questionnaires, policies, certifications, audit reports, penetration testing results, independent assurance reports, and supporting evidence.Evaluate control effectiveness against recognised frameworks and standards including ISO 27001, NIST Cybersecurity Framework, SOC reports, DORA, and relevant SWIFT security requirements.Identify security gaps, residual risks, and compensating controls, providing clear risk ratings and recommendations to stakeholders.Supplier … experience conducting security assessments of cloud providers, SaaS vendors, technology suppliers, and outsourced service providers.Strong understanding of security frameworks and standards including ISO 27001, NIST, SOC 1/2, CIS Controls, and cloud security best practices.Experience evaluating security controls across identity management, network security, encryption, vulnerability management, incident response, resilience ...