Overall purpose of the job:
Reporting to the CNI Service Assurance and Orchestration Manager, the overall purpose of the role is to:
- Support regulatory compliance within the scope of Operational Technology (OT) and Information Technology (IT) support services provided
- Provide specific guidance on the operational implementation of controls to support compliance against the following:
- ISO 27001 - Security Management
- Cyber Assessment Framework (CAF)
- Network Information Systems (NIS)
- Center for Internet Security (CIS) Benchmarks
- IEC 62443
Key responsibilities for this job:
Governance
- Define and maintain operational policies, standards, and procedures for compliance against OT and IT security frameworks
- Provide technical compliance guidance to project and engineering teams during new builds and ongoing operations.
- Support the handover and implementation of compliance processes, procedures and controls within operational engineering teams, as part of service implementation or transition
Risk Management
- Identify, assess, and prioritise and compliance risks associated with new implementation projects and existing supported systems.
- Map compliance framework objectives to technical controls within the scope of supported assets under contract.
- Review and update controls based on regular assessment.
Compliance
- Ensure adherence to regulatory frameworks (e.g., CAF, ISO, CIS, IEC 62443).
- Ensure adherence to customer contractual compliance obligations.
- Coordinate audits and manage compliance reporting.
Control Framework
- Define technical compliance controls for projects and operational environments.
- Validate implementation of compliance controls during build phases and monitor effectiveness during support phases.
Monitoring & Reporting
- Implement continuous monitoring processes for compliance and risk indicators.
- Provide regular customer aligned reports on compliance status.
Knowledge and experience required:
- Active SC clearance or eligibility
- Strong knowledge of regulatory standards and industry frameworks, including:
- Center for Internet Security (CIS) benchmarking
- Network and Information Systems (NIS)
- National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF)
- ISO Standards - particularly ISO27001 (Information Security Management)
- IEC 62443 - especially risk management elements
- Expertise in risk assessment methodologies and compliance management tools.
- Excellent communication and stakeholder engagement skills.
- Experience of implementation/governance of technical compliance regimes in an operational context - ideally within an OT environment
- Working knowledge of some or all the following technology types:
- Server operating systems
- Networking
- Fire-walling
- Virtualisation
- Endpoint devices
- Encryption
- Anti-virus and malware
- Vulnerability Management
- Security information and event management (SIEM)
- Intrusion Detection and Prevention systems (IDS and IPS)
#J-18808-Ljbffr
CNI Service Compliance Engineer in Chippenham employer: GCS Recruitment
Join a forward-thinking organisation that values innovation and collaboration, where as a Senior Site Reliability Engineer, you will play a pivotal role in enhancing the reliability and performance of critical banking systems. With a hybrid working model based in Knutsford or Glasgow, you will benefit from a supportive work culture that prioritises continuous improvement and employee growth, alongside opportunities for technical leadership and mentorship. Enjoy a competitive benefits package and the chance to work with cutting-edge technologies in a dynamic environment that fosters professional development.