TESTQ Technologies
IT Risk and Control Specialist

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role
Overview
Join our dynamic team as an IT Risk and Control Specialist where you'll play a pivotal role in safeguarding and enhancing the technology landscape supporting our People Governance and Communications functions. You'll collaborate across multiple internal teams to drive robust risk management control practices and process improvements ensuring our systems and workplace technologies remain secure, efficient, and resilient.
Key Responsibilities
- Build Trusted Partnerships
- Develop strong working relationships with the People Governance Communications Group, COO, Technology, ITSO community, technical leads, developers, and architects to understand end-to-end services and proactively identify control gaps.
- Risk Control Leadership
- Work closely with Cybersecurity teams, senior management, and business stakeholders to address potential security issues and ensure best practices are embedded across all technology functions.
- Process Tool Enhancement
- Contribute to the identification and improvement of processes, procedures, and tools that support effective risk management and control.
- Lifecycle Management
- Champion best practices in Software Life Cycle Management including Identity Access Management (IDAM), Evergreening, and Data Movement (DMOV) to mitigate cyber risks and ensure compliance.
- Vulnerability Management
- Design and implement vulnerability reporting and monitoring solutions for key stakeholders from engineers to CIOs. Liaise with technology product owners and ITSOs to support timely remediation of identified risks.
- Patch Remediation Coordination
- Collaborate with cybersecurity teams to understand patching requirements and ensure vulnerabilities are addressed within agreed timelines.
- Documentation Reporting
- Maintain and update process guides, support control remediation activities, and create insightful reports and presentations for senior stakeholders and governance forums.
- Continuous Improvement
- Stay abreast of industry trends and best practices, sharing knowledge and insights with the wider team to foster a culture of continuous learning and improvement.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Qualifications & Experience
- Solid understanding of IT Risk and Control Management including risk management frameworks.
- Strong analytical skills with experience interpreting patching and vulnerability reports.
- Specific experience of working with at least one of the controls would be beneficial.
- Ability to assess threats, controls, and vulnerabilities and communicate findings effectively to both technical and business audiences.
- Excellent written and verbal communication skills.
- Proven experience in security concepts and principles with knowledge of network, host, and application security practices.
- Hands-on experience with tools such as Cyberport, Cyberflows, Power BI, Confluence, and Jira.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Skills
- Mandatory Skills: BMC Control-M, Risk Management (Credit/Market/IT/Ops)
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills