Website Commission for Communications Regulation (ComReg)
The Technical Advisor – Operational Resilience is a senior role that is responsible for the delivery of regulatory supervision activities to in-scope entities. This role sits at the intersection between the CER Directive and NIS2 Directive focusing on the resilience aspects of the all-hazards approach. The role is accountable for regulatory activities including assessment, inspection and audit to gain assurance that resilience requirements have been implemented in entities in scope including the ability to prevent, withstand, respond to, and recover from disruptive incidents to ensure resilience.
The Technical Advisor Operational Resilience will provide expert input to CER functions including the identification of critical entities, the national resilience strategy and provide representation to key internal and external stakeholders including national and European resilience working groups when required.
The suitable candidate will combine technical expertise in operational resilience with strong leadership and communication skills to fulfil regulatory supervision obligations and strengthen resilience within the digital infrastructure, digital providers, ICT service management, space, postal and courier services sectors.
The Technical Advisor – Operational Resilience will have a senior operational role including:
- Provide operational resilience expertise in the assessment, inspection and audit of regulated entities NIS2 legislative requirements;
- Lead and support the identification and designation of critical entities in the CER Directive, including detailed analysis of entities potentially in scope;
- Provide expert input into the national resilience strategy to ensure ComReg contributes to the development of robust and effective national resilience objectives;
- Evaluation of entities resilience measures to assess if they are proportionate, risk-based, and effectively implemented across both physical and cyber domains, identifying non-compliance;
- Expert analysis of entities implementation of an all-hazard approach, for example provisions for natural disasters, sabotage, terrorism, infrastructure failure;
- Lead, support and manage operational resilience supervision and enforcement activities including remediation, follow up assessments and audits or enforcement action
- Provide expert participation and support to national and European operational resilience working groups where required to develop collaborate and cohesive relationship with other agencies or competent authorities;
- Management of operational resilience specialists, business continuity specialists or external advisors where required;
- Mentor and coach team members to support capability development and continuous improvement.
Essential Criteria
- An Honours degree (equivalent to level 8 on the National Framework of Qualifications – NFQ), third level qualification or significant relevant senior experience, in cybersecurity, science, technology, engineering, or other equivalent area/s;
- Proven recent experience in senior role/s with demonstrable evidence of working within a regulatory or regulated environment in the area of operational resilience with a focus on operational aspects including advisory, assurance or risk management – within the Digital Infrastructure, Digital Providers, ICT Service Management and Space sectors which could include but not limited to cloud, data centres, telecommunications, ICT networks, managed service providers, online platforms etc
- Experience applying cybersecurity and resilience risk and regulatory frameworks (e.g. ISO 27001, NIST, CSF, DORA, GDPR) in complex environments;
- Experienced understanding of risk-based supervision and enforcement approaches in a regulatory context with demonstrable ability to conduct or support inspections, audits, and compliance assessments of regulated organisations.
- Experience working with European Union regulatory legislation including CER,NIS, NIS2, DORA, GDPR or sectoral operational resilience legislation.
- Professional accreditations such as ISO 27001 Lead Auditor, CISSP, CISM, CRISC, or CISA with senior experience in risk assessment, audit or IT audit or equivalent experience.
- Proven and demonstratable experience in engagement and communication with internal and external stakeholders.
- Previous experience in technical management and/or programme/project management of resource.
Desired criteria
- Master’s degree (equivalent to level 9 on the NFQ) in science, technology, engineering, data analytics or another equivalent area/s and/or Cybersecurity leadership qualification;
- Experience delivering large scale regulatory driven security or resilience initiatives in either public or industry environment
- Experience presenting and influencing senior stakeholders, with the ability to develop and sustain strong working relationships;
- Demonstratable ability to establish evidence-based operational resilience assurance models, including documentation review, technical testing, and control validation
- Experience of working with Irish of EU regulatory authorities which could include regulatory engagements with National Competent Authorities.
Core Competencies & Skills for the Role
- Communication and Influencing – Communicates clearly, confidently and respectfully. Engages and influences others to follow a particular course of action. Ensures all relevant parties are appropriately updated and notified.
- Decision Making and Judgement – Effectively uses evidence to support the decision-making process. Assesses alternative positions while using sound judgement to adapt to specific and challenging requirements of the organisation.
- Analytical and Critical Thinking – Objectively analyses and evaluates information in order to identify patterns between situations that are not obviously related. Develops and clearly articulates solutions to complex problems.
- Technical Knowledge & Continuous Improvement – Possesses a command over the technical and professional skills for a particular discipline. Keeps an open mind. Demonstrates commitment to continuous improvement.
- Teamwork – Promotes and enhances team performance through working collaboratively and in cooperation with others to achieve goals. Interacts in a manner that builds respect and fosters trust.
To apply for this job please visit www.comreg.ie.