March 2026
Corporate Security Consultant
Job Description
Role: Corporate Security Consultant / Regulatory Security Consultant
Focus: DORA, MaRisk, NIS2, ICT governance, audit readiness, regulatory change
Role Purpose
We are looking for a Corporate Security Consultant to strengthen our corporate security and regulatory compliance capabilities across IT, governance, access management, and operational resilience.
This role is ideal for someone who understands how regulatory requirements translate into practical organisational controls. You will help ensure the business is secure against internal and external threats by assessing risks, strengthening governance, coordinating security measures, and preparing the organisation for audits, certifications, and regulatory reviews.
The successful candidate will act as a bridge between regulatory requirements and IT delivery teams, providing practical guidance on what must be implemented, evidenced, and maintained to meet obligations under frameworks such as DORA, MaRisk, NIS2, and related supervisory requirements.
Key Responsibilities
Support the design, implementation, and continuous improvement of the corporate security framework across IT security, governance, compliance, and access rights.
Interpret and operationalise regulatory requirements from DORA, MaRisk, NIS2, and related frameworks such as BAIT, VAIT, and relevant EBA guidance. DORA establishes uniform rules for ICT risk and digital operational resilience in the financial sector, while BaFin guidance notes that many DORA requirements align with BAIT/VAIT/ZAIT/KAIT expectations.
Assess current controls, processes, and governance arrangements against regulatory expectations and identify gaps, remediation actions, and priority areas.
Build a deep understanding of how the organisation operates, including key processes, stakeholders, control owners, and lines of responsibility.
Identify the right internal contacts for control design, evidence gathering, audit coordination, and remediation tracking.
Define what information and evidence must be collected to demonstrate compliance and support successful audits, certifications, and supervisory reviews.
Coordinate and support internal and external audits, control assessments, and regulatory examinations.
Work closely with IT, risk, compliance, and business stakeholders to translate regulatory requirements into practical, proportionate measures.
Advise on security governance, risk assessments, control effectiveness, access management, and policy alignment.
Support regulatory change initiatives and ensure security and governance requirements are embedded into transformation and operating model changes.
Promote a sustainable, risk-based approach to corporate security, balancing regulatory requirements with business practicality.
Job Description
Role: Corporate Security Consultant / Regulatory Security Consultant
Focus: DORA, MaRisk, NIS2, ICT governance, audit readiness, regulatory change
Role Purpose
We are looking for a Corporate Security Consultant to strengthen our corporate security and regulatory compliance capabilities across IT, governance, access management, and operational resilience.
This role is ideal for someone who understands how regulatory requirements translate into practical organisational controls. You will help ensure the business is secure against internal and external threats by assessing risks, strengthening governance, coordinating security measures, and preparing the organisation for audits, certifications, and regulatory reviews.
The successful candidate will act as a bridge between regulatory requirements and IT delivery teams, providing practical guidance on what must be implemented, evidenced, and maintained to meet obligations under frameworks such as DORA, MaRisk, NIS2, and related supervisory requirements.
Key Responsibilities
Support the design, implementation, and continuous improvement of the corporate security framework across IT security, governance, compliance, and access rights.
Interpret and operationalise regulatory requirements from DORA, MaRisk, NIS2, and related frameworks such as BAIT, VAIT, and relevant EBA guidance. DORA establishes uniform rules for ICT risk and digital operational resilience in the financial sector, while BaFin guidance notes that many DORA requirements align with BAIT/VAIT/ZAIT/KAIT expectations.
Assess current controls, processes, and governance arrangements against regulatory expectations and identify gaps, remediation actions, and priority areas.
Build a deep understanding of how the organisation operates, including key processes, stakeholders, control owners, and lines of responsibility.
Identify the right internal contacts for control design, evidence gathering, audit coordination, and remediation tracking.
Define what information and evidence must be collected to demonstrate compliance and support successful audits, certifications, and supervisory reviews.
Coordinate and support internal and external audits, control assessments, and regulatory examinations.
Work closely with IT, risk, compliance, and business stakeholders to translate regulatory requirements into practical, proportionate measures.
Advise on security governance, risk assessments, control effectiveness, access management, and policy alignment.
Support regulatory change initiatives and ensure security and governance requirements are embedded into transformation and operating model changes.
Promote a sustainable, risk-based approach to corporate security, balancing regulatory requirements with business practicality.