about the company
Our client is a fast-growing technology company operating within a highly regulated environment where cybersecurity, governance and operational resilience are critical to business success. The organization emphasizes strong security governance, continuous improvement and technical excellence while supporting modern cloud and enterprise infrastructure.
This role offers the opportunity to work closely with engineering teams while developing hands-on expertise in technical security governance.
...
about the job
We are looking for an IT Governance Analyst who combines strong governance knowledge with practical technical experience. Unlike traditional audit-focused roles, this position requires someone who can independently validate technical security controls, review enterprise configurations and work directly with engineering teams to ensure systems comply with organizational security policies and regulatory requirements.
You will play a key role in strengthening the organization's security governance framework by performing technical reviews, validating security configurations and supporting compliance initiatives across cloud and enterprise environments.
Key Responsibilities
- Perform technical governance reviews across enterprise infrastructure, cloud platforms and identity management systems.
- Independently review and validate security configurations within AWS, Microsoft 365, Active Directory, Group Policy (GPO), Google Workspace or other enterprise platforms.
- Conduct IT security compliance assessments and verify that security controls are implemented according to internal policies and regulatory requirements.
- Collect and review technical evidence to support internal audits, external audits and customer due diligence requests.
- Work closely with infrastructure, cloud and security engineering teams to identify control gaps and recommend practical remediation.
- Assist in developing, maintaining and improving IT security policies, standards, procedures and governance documentation.
- Monitor regulatory requirements and industry best practices to ensure ongoing compliance.
- Prepare governance reports, risk assessments and management presentations for key stakeholders.
Preferred Skills & Experience
- Minimum 5 years of experience in IT Governance, Information Security, Cybersecurity Engineering or Infrastructure Security.
- Hands-on experience administering or reviewing enterprise technologies such as:
- AWS
- Microsoft 365
- Active Directory
- Group Policy (GPO)
- Google Workspace
- Identity & Access Management (IAM)
- Privileged Access Management (PAM)
- Strong understanding of security frameworks and standards including:
- ISO 27001
- NIST Cybersecurity Framework
- CIS Controls
- PCI DSS
- Regulatory compliance requirements
- Experience performing technical security reviews, compliance assessments or infrastructure validation.
- Ability to independently validate security configurations rather than relying solely on audit evidence.
- Strong analytical and problem-solving skills with the ability to work collaboratively across technical teams.
- Excellent communication skills for engaging technical and non-technical stakeholders.
Nice to Have
- Experience supporting cloud security governance across AWS or Azure environments.
- Knowledge of vulnerability management, endpoint security or security monitoring platforms.
- Professional certifications such as ISO 27001 Lead Implementer/Auditor, Security+, CISSP, CISA, CCSP or equivalent.
- Experience working in regulated industries such as Financial Services, FinTech or Technology.
about the manager/team
You will be joining a collaborative cybersecurity team responsible for strengthening enterprise governance, security compliance and operational resilience. Working closely with cloud engineers, infrastructure teams and security professionals, you'll gain exposure to modern enterprise technologies while contributing to the continuous improvement of the organization's cybersecurity governance capabilities.
This role is ideal for professionals who enjoy combining technical expertise with governance responsibilities and want to play an active role in improving enterprise security.