Cyber GRC Controls SME - NIST CSF 2.0, Controls Frameworks, Assurance
My client is an instantly recognisable organisation seeking a Cyber GRC Controls SME to support a strategic cyber security controls and governance initiative.
This role requires expertise in enterprise cyber control framework design, control libraries, control taxonomy, control measurement, and framework mapping.
You'll be responsible for assessing and enhancing security controls, supporting governance activities, and ensuring alignment to industry best practice.
Key Requirements
- Strong background in cyber security, governance, risk and controls
- Experience designing and enhancing enterprise security control frameworks
- Proven experience developing and maintaining control libraries
- Strong understanding of control taxonomy, control objectives and control effectiveness measures
- Experience mapping controls to NIST CSF 2.0
- Knowledge of NIST 800-53 and/or ISF Standards of Good Practice
- Experience supporting audits, assurance reviews and regulatory requirements
- Ability to identify control gaps, assess effectiveness and drive improvements
- Excellent stakeholder management and communication skills
Nice to Have
- CISSP, CISM or CRISC certification
- Experience within large enterprise or regulated environments
- Insurance sector experience
- Immediate availability
If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.
If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career.