Support or drive strategic development of the capability and services of the Regulatory team Build and maintain deep knowledge of specific controls or control families within your domain (Cyber) Contribute to complex regulatory responses, explaining how controls are designed, operated, evidence and governed Interpret regulatory questions to identify the underlying control themes, processes, systems or risks involved Work with control owners and SMEs to obtain detailed input, clarifications and supporting evidence Draft, review and refine sections of responses to ensure technical accuracy and clarity Support peer reviews and apply quality checks as part of embedded quality assurance tollgates Identify potential gaps or inconsistencies in information and escalate appropriately Support the development of reuseable content and contribute to the regulatory engagement knowledge base. Track emerging regulatory themes related to your control area Ensure evidence and documentation is stored correctly in the respective market repositories and workflow tooling. Ability to engage, challenge, and secure decisions from senior Technology, Risk, Compliance, and senior stakeholders balancing regulatory requirements with delivery priorities Strong knowledge of applicable regional cyber and technology regulations and supervisory expectations Knowledge of Cyber controls, or experience working closely with control owners or SMEs Strong evidence drafting or reviewing complex regulatory responses, audit materials, or assurance documentation Ability to translate technical concepts into clear, structured regulatory responses Experience contributing to audit, assurance or regulatory engagements High attention to detail and commitment to accuracy Excellent written communications skills and the ability to challenge inconsistencies or unclear information Strong collaboration skills, with confidence in engaging SMEs and cross-functional teams Demonstrates sound judgement, confidentiality, and a strong sense of accountability; able to make balanced, defensible decisions under pressure Ability to manage multiple in-flight, multiple stakeholder engagements in a fast-moving environment in a structured and organised way. Experience in technology risk, cybersecurity or data governance in financial services Familiarity of risk and control frameworks and industry guidelines relevant to your domain (e.g. NIST, COBIT, ISO 27001, ITIL) Prior involvement in regulatory engagement or evidence preparation Cyber: CISSP, CISM, CRISC, CEH, CRISC