Senior Specialist - Is Risk (Queensland)

Senior Specialist - Is Risk (Queensland)

18 Aug
|
The Decipher Bureau
|
Queensland

18 Aug

The Decipher Bureau

Queensland

Our client is a specialist technology risk, information security and assurance organisation working with a diverse portfolio of clients across complex enterprise environments. The team provides independent advice and assurance across information security, IT risk, governance, controls and technology environments. Their work goes beyond traditional compliance and box-ticking, helping clients understand where genuine risks exist and providing practical recommendations to improve their security and control environments.
Due to continued growth, they are looking for a Senior Specialist – IS Risk to join their Brisbane team. This is an opportunity for an IT audit, cybersecurity, GRC or technology risk professional who enjoys problem-solving, investigating how technology environments actually work and engaging directly with clients.
The Role
As a Senior Specialist – IS Risk, you'll work across a range of client engagements covering IT audit, information security, technology risk and assurance. You'll contribute to the end-to-end delivery of engagements, from scoping and planning through to fieldwork, analysis, reporting and client presentation. The role combines technical understanding with strong consulting and stakeholder management skills. You'll need to understand the technology behind the controls, identify where weaknesses genuinely create risk and translate your findings into clear, practical recommendations.
Key responsibilities:
Lead and contribute to IT audit, information security and technology risk engagements
Coordinate the delivery and project management of lower-risk engagements
Contribute to medium and high-risk audits and assurance engagements
Assess information security controls, practices and processes
Identify control gaps, risks and opportunities for improvement
Analyse existing mitigating controls and determine the significance of identified findings
Conduct research, investigation and analysis across client environments
Prepare high-quality audit reports, working papers and presentations
Develop clear, evidence-based recommendations
Present and discuss findings directly with clients
Respond confidently when clients challenge or question audit observations
Explain technical issues and risk implications to both technical and non-technical stakeholders
Support engagement scoping, planning, resourcing and delivery
Review working papers and contribute to quality assurance across engagements
Work with subject matter experts where specialist technical input is required
Apply relevant audit, assurance and information security methodologies
Maintain strong client relationships throughout engagements
Contribute to continuous improvement of internal methodologies, tools and approaches
Stay current with emerging information security risks, technologies and industry practices
Lead and contribute to IT audit, information security and technology risk engagements
Coordinate the delivery and project management of lower-risk engagements
Contribute to medium and high-risk audits and assurance engagements
Assess information security controls, practices and processes
Identify control gaps, risks and opportunities for improvement




Analyse existing mitigating controls and determine the significance of identified findings
Conduct research, investigation and analysis across client environments
Prepare high-quality audit reports, working papers and presentations
Develop clear, evidence-based recommendations
Present and discuss findings directly with clients
Respond confidently when clients challenge or question audit observations
Explain technical issues and risk implications to both technical and non-technical stakeholders
Support engagement scoping, planning, resourcing and delivery
Review working papers and contribute to quality assurance across engagements
Work with subject matter experts where specialist technical input is required
Apply relevant audit, assurance and information security methodologies
Maintain strong client relationships throughout engagements
Contribute to continuous improvement of internal methodologies, tools and approaches
Stay current with emerging information security risks, technologies and industry practices
What you'll bring
2+ years' experience in IT audit, information security, cybersecurity, GRC, technology risk or a closely related discipline
Relevant tertiary degree in Information Technology, Cyber Security, Business, Commerce, Accounting or a related field
Sound understanding of IT audit, risk, assurance and information security principles
Strong critical thinking and analytical skills
Ability to investigate issues rather than simply follow a predefined checklist
Strong problem-solving skills and the ability to form evidence-based conclusions
Excellent report writing and documentation skills
Strong communication and stakeholder management capabilities
Confidence engaging directly with clients and defending audit findings
Ability to have challenging conversations while maintaining positive client relationships
Knowledge or experience with Active Directory, Microsoft Entra ID, databases and enterprise security concepts is highly regarded
Understanding of internal controls and assurance frameworks is advantageous
Experience across ERP systems, operating systems, databases or network environments is highly regarded
CISA or CISSP certification is highly regarded
CPA Australia or CAANZ membership, or progress towards membership, is advantageous
Australian working rights are required
2+ years' experience in IT audit, information security, cybersecurity, GRC, technology risk or a closely related discipline
Relevant tertiary degree in Information Technology, Cyber Security, Business, Commerce, Accounting or a related field
Sound understanding of IT audit, risk, assurance and information security principles
Strong critical thinking and analytical skills
Ability to investigate issues rather than simply follow a predefined checklist




Strong problem-solving skills and the ability to form evidence-based conclusions
Excellent report writing and documentation skills
Strong communication and stakeholder management capabilities
Confidence engaging directly with clients and defending audit findings
Ability to have challenging conversations while maintaining positive client relationships
Knowledge or experience with Active Directory, Microsoft Entra ID, databases and enterprise security concepts is highly regarded
Understanding of internal controls and assurance frameworks is advantageous
Experience across ERP systems, operating systems, databases or network environments is highly regarded
CISA or CISSP certification is highly regarded
CPA Australia or CAANZ membership, or progress towards membership, is advantageous
Australian working rights are required
The type of person we're looking for
We're looking for someone who is curious, analytical and genuinely interested in their work. You'll need to be comfortable asking "why?", challenging what you're seeing and digging into an issue rather than simply working through an audit checklist. The role involves regular client interaction, and your findings won't always be accepted immediately. You need to be able to explain your rationale, have robust conversations with stakeholders and stand behind your recommendations while maintaining strong professional relationships. This is particularly suited to someone coming from an IT audit, cyber security, GRC or technical risk background who wants to develop their career further within a specialist assurance environment.
What's in it for you?
Join a specialist technology risk and information security advisory team
Work across varied client environments and complex technology landscapes
Exposure to IT audit, information security, GRC and technology risk engagements
Develop your technical, consulting and stakeholder management skills
Work alongside an experienced and collaborative team of approximately 10 professionals
Opportunity to take ownership of client engagements and develop your career
Brisbane CBD location,4–5 days per week in the office with 1 day working from home
Competitive remuneration package
Work with clients who genuinely value independent risk and security advice
Opportunity to build a career across technology risk, information security and assurance
Join a specialist technology risk and information security advisory team
Work across varied client environments and complex technology landscapes
Exposure to IT audit, information security, GRC and technology risk engagements
Develop your technical, consulting and stakeholder management skills
Work alongside an experienced and collaborative team of approximately 10 professionals
Chance to take ownership of client engagements and develop your career
Brisbane CBD location,4–5 days per week in the office with 1 day working from home
Competitive remuneration package
Strong professional development opportunities
Work with clients who genuinely value independent risk and security advice
Opportunity to build a career across technology risk, information security and assurance
#J-*****-Ljbffr

📌 Senior Specialist - Is Risk (Queensland)
🏢 The Decipher Bureau
📍 Queensland

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior specialist - is risk (queensland) / queensland

Subscribe to this job alert:

Get the latest job offers by email for: senior specialist - is risk (queensland) / queensland