22 Aug
|
Xpt Software Australia
|
Victoria
22 Aug
Xpt Software Australia
Victoria
Job Description
XPT Software Australia Pty Ltd | Contract
n
Melbourne, Australia | Posted on 06/16/2026
n
n
- XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
n
- XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
n
- We have 120+technocrats in Australia working at our clientlocations.
n
- XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
n
- We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
n
n
Job Description
n
Role Summary
n
We are seeking anexperienced GRC Consultant – Cyber Lead to drive governance and maturityof non-OS vulnerability management across enterprise application andplatform environments.
n
This role focuses on cyberrisk oversight, exception management, and vulnerability treatment strategy,ensuring risks are effectively assessed, governed, and aligned with enterprisesecurity standards—while remediation execution remains with delivery teams.
n
Key Responsibilities
n
Governance & Risk Oversight
n
n
- Define and implement non-OS vulnerability management frameworks,policies, and standards
n
- Establish governance forums, escalation paths, anddecision-making processes
n
- Ensure compliance with regulatory, audit, and enterprisesecurity requirements
n
n
Exception & Treatment Management
n
n
- Manage remediation exceptions and risk acceptance lifecycle
n
- Validate compensating controls and residual risks
n
- Drive risk-based treatment plans with application andplatform teams
n
- Perform risk assessments for vulnerabilities that cannot beremediated
n
- Enable risk-based decision-making aligned to business riskappetite
n
- Ensure proper documentation, tracking, and periodic review ofaccepted risks
n
n
Tooling & Capability Uplift
n
n
- Lead tooling strategy, evaluation, and automation initiatives
n
- Improve vulnerability management maturity and processes
n
- Support training and adoption across delivery teams
n
n
Security Improvement & SDLC Integration
n
n
- Oversee remediation outcomes from pen tests, audits, andassessments
n
- Promote secure-by-design and DevSecOps practices
n
- Ensure vulnerabilities are identified and treated beforeproduction release
n
n
Stakeholder Management
n
n
- Collaborate with Cyber, Application, Infrastructure, andOperations teams
n
- Provide risk insights to senior leadership and governance forums
n
- Influence prioritization based on risk severity and businessimpact
n
n
Required Skills & Experience
n
n
- Strong background in GRC, cyber risk, and vulnerabilitymanagement
n
- Experience with application/platform vulnerabilities (non-OS)
n
- Knowledge of frameworks: ISO 27001, NIST, CIS
n
- Hands-on exposure to tools like Qualys, Tenable, Snyk, orsimilar
n
- Expertise in risk assessment, exception management, andcompliance
n
- Solid stakeholder engagement and communication skills
n
- Familiarity with DevSecOps / SDLC security practices
n
n
Qualifications
n
n
- Bachelor's degree in IT / Cybersecurity or related field
n
#J-18808-Ljbffr
📌 GRC Consultant - Cyber Lead (Victoria)
🏢 Xpt Software Australia
📍 Victoria