> Markdown version of [/jobs/ext/3151394-security-control-framework-engineer-policy-as-code-and-automated-ssp-for-nato-with-security-clearance](https://www.wearedevelopers.com/jobs/ext/3151394-security-control-framework-engineer-policy-as-code-and-automated-ssp-for-nato-with-security-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Control Framework Engineer (Policy-as-Code and Automated SSP) for NATO with security clearance - **Company:** WLG - **Location:** Den Haag, Netherlands - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Interoperability, JSON, YAML, Policy as Code - **Published:** September 2, 2026 - **Apply:** https://www.adzuna.nl/details/5865346738 ## About the Role * A bachelor's degree in a related discipline with three years of related experience * Three years across all of: NIST and ISO control frameworks; confident JSON and YAML; and regulatory mapping * Translating compliance requirements into code * Documented experience of process analysis and design Nice to have * Real technical knowledge of how allied organisations achieve interoperability * A working understanding of defence cloud strategy * ITIL, COBIT or an equivalent ## Description A control catalogue written in prose cannot be checked by a machine. Your job would be to change that. A multinational defence organisation in The Hague, Netherlands is digitising its security control baseline so that compliance can be measured continuously rather than audited once a year. You would architect the translation - from written standards to structured, machine-readable control data. What you would be doing * Reviewing the existing security requirement statements and the NIST or ISO baseline behind them, ready for conversion * Importing that baseline into a structured, machine-readable control format * Identifying and documenting the technical triggers that the cloud environment can raise * Mapping those triggers to specific control identifiers - policy as code * Reviewing sampled automated evidence for completeness, accuracy and fitness to support a system security plan * Generating the first full system security plan from automated evidence rather than by hand * Running stakeholder sessions to validate the assumptions, mappings, evidence sources and the generation logic * Tracking issues through to remediation