> Markdown version of [/jobs/ext/2976924-cyber-security-risk-assurance-sme](https://www.wearedevelopers.com/jobs/ext/2976924-cyber-security-risk-assurance-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Risk & Assurance SME - **Company:** Robert Walters plc - **Location:** United States (Remote available) - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, JIRA, Microsoft Azure, Cloud Computing, Control Objectives for Information and Related Technology (COBIT), Data Discovery, Graph Database, JSON, Power BI, Secure Coding, SQL Databases, Systems Integration, Software Vulnerability Management, Google Cloud, Data Lineage, Data Management, CIS Benchmarks, Golang - **Published:** September 18, 2026 - **Apply:** https://computerjobs.com/us/en/mob/job/8BEAFEE1D7C6DDE665 ## About the Role * Ability to understand structured data, data lineage, APIs, security telemetry and integrations sufficiently to challenge data completeness and fitness for purpose. * Experience defining acceptance criteria, supporting testing/UAT and documenting requirements, issues and decisions * Cyber Security Risk, Security Assurance, Controls Testing, GRC, Vulnerability Management * Assess control design, Endpoint security, Cloud, Identity, Secure Development, Third-Party risk, Incident Management Desirable: * CISSP, CISM, CRISC, CISA, ISO 27001 Lead Auditor/Implementer or equivalent experience. * Knowledge of NIST CSF, ISO/IEC 27001, COBIT, CIS Controls or enterprise risk frameworks. * Experience with SQL, JSON/CSV, APIs, Power BI or data quality controls. * Experience with Azure, AWS or GCP security controls. * Experience with security data platforms, knowledge graphs, exposure management platforms or PAI. ## Description Due to several projects, they are keen to appoint a Cyber Security Risk & Assurance SME to lead a number of Data Driven and Cyber Data Assurance projects. Cyber Security Risk & Assurance SME: Duties * Provide cyber risk and assurance input across all stages of data discovery, onboarding, testing, go-live, and service transition. * Evaluate metrics, data sources, and assessment logic to ensure reliable insights into control effectiveness and residual risk. * Validate PAI results against evidence from reporting, assessments, risk registers, audits, incidents, and exceptions. * Identify material gaps in data, controls, or reporting and coordinate actions with relevant stakeholders. * Deliver clear assurance findings and recommendations to project teams, GRC, Metric Owners, Insight Leads, and governance forums. * Maintain traceable records of assurance evidence, decisions, limitations, and risk acceptances. * Review discovery outputs and API integration documents for ownership, data lineage, completeness, security, and assurance needs. * Establish practical acceptance criteria and evidence requirements for onboarding milestones and Jira stories. * Validate data mappings, normalization, and entity resolution from a cyber control perspective. * Review assessment logic, thresholds, exclusions, and exception handling with PAI, DDS, GRC, and Metric Owners. * Define and execute risk-based test scenarios; reconcile PAI results with source evidence or manual reporting. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)