15 Aug
|
Client 1
|
Canberra
Role Title
Cyber GRC Manager
Location
Canberra
Working Arrangement
On-site
Clearance required
Active NV2 AGSVA clearance with the willingness to upgrade to Positive Vetting (PV) OR active Positive Vetting (PV)
Company overview
Our client operates within a highly secure and regulated workplace, delivering critical capabilities while maintaining strong cyber security governance, risk and compliance practices aligned with Australian Government security requirements.
Job Description
We are seeking an experienced Cyber GRC Manager to lead the organisation's governance, risk and compliance function while managing a team of approximately 4-6 cyber security professionals.
This is a hands-on leadership role where you will actively contribute to security governance, risk assessments, authorisation activities and compliance initiatives, while providing leadership, mentoring and direction to the Cyber GRC team. You will play a key role in driving security maturity, maintaining compliance with Government frameworks and supporting informed risk-based decision making across the organisation.
Working closely with the Deputy CISO and broader cyber security team, you will lead information system authorisation activities and ensure security controls remain effective, compliant and aligned with organisational objectives.
Duties and Responsibilities
- Lead and manage a Cyber GRC team of 4-6 personnel, providing leadership, mentoring and performance guidance.
- Lead the development, delivery, submission and maintenance of security authorisation documentation, including System Security Plans, Security Risk Management Plans and Cyber Incident Response Plans.
- Drive information system authorisation activities and support Government ATO processes.
- Lead the implementation and ongoing management of security standards and frameworks including ISM, ASD Essential Eight and NIST.
- Conduct and lead cyber security risk assessments to identify threats, vulnerabilities and appropriate mitigation strategies.
- Develop and maintain security policies, procedures and controls to address organisational risk.
- Provide cyber security advice for infrastructure design, monitoring, upgrades and enhancement activities.
- Provide subject matter expertise for greenfield projects, legacy system modernisation and enterprise application initiatives.
- Support the Deputy CISO and CISO in achieving strategic and technical security objectives.
- Prepare and contribute to executive briefings and security reporting.
- Build and maintain effective relationships with internal stakeholders, external vendors and relevant Government agencies.
Education/Certifications required
- Relevant tertiary qualifications in Cyber Security, Information Technology or a related discipline.
- Industry certifications in cyber security, risk management or governance are highly regarded.
- Knowledge of ISO27000 series, NIST 800 series and CIS frameworks is desirable.
Knowledge/Skills required
- Minimum 7 years' experience within Cyber Security or GRC environments.
- Demonstrated leadership experience managing and developing cyber security teams.
- Strong working knowledge of PSPF, ISM, ASD Essential Eight and NIST frameworks.
- Experience leading security governance, risk and compliance programs within enterprise environments.
- Proven ability to identify risks, develop mitigation strategies and achieve stakeholder buy-in.
- Experience working within highly regulated industries such as Federal Government, Defence, telecommunications or energy.
- Strong understanding of security authorisation and accreditation processes.
- Excellent written and verbal communication skills with the ability to engage technical and non-technical stakeholders.
- Australian Citizenship and the ability to maintain a Positive Vetting (PV) clearance.
Employment benefits
- 14% superannuation
- 6 weeks paid annual leave
- Opportunity to lead a high-performing Cyber GRC team.
- Hands-on leadership role with strategic influence across the organisation.
- Exposure to complex cyber security programs and modernisation initiatives.
- Work closely with senior cyber security leadership.
- Professional development opportunities through mentoring and continuous learning.
Diversity and Inclusion
We value diversity and are committed to creating an inclusive environment for all employees.
Veterans
Defence and Federal Government industry experience is highly desirable. We strongly encourage veterans and individuals with Defence experience to apply. Your unique skills and background are highly valued, and we are committed to supporting your transition into this role.
#J-18808-Ljbffr
📌 GRC Manager (Canberra)
🏢 Client 1
📍 Canberra