Cyber Security Risk & Assurance SME
Robert Walters is working in partnership with a global services business. They are recognised on having a strong focus on customer satisfaction, innovation whilst providing a range of bespoke services and solutions.
Due to several projects, they are keen to appoint a Cyber Security Risk & Assurance SME to lead a number of Data Driven and Cyber Data Assurance projects.
Cyber Security Risk & Assurance SME: Duties
- Provide cyber risk and assurance input across all stages of data discovery, onboarding, testing, go-live, and service transition.
- Evaluate metrics, data sources, and assessment logic to ensure reliable insights into control effectiveness and residual risk.
- Validate PAI results against evidence from reporting, assessments, risk registers, audits, incidents, and exceptions.
- Identify material gaps in data, controls, or reporting and coordinate actions with relevant stakeholders.
- Deliver clear assurance findings and recommendations to project teams, GRC, Metric Owners, Insight Leads, and governance forums.
- Maintain traceable records of assurance evidence, decisions, limitations, and risk acceptances.
- Review discovery outputs and API integration documents for ownership, data lineage, completeness, security, and assurance needs.
- Establish practical acceptance criteria and evidence requirements for onboarding milestones and Jira stories.
- Validate data mappings, normalization, and entity resolution from a cyber control perspective.
- Review assessment logic, thresholds, exclusions, and exception handling with PAI, DDS, GRC, and Metric Owners.
- Define and execute risk-based test scenarios; reconcile PAI results with source evidence or manual reporting.
Cyber Security Risk & Assurance SME: Experience
Essential:
- Ability to understand structured data, data lineage, APIs, security telemetry and integrations sufficiently to challenge data completeness and fitness for purpose.
- Experience defining acceptance criteria, supporting testing/UAT and documenting requirements, issues and decisions
- Cyber Security Risk, Security Assurance, Controls Testing, GRC, Vulnerability Management
- Assess control design, Endpoint security, Cloud, Identity, Secure Development, Third-Party risk, Incident Management
Desirable:
- CISSP, CISM, CRISC, CISA, ISO 27001 Lead Auditor/Implementer or equivalent experience.
- Knowledge of NIST CSF, ISO/IEC 27001, COBIT, CIS Controls or enterprise risk frameworks.
- Experience with SQL, JSON/CSV, APIs, Power BI or data quality controls.
- Experience with Azure, AWS or GCP security controls.
- Experience with security data platforms, knowledge graphs, exposure management platforms or PAI.
The contract opportunity for a Cyber Security Risk & Assurance SME will be on a 6-month rolling basis, with a hybrid/remote working model. It will pay a competitive day rate up to £700 per day Outside IR35.
For further information, please apply with an updated CV and contact Ajay Hayre on or
Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates