Compliance-as-Code Architect (NIST/ISO, JSON and YAML) for NATO with security clearance

WLG

Den Haag

On-site

EUR 90,000 - 120,000

Full time

15 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

WLG is seeking a security architect to translate written controls into a machine-readable catalogue and generate a complete system security plan from automated evidence. You will map NIST/ISO baselines to structured data, defining the triggers a cloud environment can raise and aligning them with control identifiers.

Collaboration with stakeholders to validate assumptions and mappings, plus remediation tracking, will be part of your responsibilities.

Qualifications

  • Bachelor's degree in a related discipline.
  • Three years across NIST and ISO control frameworks; JSON and YAML; regulatory mapping.
  • Translating compliance requirements into code.
  • Documented experience of process analysis and design.

Responsibilities

  • Review existing security requirement statements and the NIST/ISO baseline behind them.
  • Import the baseline into a structured, machine-readable control format.
  • Identify the technical triggers the cloud environment can raise.
  • Map triggers to specific control identifiers — policy as code.
  • Review sampled automated evidence for completeness and accuracy.
  • Generate the first full system security plan from automated evidence.
  • Run stakeholder sessions to validate mappings and generation logic.
  • Track issues through to remediation.

Skills

Regulatory mapping
Process analysis
Translate compliance to code
Security architecture

Education

Bachelor's degree in a related discipline

Tools

JSON
YAML

Job description

A control catalogue written in prose cannot be checked by a machine. Your job would be to change that. A multinational defence organisation in The Hague, Netherlands is digitising its security control baseline so that compliance can be measured continuously rather than audited once a year. You would architect the translation — from written standards to structured, machine-readable control data.

What You Would Be Doing
  • Reviewing the existing security requirement statements and the NIST or ISO baseline behind them, ready for conversion
  • Importing that baseline into a structured, machine-readable control format
  • Identifying and documenting the technical triggers that the cloud environment can raise
  • Mapping those triggers to specific control identifiers — policy as code
  • Reviewing sampled automated evidence for completeness, accuracy and fitness to support a system security plan
  • Generating the first full system security plan from automated evidence rather than by hand
  • Running stakeholder sessions to validate the assumptions, mappings, evidence sources and the generation logic
  • Tracking issues through to remediation
What you would bring
  • A bachelor's degree in a related discipline with three years of related experience
  • Three years across all of: NIST and ISO control frameworks; confident JSON and YAML; and regulatory mapping
  • Translating compliance requirements into code
  • Documented experience of process analysis and design
Nice to have
  • Real technical knowledge of how allied organisations achieve interoperability
  • A working understanding of defence cloud strategy
  • ITIL, COBIT or an equivalent
Why this one is worth a look

Very few architects have taken a real control catalogue all the way into code and out again as a generated security plan. This is that piece of work, on a serious estate.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance-as-Code Architect (NIST/ISO, JSON and YAML) for NATO with security clearance
Compliance-as-Code Architect (NIST/ISO, JSON and YAML) for NATO with security clearance

Wlgroup • Den Haag

On-site
EUR 70,000 - 95,000
OSCAL Architect (Security Controls as Code) for NATO with security clearance
OSCAL Architect (Security Controls as Code) for NATO with security clearance

Wlgroup • Den Haag

On-site
EUR 70,000 - 110,000
Security Control Framework Engineer (Policy-as-Code and Automated SSP) for NATO with security clearance
Security Control Framework Engineer (Policy-as-Code and Automated SSP) for NATO with security clearance

Wlgroup • Den Haag

On-site
EUR 80,000 - 120,000
OSCAL Architect (Security Controls as Code) for NATO with security clearance
OSCAL Architect (Security Controls as Code) for NATO with security clearance

WLG • Den Haag

On-site
EUR 90,000 - 120,000
Compliance Automation Engineer (Kubernetes, CI/CD, Cloud APIs) for NATO with security clearance
Compliance Automation Engineer (Kubernetes, CI/CD, Cloud APIs) for NATO with security clearance

WLG • Den Haag

On-site
EUR 65,000 - 95,000
Platform Engineer (Continuous Compliance and Identity Integration) for NATO with security clearance
Platform Engineer (Continuous Compliance and Identity Integration) for NATO with security clearance

WLG • Den Haag

On-site
EUR 60,000 - 90,000
Compliance-as-Code Architect: NIST/ISO to Auto Plans
Compliance-as-Code Architect: NIST/ISO to Auto Plans

Wlgroup • Den Haag

On-site
EUR 70,000 - 95,000
Compliance Automation Engineer (Kubernetes, CI/CD, Cloud APIs) for NATO with security clearance
Compliance Automation Engineer (Kubernetes, CI/CD, Cloud APIs) for NATO with security clearance

Wlgroup • Den Haag

On-site
EUR 75,000 - 110,000
Platform Engineer (Continuous Compliance and Identity Integration) for NATO with security clearance
Platform Engineer (Continuous Compliance and Identity Integration) for NATO with security clearance

Wlgroup • Den Haag

On-site
EUR 65,000 - 95,000
DevSecOps Engineer (Policy Automation and Evidence Pipelines) for NATO with security clearance
DevSecOps Engineer (Policy Automation and Evidence Pipelines) for NATO with security clearance

Wlgroup • Den Haag

On-site
EUR 90,000 - 130,000