- Company Name
- Randstad Technologies
- Job Title
- Cyber Assessment Framework Specialist
- Job Description
-
**Job Title**
Cyber Assessment Framework Specialist
**Role Summary**
Architect, custodian, and administrator of an enterprise Cyber Security Controls Framework. Focuses on governance, design, and continuous improvement, embedding controls across all business units and ensuring alignment with strategy and regulatory requirements.
**Expectations**
- Strengthen cyber resilience through enhanced control visibility and accountability.
- Enable risk‑ and resource‑informed decision‑making for senior stakeholders.
- Break down organisational silos and foster cross‑functional collaboration.
**Key Responsibilities**
- Design, implement, and maintain a cyber security controls framework aligned with business strategy and regulatory demands.
- Act as the central governance authority, ensuring consistency, clarity, and effectiveness across units.
- Embed the framework through ownership models, accountability structures, and aligned governance processes.
- Apply design‑thinking and systems‑thinking to improve control visibility, usability, and sustainability.
- Establish mechanisms to monitor, assess, and report on control health, maturity, and effectiveness.
- Provide transparent insights into cyber risk, control gaps, and resource prioritisation.
- Facilitate collaboration between security, risk, technology, and business stakeholders.
- Support internal and external audit and assurance activities related to cyber governance.
- Drive continuous improvement of governance processes based on feedback, performance data, and evolving threat landscapes.
**Required Skills**
- Proven experience in cyber security governance, risk, and control frameworks (NIST, ISO 27001, CIS, COBIT).
- Expertise in cyber assessment frameworks and control lifecycle management.
- Experience operating within large, complex, or regulated enterprises.
- Ability to influence and engage senior stakeholders without direct authority.
- Strong analytical capability; translate technical risk into business‑focused insights.
- Excellent communication, facilitation, and stakeholder‑management skills.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related discipline.
- Relevant certifications preferred: CISSP, CISM, ISO 27001 Lead Implementer, or equivalent.