Cybersecurity Compliance Architect

spektrum

Den Haag

On-site

EUR 70,000 - 95,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Spektrum supports the NATO Communications and Information Agency (NCIA) in The Hague, moving toward Continuous Authorization to Operate (cATO) and RegOps using OSCAL data models. The team will deploy RegScale as a workload and deliver a MVP for cATO, collaborating across CDT and SACT to modernize governance.

The role requires at least 3 years’ experience with NIST/ISO, regulatory mapping, and compliance-to-code translation, with strong JSON/YAML skills for OSCAL formats and evidence-driven SSP

Qualifications

  • Minimum of 3 years' experience with NIST/ISO frameworks and regulatory mapping.
  • Proficiency in JSON and YAML schemas for OSCAL/RegOps.
  • Experience translating compliance requirements into code (Compliance-to-code).
  • Experience with process analysis and design techniques.

Responsibilities

  • Review SRS, D32/CSRS, and NIST/ISO baseline for OSCAL conversion.
  • Identify and document relevant technical triggers from the cloud environment.
  • Review automated evidence for SSP content accuracy and completeness.
  • Conduct Stakeholder Review Sessions to validate mappings and SSP logic.
  • Provide issue tracking and remediation support.

Skills

NIST/ISO frameworks
JSON/YAML proficiency
Regulatory mapping
Compliance-to-code translation
Process analysis & design

Job description

Who we are supporting

Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.

The NCIA provides a wide range of services, including:
  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.

The program

Assistance and Advisory Service (AAS)

The NATO Communications and Information Agency (NCI Agency) is NATO's principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.

To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.

Role ID - 2026-0129
Role Background

The NATO Communications and Information Agency (NCIA) located in The Hague, The Netherlands, is providing technical support to the NATO HQ Cyber and Digital Transformation (CDT) Division and Supreme Allied Command Transformation (SACT) by moving away from manual point-in-time audits, authorization to operate and security accreditation towards Continuous Governance, Risk and Compliance Auditing leading to Continuous Authorization to Operate (cATO) and Continuous Security Accreditation via EaC (Everything as Code) + Regulatory Operations (RegOps) using NIST OSCAL (Open Security Controls Assessment Language ) data models with the ultimate goal to deploy the RegScale platform as a workload and establish a Minimum Viable Product (MVP) for Continuous Authorization to Operate (cATO)

Role Duties and Responsibilities

They shall perform the following activities in support of the deliverables. These activities are not considered deliverables in themselves.

  • Review the existing SRS, D32/CSRS, NIST/ISO baseline for OSCAL conversion.
  • Identify and document relevant technical triggers from the cloud environ.
  • Review sampled automated evidence to confirm completeness, accuracy and suitability for supporting System Security Plan (SSP) content.
  • Conduct Stakeholder Review Sessions to validate assumptions, mappings, evidence sources, and SSP generation logic.
  • Issue tracking and remediation support
Deliverables
  • D001 - Catalog Digitization
    Import the organization's SRS (D32 / CSRS) or NIST/ISO baseline into OSCAL format.
    Acceptance: Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.
  • D002 - Policy-as-Code (PaC) Mapping
    Map technical triggers from cloud to specific OSCAL Control IDs.
    Acceptance: Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.
  • D003 - Digital SSP Generation
    Use RegScale to output the first full System Security Plan based on automated evidence.
    Acceptance: Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.
Essential Skills, Experience and Certifications
  • A minimum of 3 years' experience in all of the following items:
  • NIST/ISO frameworks, JSON/YAML proficiency, regulatory mapping.
  • Compliance-to-code translation.
  • Documented (or demonstrable) experience in process analysis, and design techniques,
Desirable Skills, Experience and Certifications

Robust technical knowledge of

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Administrator
System Administrator

spektrum • Den Haag

On-site
EUR 60,000 - 90,000
Senior Assurance Engineer
Senior Assurance Engineer

spektrum • Den Haag

On-site
EUR 70,000 - 110,000
Operational Analyst
Operational Analyst

spektrum • Den Haag

On-site
EUR 40,000 - 60,000
Cybersecurity Compliance Architect for cATO & OSCAL
Cybersecurity Compliance Architect for cATO & OSCAL

spektrum • Den Haag

On-site
EUR 70,000 - 95,000
Network Engineer - Deployable Communication and Information Systems
Network Engineer - Deployable Communication and Information Systems

Spektrum • Brunssum

On-site
EUR 60,000 - 90,000
Resource and Portfolio Management Assistant
Resource and Portfolio Management Assistant

Spektrum • Den Haag

On-site
EUR 40,000 - 70,000
Senior Infrastructure Engineer - VMware & Data Center
Senior Infrastructure Engineer - VMware & Data Center

spektrum • Den Haag

On-site
EUR 70,000 - 90,000
C004997 Cyber Security Engineer (NS) - FRI 4 Sep RELAUNCH
C004997 Cyber Security Engineer (NS) - FRI 4 Sep RELAUNCH

EMW, Inc. • Den Haag

On-site
EUR 110,000 - 140,000
Penetration Tester
Penetration Tester

Spektrum • Maasdijk

On-site
EUR 65,000 - 90,000
C004928 Senior Engineer (Cyber Security) (CTS) - TUE 23 Jun
C004928 Senior Engineer (Cyber Security) (CTS) - TUE 23 Jun

EMW • Den Haag

On-site
EUR 60,000 - 85,000