Technology Control Testing Lead

  • capital.com
  • Jun 28, 2025
Full time I.T. & Communications

Job Description

We are a leading trading platform that is ambitiously expanding to the four corners of the globe. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talented team.

Responsibilities:
  • Design and maintain a robust technology control testingframework aligned with risk management standards (e.g.,NIST, ISO 27001, COBIT, ITIL).
  • Develop and update testing methodologies, ensuring theyaddress key risks related to IT infrastructure, cybersecurity,cloud services, and software development.
  • Establish and maintain control testing policies andprocedures that align with regulatory and internalgovernance requirements.
  • Ensure the control testing framework integrates seamlesslywith the broader Operational Risk Management Framework(ORMF).
  • Maintain a comprehensive control library, mapping controlsto risks and business objectives.
  • Plan and execute detailed control testing activities acrossIT operations, systems, and processes, including:
  • - Cybersecurity controls (e.g., firewalls, encryption, accessmanagement).
  • - Cloud computing controls (e.g., AWS, Azure, GoogleCloud).
  • - Data protection controls (e.g., GDPR compliance, databackups).
  • - Incident management processes and disaster recoverytesting.
  • Test both the design and operating effectiveness of ITcontrols.
  • Prioritise control testing activities based on risk assessments, focusing on high-risk areas such as paymentsystems, customer data protection, and regulatoryreporting.
  • Document and communicate control deficiencies torelevant stakeholders.
  • Work with technology teams to develop, track, andimplement remediation plans to address identified controlgaps.
  • Perform follow-up testing to validate the resolution ofissues and confirm effectiveness.
  • Assess IT controls of third-party vendors and serviceproviders, ensuring compliance with contractual andregulatory obligations.
  • Support vendor risk management activities by evaluatingthird-party cybersecurity and IT governance controls.
  • Document findings and control weaknesses, ensuring theyare communicated clearly to relevant stakeholders.
  • Work with control owners and process teams to developand track remediation plans for identified deficiencies,ensuring timely resolution.
  • Conduct follow-up testing to validate the implementationand effectiveness of corrective actions.
  • Collaborate with risk teams to ensure control testing alignswith the organisation's risk assessment and regulatoryrequirements.
  • Present findings and recommendations to seniorleadership, providing actionable insights to improve thecontrol environment.
  • Support regulatory audits and examinations by providingcontrol testing documentation and responding to inquiries.
  • Ensure the organisation is prepared for external reviews ofits control environment.
Requirements:
  • 5-7 years of experience in technology risk management, ITaudit, or control testing within a regulated FinTech orfinancial services environment.
  • Strong background in assessing IT and cybersecuritycontrols, including experience with cloud environments,DevSecOps practices, and digital payment platforms.
  • Proven ability to perform test of controls (design andoperating effectiveness)
  • Strong understanding of operational processes, riskframeworks, and regulatory requirements.
  • Proficiency in using governance, risk, and compliance(GRC) tools and control testing platforms.
  • Familiarity with IT control frameworks such as NISTCybersecurity Framework, ISO 27001, and COBIT.
  • Proficiency with GRC platforms and testing tools (e.g., RSAArcher, ServiceNow, or LogicGate).
  • Advanced knowledge of data analysis tools (e.g., Excel,SQL) and reporting tools (e.g., Tableau, Power BI).
  • Strong understanding of cloud security, data protection
  • technologies, and cybersecurity protocols.
  • Experience in managing regulatory audits.
  • Ability to work collaboratively with regional and globalpartners in other functional units; ability to navigate acomplex organisation; to influence and lead people acrosscultures at a senior level
  • Excellent problem-solving skills, inquisitive nature andcomfort challenging current practices.
  • Proven track record of taking ideas forward withoutsupervision and challenging others, where appropriate.
  • Adapt at developing relationships with senior businessexecutives with a reputation for partnering acrossorganisation lines to mitigate risks.
  • Highly disciplined, able to work with limited supervision andmake independent decisions.
  • Strong organisational, project management, andmulti-tasking skills with demonstrated ability to manageexpectations and deliver results.
  • High level of professionalism, self-motivation, and sense ofurgency.
  • Bachelor's degree in Computer Science, InformationTechnology, Risk Management, or a related field.
  • Advanced degree (e.g., MS in Cybersecurity, MBA) is aplus.
What you will get in return:
  • Competitive Salary:We believe great work deserves great pay! Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
  • Work-Life Harmony:Join a company that genuinely cares about you -because your life outside of work matters just as much as your time on the clock.
  • Annual Performance Bonus:Your hard work doesn't go unnoticed! Celebrate your achievements with a well-deserved annual bonus tied to your performance.
  • Generous Time Off:Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
  • Employee Referral Program:Love working here? Share the love! Bring your talented friends on board and get rewarded for growing our awesome team.
  • Comprehensive Health & Pension Benefits:From medical insurance to pension plans, we've got your back. Plus, location-specific benefits andperks!
  • Workation Wonderland:Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply). Adventure awaits!
  • Volunteer Days:Make a difference! Take two additional paid days each year to support causes you care about and give back to the community.

Be a key player at the forefront of the digital assets movement, propelling your career to new heights!Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity.Work alongside one of the most brilliant teams in the industry.