31 Jul
|
Cliffside Cybersecurity
|
New South Wales
31 Jul
Cliffside Cybersecurity
New South Wales
Ready to take ownership of an ISMS, not just advise from the sidelines?
At Cliffside Cybersecurity, we believe effective cybersecurity should be available to every organisation, not treated as a luxury. We are known for being Brutally Honest. We tell clients what needs attention, explain the business impact clearly and help them fix it. We do not produce generic compliance reports that leave clients with more paperwork and no practical way forward.
We are looking for a Senior Cybersecurity Consultant, GRC and ISMS to take an embedded role within our clients’ teams. You will operate and improve established information security management systems, coordinate audit readiness, manage compliance activities and turn framework requirements into work that control owners can actually complete.
This is a hands‑on delivery role. You will work directly with executives, technology teams, control owners, auditors and certification bodies to keep security and compliance programmes operating effectively.
The Opportunity
You will join Cliffside at a time when clients increasingly need experienced GRC capability without building a large permanent compliance team.
Your work will span established and emerging security frameworks. The immediate focus will be ISO 27001, SOC 2 and operational GRC delivery. Depending on client requirements, you may also contribute to international assurance programmes and AI governance initiatives.
You will be supported by Cliffside’s wider cybersecurity team, including security architects, technical consultants and specialist assurance partners. You will not be expected to solve every issue alone, but you will be expected to recognise risks early, engage the right expertise and maintain clear accountability for delivery.
What You Will Do
You will take ownership of client outcomes and keep GRC activities moving from identification through to closure.
- Operate information security management systems: Manage established ISO 27001 ISMS activities, including governance calendars, control operation, evidence collection, continual improvement and recurring compliance obligations.
- Drive audit readiness: Prepare clients for internal, certification and surveillance audits by coordinating evidence, validating control operation, briefing stakeholders and tracking actions through to closure.
- Manage remediation: Assess audit findings and control gaps, determine what genuinely requires action and coordinate practical remediation with accountable control owners.
- Maintain policies and governance records: Draft and update policies, procedures, Statements of Applicability, risk treatment plans, management review inputs and other ISMS documentation.
- Manage security risk: Maintain risk registers, facilitate risk assessments,
track treatment actions and present material risks in language executives can use to make decisions.
- Support supplier assurance: Triage suppliers, conduct proportionate third‑party security assessments and work with procurement, privacy, legal and technology stakeholders to resolve identified risks.
- Coordinate recurring controls: Support access reviews, business continuity activities, incident governance, security awareness obligations and other scheduled assurance processes.
- Operate compliance platforms: Manage evidence, controls, tests, integrations and outstanding actions within platforms such as Vanta, Drata or similar GRC and compliance automation tools.
- Work across multiple frameworks: Help clients reuse controls and evidence across ISO 27001, SOC 2 and other applicable security or regulatory frameworks rather than creating disconnected compliance programmes.
- Communicate clearly: Produce concise, evidence‑based reports that explain the issue, business impact, required decision and accountable next action.
About You
We need someone who can enter an established client environment, understand how it operates and become credible with stakeholders quickly.
- Relevant experience: At least five years of practical cybersecurity governance, risk and compliance experience, including operating or implementing ISO 27001 information security management systems.
- ISO 27001 capability: Strong working knowledge of ISO/IEC 27001:2022, including clauses 4 to 10, Annex A controls, Statements of Applicability, risk treatment and audit requirements.
- Audit readiness: Demonstrated experience preparing organisations for internal, surveillance or certification audits and coordinating the remediation of findings.
- Operational delivery: Experience maintaining policies, risk registers, evidence repositories, compliance calendars and control‑owner actions in a live business environment.
- Stakeholder management: The confidence to work with executives, auditors, technical teams and business owners, including challenging unsupported claims or incomplete evidence respectfully and directly.
- Writing and facilitation: You can facilitate workshops, explain technical and compliance issues without unnecessary jargon, and write material that can withstand auditor and executive scrutiny.
- Professional judgement: You can distinguish between a genuine control failure, a documentation issue and low‑value compliance noise,
then direct effort towards the risks that matter.
- Certification: A current ISO 27001 Lead Implementer or Lead Auditor qualification from PECB, BSI, Exemplar Global or an equivalent recognised provider.
Highly Regarded Experience
The following capabilities would allow you to contribute across a broader range of Cliffside engagements.
- Experience managing ISO 27001 or SOC 2 programmes through Vanta, Drata or a comparable platform.
- Experience with SOC 2 Type 2, supplier assurance or customer security questionnaires.
- Experience building or managing GRC workflows in Jira.
- Exposure to international security frameworks such as ENS, BSI C5 or equivalent cloud assurance requirements.
- Understanding of Microsoft 365 security controls, identity governance, access reviews and evidence requirements.
- Experience with ISO 42001, AI governance, privacy, Essential Eight, NIST CSF or ISO 9001.
What Success Looks Like
You will be successful in this role when clients know what needs to be done, control owners understand what is expected of them and audit evidence is available before it becomes urgent. Your work should leave clients with an ISMS that operates between audits, not one that is rebuilt each time an auditor arrives.
Salary Package
Base salary of $110,000 to $130,000 plus superannuation, aligned with your experience, qualifications and ability to take ownership of client outcomes.
What We Offer
This role provides a genuine opportunity to build deeper consulting capability while working across different organisations, technologies and assurance requirements.
- Competitive remuneration: A package aligned with your experience, qualifications and ability to lead client outcomes.
- Meaningful client ownership: The prospect to operate as a trusted part of client teams rather than delivering isolated assessments.
- Specialist support: Access to Cliffside’s broader capability across security architecture, Microsoft security, technical assurance, managed services and governance.
- Professional development: Structured support to extend your capability across areas such as ISO 42001, AI governance and international assurance frameworks.
- Flexible working: A hybrid model covering remote work, our Sydney CBD hub and client locations where engagement outcomes require onsite participation.
- Direct culture: A team that values sound judgement, personal accountability, straight answers and genuine care for client outcomes.
A Final Word
This role will not suit someone who wants to assess a client, produce a list of gaps and walk away. It will suit someone who wants to take ownership, work through ambiguity and help clients build security and compliance practices that continue to function after the audit is finished.
#J-18808-Ljbffr
📌 Cybersecurity Consultant GRC and ISMS (New South Wales)
🏢 Cliffside Cybersecurity
📍 New South Wales