12 дней назад
Senior GRC and Advisory Consultant (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior GRC and Advisory Consultant (Cybersecurity): Leading governance, risk, compliance, and assurance services for Australian Federal Government departments with an accent on cybersecurity risk, policy, compliance, and security assurance. Focus on delivering strategic security outcomes, conducting Essential Eight maturity assessments, writing ISM- and PSPF-aligned policies, and advising CISO-level stakeholders.
Location: Brindabella Business Park, Australian Capital Territory, Australia
Company
delivers enterprise technology, software, managed infrastructure, application modernization, and industry-specific solutions for global enterprises and public sector organisations.
What you will do
- Lead governance, risk, compliance, and assurance engagements for Federal Government departments.
- Advise senior government stakeholders and executive audiences, including CISO-level leaders.
- Develop cybersecurity policies aligned with the Information Security Manual and Protective Security Policy Framework.
- Implement and assess Essential Eight maturity controls.
- Deliver security assurance and accreditation programs and produce technical documentation and board-level briefings.
- Lead and mentor security consultants while contributing to cybersecurity proposals and tender responses.
Requirements
- 8+ years of IT experience, including 5+ years in information security, GRC, risk, or audit.
- Bachelor’s or Master’s degree, or equivalent experience.
- Deep knowledge of PSPF, ISM, Essential Eight, DSPF, ISO 27000, NIST CSF and 800 series, and CIS.
- Experience leading GRC engagements, delivering strategic security outcomes, and engaging senior government stakeholders.
- IRAP Assessor experience or active pursuit of the qualification; NV1 Security Clearance is highly desirable.
- Understanding of network, application, web, Windows, and Linux security, plus strong technical and executive writing skills.
Nice to have
- CISSP, CISA, CISM, or IRAP Assessor certification.
- Experience with ACSC reporting and government incident response frameworks.
- Experience with cloud security governance across AWS, Azure, or GovCloud.
- Experience driving security assurance and accreditation programs end-to-end.
- Capability in detecting, deterring, and responding to cyber threats.
Culture & Benefits
- People-first culture focused on inclusion, belonging, and corporate citizenship.
- Competitive remuneration, benefits, training, and career opportunities.
- In-person collaboration model with flexibility to support wellbeing, productivity, and individual work styles.
- Commitment to equal opportunity and reasonable workplace accommodations.
Hiring process
- Submit a resume through the application process.
- Hiring is designed to be thorough and fair.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →