Cybersecurity Lead
Listed on 2026-09-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations, IT Consultant
The post is budgeted from 1 January 2027 and the successful candidate is expected to start employment as soon as possible thereafter.
1. OVERVIEW OF DIANA
NATO DIANA is the Defence Innovation Accelerator for the North Atlantic a NATO body dedicated to finding and accelerating innovation to provide decisive defence and security effects for the Alliance while fostering deep-tech innovation. NATO DIANA is comprised of a Board of Directors representing all 32 nations and an operational team referred to as the DIANA Executive (DX). Operating from three offices in Europe and North America the DX leverages a network of military end users world-leading accelerator sites test centres professional mentors and experts and Allied expertise to accelerate the most innovative technologies from across the NATO Alliance.
DIANA is a dynamic agile workplace which strives for innovative thinking diversity and performance excellence across all teams. To achieve our mission DIANA is committed to providing our people with an environment that is positive inclusive and collaborative.
2. OVERVIEW OF THE ROLE
The Safety Security & Resilience (SSR) Team is responsible for safeguarding DIANAs people information facilities and digital assets. The team develops and maintains proportionate frameworks policies controls and assurance arrangements across cyber security information security physical security safety and security risk management to enable secure safe and resilient operations across DIANA. The Cybersecurity Lead is responsible for delivering DIANAs cyber security activities ensuring the secure and resilient operation of its cloud digital and business technology services along with cyber security architectural role combines hands-on technical expertise with responsibility for cyber governance risk management compliance resilience and assurance embedding security by design across the organisation.
* Reserve candidates may be considered for similar posts in Estonia or Canada if appropriate.*
Reporting toDIANAs Head of Safety Security & Resilience
Duties of this role include:
- Lead the development implementation and continual improvement of DIANAs cyber security security architecture governance framework risk-management arrangements and assurance programme building in security by design principles.
- Establish and manage cyber security policies standards control frameworks risk registers security metrics and assurance documentation.
- Lead and oversee security risk assessments for DIANA Digital assets.
- Provide second-line challenge oversight and assurance across technology projects suppliers cloud platforms SaaS applications AI solutions and operational processes ensuring that risks are identified assessed treated and escalated appropriately.
- Lead cyber security incident responseassurance and risk management activities including for suppliers service providers and third-party technology partners.
- Lead internal and external audit assurance accreditation and certification activities against relevant standards and assurance frameworks including ISO/IEC 27001 NIST Cybersecurity Framework NIST SP 800-53 Cyber Essentials Plus CIS Benchmarks and applicable NATO security-accreditation expectations.
- Provide guidance mentoring or managerial leadership as required to enable collaboration capability development and successful delivery.
- Perform any other related duties as may be required.
3. ROLE REQUIREMENTS QUALIFICATIONS AND EXPERIENCE
ESSENTIAL
The incumbent must have:
A minimum requirement of a Bachelors degree at a nationally recognised/certified University in Cyber Security Information Security Computer Science Information Technology Engineering Digital Forensics Networks or a closely related technical discipline and 3 years post-related experience OR exceptionally the lack of a university degree may be compensated by at least 10 years extensive and progressive expertise in duties related to the function of the post.
A minimum of 3 years professional experience in cyber security cloud security security architecture information assurance or related technology-security roles.
Arecognized cyber security qualification (e.g. CISSP CCSP CCSK or equivalent).
Enterpriseor security architecture qualifications (e.g. TOGAF or equivalent).
Proven experience working in government defence law-enforcement national security critical infrastructure NATO or equivalent high-assurance sectors handling sensitiveregulatedor classified information.
Proven experience leading cyber security governance risk management assurance security accreditation audit and control validation activities including the application of recognised security standards frameworks and principles.
Proven experience in taking an organisation through ISO 27001 certification and other benchmarks such as Cyber Security Plus.
Proven experience designing implementing securing and assuring enterprise cloud and digital technology environments particularly Microsoft Azure and Microsoft 365 including identity and access…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: