- Familiarity with security design and controls documentation including HLDs, LLDs and Controls Catalogues.
- Experience applying recognised testing methodologies, including documentation reviews, walkthroughs, sampling and evidence-based assurance activities.
- Strong understanding of relevant legislation and compliance requirements, including GDPR, PCI DSS and ICO guidance.
- Working knowledge of HMG and NCSC security policies, standards and guidance.
- Ability to produce clear, well-structured test plans, assurance reports and remediation recommendations.
- Strong stakeholder management and communication skills, with experience engaging risk teams, security architects and business stakeholders.
- Strong analytical and problem-solving skills, with a methodical approach to identifying, evidencing and reporting security control weaknesses.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Skills & Certifications
- CISA certification.
- ISO 27001 Lead Auditor or Lead Implementer certification.
- CRISC certification.
- CompTIA Security+ or similar security assurance-related certification.
- Experience working within central government or public sector environments.
- Experience supporting governance, risk and compliance (GRC) programmes.
- Exposure to cloud security assurance across Azure and AWS environments.
- Experience supporting IT Health Checks (ITHCs), penetration testing exercises or security accreditation activities.
Please note: Active SC Clearance is a mandatory requirement for this role and must be current and capable of being validated.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London