UK remote
Control Analyst (SDLC and Deployment Controls)
About this role
Anticipated Contract End Date/Length: 3-4 months contract Work Set Up: Hybrid — 3 days per week in office, 2 days remote Our client in the Information Technology and Services industry is looking for a Control Analyst (SDLC and Deployment Controls) to support Cybersecurity Engineering and application teams in meeting software delivery requirements. The role will drive the adoption of Software Development Life Cycle (SDLC) and Deployment (DEPL) controls across internally developed applications and third-party/vendor software solutions, while monitoring compliance, improving evidence quality, identifying risks, supporting remediation, and providing user-focused training and guidance.
The role sits within the first line of defence of the risk management framework and will work closely with application teams, Cyber Management teams, Control Owners, central control functions, audit partners, and wider governance, risk, and compliance stakeholders. What you will do: Define and embed good practice for SDLC and DEPL controls, establish what good compliance looks like, coach teams on best practices, and support remediation of gaps and non-compliance.
Plan and run SDLC and DEPL control-related spot checks for Cyber changes and applications, tracking outcomes, actions, remediation activities, and closure. Support teams in producing complete, accurate, and audit-ready evidence, including testing records, approvals, change records, and other control documentation. Monitor agreed DevOps metrics supporting software delivery, identify trends, outliers, and recurring issues, and recommend appropriate corrective actions.
Create and deliver clear, user-friendly training materials, guidance documents, process documentation, and communications for technical and non-technical audiences. Facilitate workshops and working sessions to clarify expectations, drive decisions, resolve issues, and manage stakeholder queries and engagements in a timely manner. Simplify and improve workflows, processes, and documentation to make SDLC and DEPL compliance easier for engineering delivery teams.
Partner with application delivery teams to improve control adoption and increase the quality, consistency, and completeness of control evidence. Assess, document, and communicate control weaknesses, compliance issues, and delivery risks to Cyber Management, Control Owners, and central governance and control teams. Track and support appropriate escalation, mitigation, and remediation actions for identified control and compliance risks.