Develop, maintain, and continuously improve security assessment frameworks, testing procedures, methodologies, standards, and guidelines.
Drive efficiency and consistency in assurance activities through the enhancement of control assessment approaches and security governance practices.
Oversee security testing delivery across projects and business-as-usual activities, ensuring testing approaches, documentation, and outcomes are fit for purpose.
...
Assess IT general controls (ITGCs) and application controls supporting financial reporting and revenue assurance (e.g., user access, change management, job scheduling, interface controls, billing accuracy).
Review technology project delivery and SDLC/DevSecOps practices, including secure coding, CI/CD controls, environment segregation, release management, and third‑party components.
Assess resilience and availability controls: backup, recovery, DR/BCP, capacity management, patching, configuration management, and operational monitoring.
...