Kellwick is looking for a Senior DORA & EU Cyber Regulatory Consultant to support organisations facing European cybersecurity, operational resilience and ICT governance requirements.
The role focuses primarily on DORA and NIS2 and requires practical implementation experience, not only regulatory knowledge.
You will help clients translate regulatory requirements into governance structures, operational controls, evidence and remediation programmes.
What You Will Do
Lead DORA readiness and gap assessment engagements
Assess ICT risk management frameworks
Map DORA requirements to existing controls and operating processes
Assess ICT third-party risk management
Support DORA Register of Information preparation and governance
Review ICT third-party contractual requirements
Assess incident management and regulatory reporting readiness
Review digital operational resilience testing programmes
Assess governance, accountability and management oversight
Review ICT business continuity and resilience arrangements
Support remediation of identified DORA gaps
Perform NIS2 readiness and gap assessments
Map NIS2 requirements to security and governance controls
Help organisations establish appropriate cybersecurity risk-management measures
Produce regulatory readiness roadmaps
Prepare evidence packs and management reporting
Work with client risk, compliance, security, technology, procurement and legal teams
Coordinate with Kellwick ISO 27001, privacy and vCISO specialists
Required Experience
5+ years of professional experience in GRC, ICT risk, operational risk, cybersecurity regulation, information security or regulatory consulting
Practical DORA implementation or readiness experience
Strong understanding of DORA ICT Risk Management requirements
Strong understanding of ICT third-party risk requirements
Knowledge of DORA Register of Information requirements
Understanding of DORA incident management and resilience testing requirements
Strong working knowledge of NIS2
Experience translating regulatory obligations into operational controls
Experience performing regulatory gap assessments
Experience producing remediation roadmaps and executive-level findings
Experience working directly with senior client stakeholders
Professional English at C1 level or higher
Strong Plus
Experience within financial services or with DORA-regulated organisations
Experience with banks, payment institutions, electronic money institutions, investment firms, insurers or regulated ICT providers
ISO 27001 Lead Implementer or Lead Auditor
CRISC
CISA
CISM
CISSP
Operational resilience experience
ICT third-party risk management experience
Regulatory audit or supervisory review experience
Experience with EU cybersecurity regulatory frameworks beyond DORA and NIS2
Engagement Model
This is a project-based independent contractor position.
Assignments may include DORA readiness assessments, Register of Information work, ICT third-party risk reviews, remediation programmes, NIS2 readiness and ongoing regulatory governance support.
Kellwick matches consultants to engagements based on regulatory expertise, jurisdiction, language and availability.
Apply for this role
Upload your CV (required) and, optionally, a cover letter. We review every application.