Information Security Consultant (Policy-as-Code & Governance Engineering)
Core
Drive the transition from traditional policy management to a modern Policy-as-Code and governance engineering capability, translating security requirements into machine-readable, testable, and enforceable controls.
Role type
Senior IC Information Security Consultant (Policy-as-Code & Governance Engineering)
Builds
Machine-readable control frameworks, automated compliance monitoring, and governance workflows integrated into technology solutions.
Domain
Banking / Cybersecurity Governance & Risk Management
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Cybersecurity governance, risk, and compliance (GRC); Policy-as-Code concepts; Control automation; Version control workflows; Python scripting; CI/CD practices; JSON/YAML; OSCAL fundamentals; OPA/Rego; AI governance
Preferred skills
Experience with GitHub or Bitbucket; ServiceNow IRM/GRC; UCF and control mapping frameworks; Palantir; Emerging governance automation technologies
Responsibilities
Maintain and enhance cybersecurity policies, standards, and control frameworks; Embed cybersecurity requirements into technology solutions and delivery practices; Monitor control effectiveness, compliance, and exception trends; Support audits, assurance, and regulatory activities through evidence-based assessments; Leverage automation and AI to enhance governance processes and policy lifecycle management
Seniority
Senior, hands-on IC