Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Information Security Controls Assessor image - Rise Careers
Job details

Senior Information Security Controls Assessor

Company Description

About us, but we'll be brief

Experian is the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses, and society.

Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to accomplish their financial goals and help them save time and money.

We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. Also, for the last five years we've been named in the 100 "World's Most Innovative Companies" by Forbes Magazine. Experian prioritizes our culture and look to bring people to the team who are passionate about their jobs, who are easy to work with, and who continue to value team over self.

We have 23,000 people operating across 44 countries and every day we're investing in new technologies, experienced people, and new ideas to help all our clients maximize every opportunity.

Job Description

As a Senior Control Assurance Assessor, you'll test security controls both on-premise and in the cloud to ensure design implementation, safeguarding Experian's assets. You'll assess control design, performance, and compliance with standards and regulations, reporting to the Information Security Control Assurance Testing Manager. Identifying gaps, documenting findings, and recommending improvements to mitigate risks are important responsibilities. Using data-driven testing techniques and a defined methodology, you'll collaborate to ensure controls meet current risks and regulatory requirements.

Primary Responsibilities

  • Conduct security control assessments, using documented control activities (where they exist) and regulatory requirements.
  • Develop test plans, test cases, and procedures, applying data from security tools to capture evidence.
  • Use queries and dashboards to identify potential control failures as part of the control testing process.
  • Ensure the accuracy and timely completion of control testing, providing peer review.
  • Document findings, including root cause analysis and applicable recommendations for remediation.
  • Be the primary liaison with partners, delivering clear progress updates and results.
  • Contribute lessons learned by integrating partner feedback to improve the control testing program.

Qualifications

What your background is

  • A bachelor's degree in computer science, management information systems, or a relevant field, or equivalent demonstrable experience.
  • 5+ years' of experience in Information Security or Information Technology
  • 3+ years' experience performing IT Audit or security control testing.
  • Knowledge of internal audit methodologies, including risk assessment, execution, and reporting.
  • Proficiency in industry standards and frameworks (e.g., NIST 800-53, ISO 27001/27002).
  • Familiarity with privacy regulations (e.g., GDPR, CCPA) and breach notification laws.
  • Experience with sector-specific frameworks (e.g., HIPAA, PCI).

Technical Skills

  • Proficiency with security tools (SailPoint, Rapid7, Wiz.io, MS Defender, SIEM, vulnerability management, penetration testing).
  • Knowledge of cloud technologies (AWS, Azure).
  • Experience using generative AI (e.g., ChatGPT) for test strategies, reports, and communications.
  • Skills in automation and analytics tools (Excel, Tableau, Alteryx, or PowerBI).
  • Create queries and reports in RSA Archer and ServiceNow.
  • Familiarity with Kanban boards and Jira.

Desired Competencies

  • Understanding of cybersecurity principles and organizational requirements.
  • Experience applying governance, risk, and control principles.
  • Experience in automated and manual testing of security controls.
  • Experience facilitating meetings and conveying complex ideas.
  • Data collection, validation, analysis, and interpretation.
  • Experience Researching and applying latest technologies.
  • Experience with Agile methodology.
  • Big 4 accounting experience.
  • Hold a professional certification such as CISA, CISM, CISSP, PCI QSA, ISO 27001 Lead Auditor, or equivalent.

Additional Information

This is a permanent hybrid role in Costa Rica. No relocation available.

Culture at Experian

Our uniqueness is that we value yours.

Experian's culture, people, and environments are main differentiators. We take our people's agenda very seriously. We focus on what matters; diversity and inclusion, work/life balance, flexible work, development, engagement, collaboration, wellness, rewards & recognitions, volunteering... the list goes on!

Our benefits include: Medical, life and dental insurance, Asociacion Solidarista, International Share Save Plan, Flex Work/Work from home, Paid time off, Annual Performance Bonus, Education Reimbursement, Family Bonding, Bereavement Leave, Referral Program, and more.

Experian Careers - Creating a better tomorrow together

Find out what its like to work for Experian by clicking here

#LI-Hybrid

Experian is proud to be an Equal Opportunity and Affirmative Action employer. Our goal is to create a successful, inclusive and diverse team where people love their work and love working together. We believe that diversity, equity and inclusion is necessary to our purpose of creating a better tomorrow. For us, this is The Power of YOU and it ensures that we live what we believe.

Experian Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Experian DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Experian
Experian CEO photo
Jennifer Schulz
Approve of CEO

Average salary estimate

$95000 / YEARLY (est.)
min
max
$80000K
$110000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Information Security Controls Assessor, Experian

Join Experian as a Senior Information Security Controls Assessor in our vibrant office located in Centro Corporativo el Cafetal, Heredia, Costa Rica! At Experian, we pride ourselves on being the world's leading global information services company, working tirelessly to help businesses and consumers unlock the power of data. As a Senior Information Security Controls Assessor, you will play a key role in safeguarding our assets by testing and assessing security controls both on-premise and in the cloud. Your expertise is essential in identifying gaps and recommending improvements to our processes. With a collaborative approach, you will develop test plans and utilize data-driven techniques to ensure compliance with standards and regulations. Your contributions will not only enhance our control testing program but also strengthen the overall security of our operations. We value innovation, collaboration, and a forward-thinking mindset. If you're looking for a place where you can make a real impact and join a diverse team passionate about their work, Experian is the right fit for you!

Frequently Asked Questions (FAQs) for Senior Information Security Controls Assessor Role at Experian
What are the key responsibilities of a Senior Information Security Controls Assessor at Experian?

As a Senior Information Security Controls Assessor at Experian, you will conduct security control assessments, develop test plans and test cases, and leverage data from security tools to document findings and recommend remediation. You'll also ensure that security controls meet current risks and regulatory requirements by collaborating with partners and delivering clear updates.

Join Rise to see the full answer
What qualifications do I need to apply for the Senior Information Security Controls Assessor position at Experian?

To qualify for the Senior Information Security Controls Assessor position at Experian, candidates should have a bachelor’s degree in computer science or a relevant field, along with 5+ years of experience in Information Security or IT, including 3+ years of IT Audit or security control testing experience. Familiarity with industry frameworks such as NIST and ISO is also essential.

Join Rise to see the full answer
What technical skills are required for the Senior Information Security Controls Assessor role at Experian?

Candidates for the Senior Information Security Controls Assessor role at Experian should possess proficiency with security tools like SailPoint and penetration testing software, understanding of cloud technologies such as AWS and Azure, and familiarity with data analytics tools. Additionally, skills in automation and experience using reporting tools like Tableau or PowerBI are preferred.

Join Rise to see the full answer
What makes Experian a great place to work for a Senior Information Security Controls Assessor?

Experian has been recognized by Fortune as one of the 100 Best Companies to Work For and is continuously listed among the world’s most innovative companies. The culture prioritizes diversity, inclusion, and employee well-being, offering a supportive environment where your contributions are valued and can lead to exciting advancements in your career.

Join Rise to see the full answer
What is the work environment like for a Senior Information Security Controls Assessor at Experian?

As a Senior Information Security Controls Assessor at Experian, you'll enjoy a permanent hybrid work setup in Costa Rica. The environment is dynamic and engaging, where employees are encouraged to collaborate, share ideas, and continuously learn. The company's focus on work-life balance means you can thrive both personally and professionally.

Join Rise to see the full answer
Common Interview Questions for Senior Information Security Controls Assessor
Can you explain your experience with IT Audit or security control testing?

When answering this question, highlight specific projects where you led or participated in IT Audit or security control testing, detailing the methodologies and frameworks you employed, such as NIST or ISO, and discuss the impact your work had on improving security controls.

Join Rise to see the full answer
How do you stay updated with emerging cybersecurity threats?

In your response, mention the resources you utilize such as cybersecurity blogs, webinars, and industry publications. Highlight any communities you engage with or certifications you pursue that keep you informed about current security threats and solutions.

Join Rise to see the full answer
Describe a time you identified a security control gap. What action did you take?

Provide a scenario where you discovered a security control gap, explaining the steps you took to assess the situation, the recommendations you made for remediation, and how your actions improved the overall security posture of the organization.

Join Rise to see the full answer
What tools and technologies do you prefer for security control assessments?

Discuss specific tools like SailPoint or Rapid7 that you've used in your previous roles. Explain why these tools are effective and how they contribute to efficient security assessments.

Join Rise to see the full answer
Can you discuss your experience with compliance standards like GDPR or HIPAA?

