NextGen | GTA: A Kelly Telecom Company · 14 hours ago
Telecom Security & Compliance specialist
NextGen, a Kelly Telecom Company, is seeking a Telecom Security & Compliance Specialist to ensure the effectiveness of security, privacy, and technology controls in real-world conditions. The role involves validating controls, identifying weaknesses, and assessing risks across hybrid environments.
Responsibilities
Test design and operating effectiveness of controls across people, process, and technology
Perform end-to-end walkthroughs and re-performance of technical controls
Evaluate evidence quality, favoring system-generated proof over screenshots or attestations
Identify patterns of control failure and assess severity based on regulatory exposure
Test identity, access, and privileged controls, including joiner/mover/leaver processes
Validate security and privacy controls across on-prem, cloud, hybrid, and vendor environments
Assess privacy, data protection, and consent controls involving sensitive data
Support regulatory readiness by aligning testing to enforcement expectations, not theory
Qualification
Required
Operational Effectiveness Tester
Hybrid 3 days in office Mandatory!
US Citizens ONLY due to nature of project
Independently validating that security, privacy, and technology controls operate effectively in real-world conditions
Evidence-based testing, regulatory exposure, and risk across complex, hybrid environments
Evaluates controls end-to-end, identifies systemic weaknesses, and translates technical failures into clear regulatory and business risk for leadership
Test design and operating effectiveness of controls across people, process, and technology
Perform end-to-end walkthroughs and re-performance of technical controls
Evaluate evidence quality, favoring system-generated proof over screenshots or attestations
Identify patterns of control failure and assess severity based on regulatory exposure
Test identity, access, and privileged controls, including joiner/mover/leaver processes
Validate security and privacy controls across on-prem, cloud, hybrid, and vendor environments
Assess privacy, data protection, and consent controls involving sensitive data
Support regulatory readiness by aligning testing to enforcement expectations, not theory
Industry-specific risk and sensitive data handling
Identity & Access Management, including PAM, service accounts, SoD, and emergency access
Cloud and hybrid control testing (AWS, Azure, shared responsibility models)
Privacy and data protection (PII, PCI, consent, retention, incident escalation)
Regulatory drivers and compliance obligations
Control frameworks such as NIST, ISO, SOC 2, COBIT, and internal standards
GRC tools (e.g., ServiceNow, Archer)
CyberArk, SailPoint
Splunk, Sentinel
Vulnerability management tools (Qualys, Tenable)
Cloud platforms (read-only console access)
Audit and evidence management repositories
Preferred
CISA, CISM, CRISC, or ISO 27001 Lead Auditor
CISSP, CCSP, CIPP/US, CIPM, PCI ISA/QSA
CAP or formal NIST RMF training
Benefits
Health, Dental and Vision Benefits
401k
Company
NextGen | GTA: A Kelly Telecom Company
As part of KELLY’s SETT (Science, Engineering, Technology, and Telecom) Business Unit, we are committed to providing state-of-the-art digital infrastructure and telecom engineering solutions for legacy, 5G, and private networks.