Senior Technical Advisor - Operational Resilience
Our client is a public-sector regulatory organisation with responsibility for overseeing critical communications, digital and technology services in Ireland.
The organisation is entering an exciting period of growth as it takes on additional statutory responsibilities relating to cybersecurity, operational resilience, critical infrastructure, artificial intelligence, cloud, data and accessibility.
As the regulatory landscape continues to evolve, the organisation is expanding its specialist capabilities to support the implementation and supervision of new European and Irish regulatory requirements, including NIS2, the Critical Entities Resilience (CER) Directive, the EU Data Act, the EU AI Act and the European Accessibility Act.
This is an opportunity to join a professional, multidisciplinary team operating at the intersection of technology, regulation, cybersecurity and national resilience.
We are seeking a Senior Technical Advisor - Operational Resilience to provide specialist expertise across operational resilience, cybersecurity and regulatory supervision.
The successful candidate will play a key role in assessing how regulated organisations identify, manage and mitigate operational resilience risks. The role will involve working across both cyber and physical resilience, applying an all-hazards approach to ensure organisations can prevent, withstand, respond to and recover from disruptive incidents.
You will contribute to regulatory assessments, inspections, audits and enforcement activities, while also providing expert input into wider national resilience initiatives.
The position will involve engagement with senior stakeholders across industry, government, regulatory bodies and European working groups.
Provide specialist operational resilience expertise across regulatory assessments, inspections and audits.
Support the identification and designation of critical entities under the CER framework.
Analyse organisations potentially falling within the scope of critical infrastructure and resilience legislation.
Assess whether resilience measures are proportionate, risk-based and effectively implemented across both cyber and physical domains.
Evaluate the implementation of an all-hazards resilience approach, including preparedness for natural disasters, sabotage, terrorism and infrastructure or technology failure.
Lead and support regulatory supervision, remediation, follow-up assessments, audits and, where required, enforcement activity.
Provide expert input into the development of national operational resilience and critical infrastructure strategies.
Represent the organisation at relevant national and European operational resilience forums and working groups.
Develop constructive relationships with regulated organisations, government bodies, regulators and other key stakeholders.
Lead, coordinate and manage specialist resources, including internal resilience professionals and external advisors.
Mentor and develop colleagues, supporting continuous improvement and the growth of organisational capability.
The successful candidate will have:
An honours degree or equivalent third-level qualification in cybersecurity, science, technology, engineering or a related discipline, or significant relevant senior-level experience.
Significant recent experience in a senior operational resilience, cybersecurity, risk, assurance or regulatory role.
Demonstrable experience working within a regulated or regulatory environment.
Strong experience in operational resilience, particularly across advisory, assurance, risk management, audit or compliance functions.
Experience operating within complex technology or infrastructure environments, ideally across areas such as digital infrastructure, digital services, ICT, telecommunications, cloud or other critical sectors.
The following would be advantageous:
Experience applying recognised cybersecurity, resilience and risk frameworks such as ISO 27001, NIST CSF, DORA or GDPR.
Strong understanding of risk-based supervision and regulatory enforcement.
Experience conducting or supporting inspections, audits, compliance assessments or regulatory reviews.
Experience working with European regulatory legislation such as CER, NIS/NIS2, DORA or GDPR.
Relevant professional qualifications such as CISSP, CISM, CRISC, CISA or ISO 27001 Lead Auditor.
Senior-level experience in risk assessment, IT audit, information security assurance or operational resilience.
Demonstrable experience engaging and influencing senior internal and external stakeholders.
Experience managing technical teams, programmes, projects or specialist resources.
A master's degree or postgraduate qualification in cybersecurity, technology, data analytics or a related discipline.
Experience delivering large-scale regulatory, security or operational resilience programmes.
Experience developing evidence-based resilience assurance models incorporating documentation review, technical testing and control validation.
Experience engaging with Irish or European regulatory authorities or National Competent Authorities.
Confidently communicates complex technical and regulatory issues to a wide range of stakeholders. Builds credibility and is able to influence senior decision-makers.
Uses evidence and sound judgement to assess complex situations, evaluate alternative approaches and make well-reasoned decisions.
Able to analyse complex information, identify relationships and risks, and develop practical, evidence-based solutions.
Strong technical and professional knowledge of operational resilience, cybersecurity, risk or assurance. Demonstrates curiosity and a commitment to developing expertise as the regulatory landscape evolves.
Works collaboratively across multidisciplinary teams, builds trusted relationships and supports the development of colleagues and organisational capability.
