06 Aug
|
Client 1
|
Canberra
Role Title
GRC Consultant
Location
Canberra
Working Arrangement
On-site
Clearance Required
Active TSPV Security Clearance and willing to obtain DISA/OSA.
Company Overview
We are seeking experienced Governance, Risk and Compliance (GRC) professionals to join a Defence-focused cyber security team supporting nationally significant capabilities. These roles play an important part in strengthening security governance, managing cyber risk and supporting accreditation activities across a highly secure and complex operational environment.
Job Description
As a GRC Consultant, you will contribute to the delivery of cyber security governance outcomes within a major Defence program. Working closely with technical teams, project stakeholders and security authorities, you will be responsible for ensuring systems comply with Defence security standards and authorisation requirements.
The role involves providing governance guidance, assessing cyber security risks, supporting accreditation processes and maintaining key security artefacts throughout the lifecycle of Defence systems. You will be expected to operate autonomously while collaborating with a broad range of internal and external stakeholders.
Duties and Responsibilities
- Build and maintain strong relationships with Defence representatives, project teams, business stakeholders and cyber security partners.
- Provide guidance on security governance obligations, control implementation and risk treatment strategies.
- Lead and coordinate activities associated with system accreditation and authorisation processes.
- Prepare, review and maintain documentation required to support security assessment and authorisation activities.
- Evaluate system compliance against Defence security frameworks,
the Information Security Manual (ISM) and Essential Eight controls.
- Conduct cyber risk assessments and present findings, recommendations and treatment plans to stakeholders.
- Work collaboratively with cyber security, engineering and operations teams to ensure security requirements are embedded throughout delivery and sustainment activities.
- Support project teams by identifying security dependencies, risks and compliance obligations early in the delivery lifecycle.
- Monitor remediation activities and provide assurance that identified security issues are appropriately addressed.
- Contribute to continuous improvement initiatives that enhance governance and risk management processes.
Knowledge / Skills Required
- Demonstrated experience working within governance, risk and compliance functions in secure or regulated environments.
- Strong understanding of the Protective Security Policy Framework (PSPF), Information Security Manual (ISM) and Defence security standards.
- Experience producing and maintaining key security governance documentation, including System Security Plans, Security Risk Management Plans and Incident Response Plans.
- Exposure to system accreditation, certification or Authority to Operate (ATO) processes within Defence, Government or Intelligence environments.
- Familiarity with security assessment methodologies such as IRAP or comparable assurance frameworks.
- Experience working within cloud-hosted environments, ideally AWS, as well as traditional enterprise infrastructure.
- Understanding of security requirements across systems operating at different classification levels.
- Strong analytical and risk assessment capabilities, with the ability to identify, articulate and manage security risks.
- Excellent communication and stakeholder engagement skills, including the ability to influence technical and non-technical audiences.
- A minimum of two years' relevant cyber security or GRC experience. More senior opportunities are available for candidates with extensive industry experience.
Employment Benefits
- Opportunity to support a mission-critical Defence capability.
- Multiple positions available across varying levels of experience.
- Work within a highly skilled cyber security and governance team supporting Defence capabilities.
- Opportunity to contribute to complex and nationally significant security outcomes.
Diversity and Inclusion
We value diversity and are committed to creating an inclusive environment for all employees.
Veterans
Defence and Federal Government industry experience is highly desirable. We strongly encourage veterans and individuals with Defence experience to apply. Your unique skills and background are highly valued, and we are committed to supporting your transition into this role.
About Cleared
At Cleared, we provide tailored recruitment solutions to individuals seeking their next chance and to organisations searching for talent within Defence Industry, Intelligence and National Security.
#J-18808-Ljbffr
📌 GRC Consultant (Canberra)
🏢 Client 1
📍 Canberra