Company Description
Who is HelloKindred?
HelloKindred are specialists in staffing marketing, creative and technology roles, offering a range of talent solutions that can be delivered on-site, remotely or hybrid.
Our vision is to make work accessible and people’s lives better. We do this by disrupting traditional employment barriers – connecting ambitious talent to flexible opportunities with trusted brands.
Job Description
Anticipated Contract End Date/Length: 3-4 months contract
Work Set Up: Hybrid — 3 days per week in office, 2 days remote
Our client in the Information Technology and Services industry is looking for a Control Analyst (SDLC and Deployment Controls) to support Cybersecurity Engineering and application teams in meeting software delivery requirements. The role will drive the adoption of Software Development Life Cycle (SDLC) and Deployment (DEPL) controls across internally developed applications and third-party/vendor software solutions, while monitoring compliance, improving evidence quality, identifying risks, supporting remediation, and providing user-focused training and guidance.
The role sits within the first line of defence of the risk management framework and will work closely with application teams, Cyber Management teams, Control Owners, central control functions, audit partners, and wider governance, risk, and compliance stakeholders.
What you will do:
- Define and embed good practice for SDLC and DEPL controls, establish what good compliance looks like, coach teams on best practices, and support remediation of gaps and non-compliance.
- Plan and run SDLC and DEPL control-related spot checks for Cyber changes and applications, tracking outcomes, actions, remediation activities, and closure.
- Support teams in producing complete, accurate, and audit-ready evidence, including testing records, approvals, change records, and other control documentation.
- Monitor agreed DevOps metrics supporting software delivery, identify trends, outliers, and recurring issues, and recommend appropriate corrective actions.
- Create and deliver clear, user-friendly training materials, guidance documents, process documentation, and communications for technical and non-technical audiences.
- Facilitate workshops and working sessions to clarify expectations, drive decisions, resolve issues, and manage stakeholder queries and engagements in a timely manner.
- Simplify and improve workflows, processes, and documentation to make SDLC and DEPL compliance easier for engineering delivery teams.
- Partner with application delivery teams to improve control adoption and increase the quality, consistency, and completeness of control evidence.
- Assess, document, and communicate control weaknesses, compliance issues, and delivery risks to Cyber Management, Control Owners, and central governance and control teams.
- Track and support appropriate escalation, mitigation, and remediation actions for identified control and compliance risks.
- Extract, transform, analyse, and report compliance and operational control data using APIs, Excel Power Query, and other appropriate reporting, automation, and data analysis tools.
- Work across Cybersecurity project and product teams, application owners, engineering and delivery teams, Control Owners, Cyber Management, central control functions, audit partners, and wider governance, risk, and compliance stakeholders.
- Support adherence to SDLC and DEPL controls and evidence quality while maintaining clear ownership of delivery activities within engineering teams and control responsibilities with designated Control Owners.
Qualifications
- Demonstrate experience working in an Agile software delivery environment as a Change or Control Analyst, Business Analyst, Test Analyst, or similar role.
- Demonstrate experience defining, collecting, and presenting evidence to meet control, audit, or assurance expectations.
- Demonstrate working knowledge of change delivery processes and tooling, including ServiceNow or equivalent platforms.
- Demonstrate understanding of Governance, Risk and Compliance concepts and control-based ways of working.
- Demonstrate strong stakeholder management skills, including the ability to facilitate workshops and influence delivery teams.
- Demonstrate strong reporting and analysis skills using Excel, PowerPoint, and Visio or equivalent process-mapping tools.
- Demonstrate strong written and spoken English communication skills.
- Demonstrate strong understanding of Software Development Lifecycle and Deployment controls within software delivery environments.
- Demonstrate experience implementing, assessing, or managing SDLC and Deployment controls across internally developed applications and third-party/vendor software solutions.
- Demonstrate experience extracting, transforming, analysing, and reporting data using APIs, Excel Power Query, or similar reporting, automation, and data analysis tools.
- Demonstrate ability to assess, articulate, and communicate compliance risks, control weaknesses, and remediation requirements to technical teams, Cyber Management, and central governance and control functions.
- Demonstrate experience creating user-facing guidance, training materials, and process documentation for technical and non-technical audiences.
- Demonstrate ability to work independently, manage competing priorities, and drive activities through to successful completion with minimal supervision.
- Demonstrate experience working with DevOps metrics and software delivery performance measures.
- Hold a relevant industry certification such as IIBA, ITIL, Agile, or SAFe certification.
- Demonstrate hands-on experience with QA or test management tools such as qTest, Tricentis, or Zephyr.
- Demonstrate knowledge of application security testing and scanning concepts, including SAST, DAST, MAST, and vulnerability management.
- Demonstrate experience working with Jira, Confluence, ServiceNow, Excel Power Query, Google Data Studio, or equivalent tools.
- Demonstrate ability to work at pace across multiple stakeholders, priorities, and deadlines while proactively sharing knowledge and improving wider team operations.
Additional Information
Candidates must be legally authorized to live and work in the country where the position is based, without requiring employer sponsorship.
HelloKindred is committed to fair, transparent, and inclusive hiring practices. We assess candidates based on skills, experience, and role-related requirements.
We appreciate your interest in this opportunity. While we review every application carefully, only candidates selected for an interview will be contacted.
HelloKindred is an equal opportunity employer. We welcome applicants of all backgrounds and do not discriminate on the basis of race, colour, religion, sex, gender identity or expression, sexual orientation, age, national origin, disability, veteran status, or any other protected characteristic under applicable law.