Haystack
← Back to Jobs
Technology
SS

Cyber Security Controls Assessor

Shiv Software Experts LLCOakland, CA🇺🇸United StatesPosted 4 Sept 2026

Why This Role Stands Out

This role offers a significant opportunity to safeguard critical energy infrastructure by assessing and validating vital cybersecurity controls, with strong potential for professional growth. You'll thrive here if you have a solid background in security assessments, risk management, and compliance, particularly within complex IT and OT environments. Apply today to contribute to a vital mission and develop your expertise in a reputable organization.

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Oakland, CA, United States
Posted
17 hours ago
AWSAzure

Job Description

Role: Cyber Security Controls Assessor

Location: Oakland, CA (Local)

Note: Need Only Local Candidates

Position Summary

We are seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments.

The ideal candidate will possess strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations.

Key Responsibilities

Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments.

Evaluate security controls against industry standards and regulatory requirements, including NIST Cybersecurity Framework (CSF), NIST 800-53, NERC CIP, CIS Controls.

Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions.

Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and overall control effectiveness.

Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders to ensure risks are identified and appropriately managed.

Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments.

Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection.

Track remediation activities and validate closure of cybersecurity findings.

Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team.

Required Qualifications

Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, Information Technology, or related field; or equivalent experience.

5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment.

Experience performing security assessments and evaluating cybersecurity controls.

Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies.

Experience with regulatory compliance programs and audit support.

Strong analytical, communication, and technical documentation skills.

Ability to communicate security risks and recommendations to technical and non-technical stakeholders.

Preferred Qualifications

Experience within electric utilities, critical infrastructure, energy, or other regulated industries.

Knowledge of NERC CIP standards and compliance requirements.

Experience assessing Operational Technology (OT), SCADA, Industrial Control Systems (ICS), or energy management systems.

Familiarity with cloud security environments, including Azure and AWS.

Experience with governance, risk, and compliance (GRC) platforms.

Professional certifications such as CISSP, CISA, CRISC, GICSP, Security+, or equivalent

Please share your updated resume at

Similar jobs