Robert Walters is working in partnership with a global services business.
They are recognised on having a strong focus on customer satisfaction, innovation whilst providing a range of bespoke services and solutions.
Due to several projects, they are keen to appoint a Cyber Security Risk & Assurance SME to lead a number of Data Driven and Cyber Data Assurance projects.
Cyber Security Risk & Assurance SME: Duties
- Provide cyber risk and assurance input across all stages of data discovery, onboarding, testing, go-live, and service transition.
- Evaluate metrics, data sources, and assessment logic to ensure reliable insights into control effectiveness and residual risk.
- Validate PAI results against evidence from reporting, assessments, risk registers, audits, incidents, and exceptions.
- Identify material gaps in data, controls, or reporting and coordinate actions with relevant stakeholders.
- Deliver clear assurance findings and recommendations to project teams, GRC, Metric Owners, Insight Leads, and governance forums.
- Maintain traceable records of assurance evidence, decisions, limitations, and risk acceptances.
- Review discovery outputs and API integration documents for ownership, data lineage, completeness, security, and assurance needs.
- Establish practical acceptance criteria and evidence requirements for onboarding milestones and Jira stories.
- Validate data mappings, normalization, and entity resolution from a cyber control perspective.
- Review assessment logic, thresholds, exclusions, and exception handling with PAI, DDS, GRC, and Metric Owners.
- Define and execute risk-based test scenarios; reconcile PAI results with source evidence or manual reporting.
Cyber Security Risk & Assurance SME: Experience
Essential:
Ability to understand structured data, data lineage, APIs, security telemetry and integrations sufficiently to challenge data completeness and fitness for purpose.
Experience defining acceptance criteria, supporting testing/UAT and documenting requirements, issues and decisions
Cyber Security Risk, Security Assurance, Controls Testing, GRC, Vulnerability Management
Assess control design, Endpoint security, Cloud, Identity, Secure Development, Third-Party risk, Incident Management
Desirable:
CISSP, CISM, CRISC, CISA, ISO 27001 Lead Auditor/Implementer or equivalent experience.
Knowledge of NIST CSF, ISO/IEC 27001, COBIT, CIS Controls or enterprise risk frameworks.
Experience with SQL, JSON/CSV, APIs, Power BI or data quality controls.
Experience with Azure, AWS or GCP security controls.
Experience with security data platforms, knowledge graphs, exposure management platforms or PAI.
The contract opportunity for a Cyber Security Risk & Assurance SME will be on a 6-month rolling basis, with a hybrid/remote working model.
It will pay a competitive day rate up to £700 per day Outside IR35.