Compliance Engineer
Compliance Engineer
Employee type
Permanent
Salary
Competitive
Category
IT
Job Description
Overall purpose of the job:
Provide specific guidance on the operational implementation of controls to support compliance against the following:
* ISO 27001 – Security Management
* Cyber Assessment Framework (CAF)
* Network Information Systems (NIS)
* Centre for Internet Security (CIS) Benchmarks
* IEC 62443
Key responsibilities for this job:
* Define and maintain operational policies, standards, and procedures for compliance against OT and IT security frameworks
* Provide technical compliance guidance to project and engineering teams during new builds and ongoing operations.
* Support the handover and implementation of compliance processes, procedures and controls within operational engineering teams, as part of service implementation or transition
* Map compliance framework objectives to technical controls within the scope of supported assets under contract.
* Ensure adherence to regulatory frameworks (e.g., CAF, ISO, CIS, IEC 62443).
* Ensure adherence to customer contractual compliance obligations.
* Coordinate audits and manage compliance reporting.
* Implement continuous monitoring processes for compliance and risk indicators.
* Provide regular customer aligned reports on compliance status.
Knowledge and experience required:
Strong knowledge of regulatory standards and industry frameworks, including:
* Centre for Internet Security (CIS) benchmarking
* Network and Information Systems (NIS)
* National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF)
* ISO Standards – particularly ISO27001 (Information Security Management)
* IEC 62443 – especially risk management elements