About this roleControls Analyst - Contract - Vienna, VA/Hybrid - $50.00 - $56.63/hr.
The final salary or hourly wage, as applicable, paid to each candidate/applicant for this position is ultimately dependent on a variety of factors, including, but not limited to, the candidate's/applicant's qualifications, skills, and level of experience as well as the geographical location of the position.
Applicants must be legally authorized to work in the United States. Sponsorship not available.
Our client is seeking a Controls Analyst in Vienna, VA/Hybrid.
Role Description
We are seeking a detail-oriented Technical Risk Analyst to support second-line risk oversight through independent IT security controls testing and assurance activities. This role is heavily focused on evaluating the design and operating effectiveness of controls, with primary emphasis on identity and access management (IAM) and other technology security controls. The ideal candidate has deep experience in control testing methodologies and is confident in assessing control effectiveness, challenging first-line conclusions, and delivering high-quality, evidence-based risk insights.
What are the top 2-3 control areas this role will focus on first (IAM, privileged access, provisioning, etc.)? The focus on control testing would be Provisioning, Deprovisioning, Access Reviews, Separation of Duties. Think of testing under an overarching control objective such as Manage Access.
Which IAM tools/platforms should that have worked with? SailPoint, Saviynt, CyberArk, Azure AD, Okta) Saviynt, CyberArk, manually tracking via various tools. Most of the controls are manual.
Which testing methodology should they have exp in? (NIST, RCSA, etc.) NIST / RCSA
Is hands-on control testing experience required, or will audit-only backgrounds work? I would take hands on or audit backgrounds.
Are they open to candidates stronger in IAM engineering vs pure risk/testing, or strictly GRC? Interest in engineering would be helpful for context and background but the primary responsibilities will be control testing and 2nd line of defense oversight and effective challenge. The split would be about 80% testing, 20% 2LOD oversight / effective challenge.
Skills & Requirements
5-10 years exp
2nd line of defense
controls testing
tools: cyberark and saviynt as well as other tools they use to track manually
NIST and RCSA
Benefits/Other Compensation
This position is a contract/temporary role where Hays offers you the opportunity to enroll in full medical benefits, dental benefits, vision benefits, 401K and Life Insurance ($20,000 benefit).
Why Hays?
You will be working with a professional recruiter who has intimate knowledge of the industry and market trends. Your Hays recruiter will lead you through a thorough screening process in order to understand your skills, experience, needs, and drivers. You will also get support on resume writing, interview tips, and career planning, so when there's a position you really want, you're fully prepared to get it.
Nervous about an upcoming interview? Unsure how to write a new resume?
Visit the Hays Career Advice section to learn top tips to help you stand out from the crowd when job hunting.
Hays is committed to building a thriving culture of diversity that embraces people with different backgrounds, perspectives, and experiences. We believe that the more inclusive we are, the better we serve our candidates, clients, and employees. We are an equal employment opportunity employer, and we comply with all applicable laws prohibiting discrimination based on race, color, creed, sex (including pregnancy, sexual orientation, or gender identity), age, national origin or ancestry, physical or mental disability, veteran status, marital status, genetic information, HIV-positive status, as well as any other characteristic protected by federal, state, or local law. One of Hays' guiding principles is 'do the right thing'.
We also believe that actions speak louder than words.
In that regard, we train our staff on ensuring inclusivity throughout the entire recruitment process and counsel our clients on these principles. If you have any questions about Hays or any of our processes, please contact us.
In accordance with applicable federal, state, and local law protecting qualified individuals with known disabilities, Hays will attempt to reasonably accommodate those individuals unless doing so would create an undue hardship on the company. Any qualified applicant or consultant with a disability who requires an accommodation in order to perform the essential functions of the job should call or text .
Drug testing may be required; please contact a recruiter for more information.
#LI-DNI