Description
* End-to-end leadership of one or more blocks of the Cybersecurity Master Plan (maturity diagnosis, definition of strategic lines, roadmap, and prioritized initiatives), with full accountability for client-facing deliverables.
* Definition of the maturity analysis methodology aligned with reference frameworks (NIST CSF, ISO/IEC 27001, ENS, CIS Controls) and facilitation of interviews with domain owners to identify gaps against the target state.
* Definition of the cybersecurity dashboard (KPIs/KRIs) aligned with the client’s business objectives, and formulation of prioritized recommendations—including justification of business impact and risk implications—based on that dashboard.
* Autonomous facilitation of working sessions with the CISO and mid-level management, and co-presentation of findings and recommendations to senior leadership, tailoring messaging to either executive or technical audiences and defending positions rigorously against objections.
* Development of periodic security posture reports serving as a foundation for strategic decision-making, ensuring quality assurance (QA) of workflow deliverables prior to submission.
* Support in aligning cyber strategy with corporate governance frameworks (ISO 38500, COBIT, NIST AI RMF for AI-related projects), including autonomous cross-mapping between frameworks.
* Design of the cybersecurity governance model (roles, responsibilities, committees, and reporting flows) and facilitation of validation workshops with relevant internal stakeholders.
* Coordination of 1–2 junior team members: task assignment, quality review of their deliverables, and methodological mentoring.
* Day-to-day workflow management: scheduling of assigned timeline portions, progress tracking, and stakeholder relationship management within the client’s designated scope.
* Experience: \+5 years in cybersecurity or GRC consulting, with at least 2 years focused on developing Master Plans or conducting maturity assessments.
* English level: C1 (or upper B2 with demonstrated fluency in executive meetings).
* Valuable certifications: CRISC, CISM, or equivalent;