Cyber Security Controls Assessor III

Pivot Point SolutionsOakland, CA
$50 - $71Hybrid

About The Position

Pivot Point Solutions is seeking a Cyber Security Controls Assessor to support Identity and Access Management (IAM) control testing and audit readiness within a complex enterprise technology environment. This role will focus on evaluating IAM controls through structured IT compliance testing, including planning, control walkthroughs, evidence review, test execution, deficiency identification, remediation tracking, and results reporting. The ideal candidate brings 5+ years of IT Audit or IT Compliance experience with direct exposure to IAM controls, IT General Controls (ITGCs), and NIST-aligned control environments. This position requires someone who can independently work with system owners, IT and Security teams, internal stakeholders, and external auditors while producing clear, audit-ready documentation.

Requirements

  • Bachelor's degree in Information Systems or a related field.
  • 5+ years of professional IT Audit, IT Compliance, IT Risk, or closely related control-testing experience.
  • Hands-on experience executing IAM control testing, including planning, walkthroughs, evidence review, testing, documentation, and results reporting.
  • Strong experience evaluating IT General Controls (ITGCs).
  • Working knowledge of NIST-aligned control environments and cybersecurity compliance principles.
  • Experience conducting control walkthroughs directly with system owners and technical stakeholders.
  • Ability to identify control deficiencies, document findings, recommend remediation, and track corrective actions.
  • Experience partnering with internal stakeholders and external auditors during formal testing or audit cycles.
  • Advanced Microsoft Excel skills, including pivot tables, VLOOKUP/XLOOKUP, and complex formulas.
  • Strong technical writing skills with experience developing audit-ready narratives, testing documentation, and workpapers.
  • Ability to independently manage multiple testing activities and deadlines in a structured compliance environment.
  • Must be local and able to meet the requirements of a hybrid work schedule.

Nice To Haves

  • CISA, CRISC, CISSP, or a comparable IT risk, audit, or cybersecurity certification.
  • Experience testing Identity and Access Management controls within a large enterprise environment.
  • Experience with NIST and COBIT control frameworks.
  • Experience working with SAP, Oracle, or other large enterprise ERP environments.
  • Experience with Governance, Risk, and Compliance (GRC) or audit-management platforms.
  • Experience supporting complex remediation programs involving multiple IT control owners.
  • Experience working within a large utility, regulated organization, or similarly complex enterprise environment.

Responsibilities

  • Support the execution of IAM compliance and control-testing activities across enterprise systems and technology environments.
  • Plan and perform IT control testing, including control walkthroughs, evidence validation, test execution, workpaper development, and results reporting.
  • Lead detailed walkthroughs with system and control owners to understand processes and evaluate control design and execution.
  • Develop clear, defensible, and audit-ready control narratives and testing documentation.
  • Evaluate IAM and ITGC evidence to determine whether controls are operating as designed.
  • Review test plans, evidence packages, and workpapers for completeness, accuracy, and alignment with audit standards.
  • Identify control deficiencies and clearly document testing exceptions, findings, and supporting evidence.
  • Partner with control owners and IT/Security teams to develop remediation approaches and track corrective actions through closure.
  • Coordinate evidence requests and follow-up activities with system owners and other stakeholders.
  • Work with internal and external auditors throughout testing and audit cycles.
  • Analyze testing data and evidence using advanced Excel functionality, including pivot tables, lookup functions, and complex formulas.
  • Develop reporting and analytical outputs that support testing conclusions and communicate control status.
  • Manage multiple testing activities and priorities while meeting established compliance and audit deadlines.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service