Talk about your familiarity with these regulations, providing examples of how you've ensured compliance in past roles. Discuss any audits you have conducted or assessments related to these regulations.

Join Rise to see the full answer
What role does data analysis play in your assessment process?

Emphasize your analytical skills and how you use data analytics tools to enhance your testing processes. Speak to how gathering and interpreting data leads to more accurate assessments and informed recommendations.

Join Rise to see the full answer
How would you document your findings during security control assessments?

Describe your methodical approach to documentation, including tools you use for tracking and reporting. Mention the importance of clarity, thoroughness, and following organizational standards to ensure transparency and accountability.

Join Rise to see the full answer
How do you prioritize your tasks during control testing?

Address your organizational skills and how you assess risk to prioritize control testing tasks. Discuss how you manage deadlines and ensure timely completion of testing without compromising quality.

Join Rise to see the full answer
What is your approach to collaborating with cross-functional teams?

Highlight your communication skills and collaborative mindset. Detail how you build relationships with different teams and ensure that security requirements are understood and integrated across the organization.

Join Rise to see the full answer
Why do you want to work at Experian as a Senior Information Security Controls Assessor?

Share your enthusiasm for Experian’s innovative culture and how its mission aligns with your professional values. Discuss your desire to contribute to a leading company and how your skills will help enhance their security framework.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Experian Remote ., ., ., United States
Posted 8 days ago
Photo of the Rise User
Experian Remote 80 Victoria Street, London, United Kingdom
Posted 8 days ago
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Sopra Steria Hybrid Brussels, Brussels, Antwerp, Brussels, Belgium
Posted 10 days ago
Photo of the Rise User
Posted yesterday
L3Harris Technologies Hybrid US, El Paso County, CO; Colorado, Colorado Springs, CO
Posted 5 days ago
Photo of the Rise User
Posted yesterday

We pride ourselves on being certified as a Great Place To Work and firmly believe that creating a positive company culture is less about ping pong tables and more about transparency, connection, and "work with purpose." The unique perspective of e...

852 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
March 28, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cleveland just viewed Marketing Analytics Intern - Summer 2025 at Spectrum
Photo of the Rise User
28 people applied to IT Intern at USAA
Photo of the Rise User
8 people applied to IT Help Desk Intern at Fearless
Photo of the Rise User
Someone from OH, Cincinnati just viewed Bookkeeper - Franchise Location at H&R Block
Photo of the Rise User
Someone from OH, Holland just viewed Data Intelligence Intern at Actian Corporation
Photo of the Rise User
Someone from OH, Holland just viewed Program Intern, Data Engineering at Pilot Company
Photo of the Rise User
44 people applied to SOC Analyst I at Epsilon
Photo of the Rise User
30 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
11 people applied to Director CISO at Elevation Capital
Photo of the Rise User
Someone from OH, Sandusky just viewed Head of IT/Security at Aerones
Photo of the Rise User
Someone from OH, Sandusky just viewed Vice President, Technology at MedVA
I
Someone from OH, Sandusky just viewed IT Manager at Infinite Locus
Photo of the Rise User
Someone from OH, Cincinnati just viewed Finance Associate at Street Diligence
M
Someone from OH, Sandusky just viewed Director of Security, IT, & Compliance at Murmuration
W
Someone from OH, Sandusky just viewed Enterprise Technology Director at World Central Kitchen
Photo of the Rise User
Someone from OH, Sandusky just viewed Director of IT at Kyo
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Remote Manager in Training- CS/Sales at Global Elite
Photo of the Rise User
Someone from OH, Cleveland just viewed Software Engineer I (DevOps) at Mastercard
C
Someone from OH, Warren just viewed Front End Developer (for AI Agent) at CyberCare
I
Someone from OH, Warren just viewed Senior Angular Lead at Integrators services a.s.
Photo of the Rise User
Someone from OH, Warren just viewed SSr. Front End Engineer (Angular.js) at NTD Software
Photo of the Rise User
Someone from OH, Warren just viewed Front-End Developer at Apex Logic
S
Someone from OH, Warren just viewed Angular Developer at Sparkland
Photo of the Rise User
Someone from OH, New Albany just viewed Diversity, Equity & Inclusion Manager at Axios
Photo of the Rise User
Someone from OH, Cincinnati just viewed Customer Service Associate at 2K