21 Aug
|
The Decipher Bureau
|
Brisbane
21 Aug
The Decipher Bureau
Brisbane
Our client is a specialist technology risk, information security and assurance organisation working with a diverse portfolio of clients across complex enterprise environments.
The team provides independent advice and assurance across information security, IT risk, governance, controls and technology environments.
Their work goes beyond traditional compliance and box-ticking, helping clients understand where genuine risks exist and providing practical recommendations to improve their security and control environments.Due to continued growth, they are looking for a Senior Specialist – IS Risk to join their Brisbane team.
This is an opportunity for an IT audit, cybersecurity, GRC or technology risk professional who enjoys problem-solving, investigating how technology environments actually work and engaging directly with clients.The RoleAs a Senior Specialist – IS Risk, you'll work across a range of client engagements covering IT audit, information security, technology risk and assurance.
You'll contribute to the end-to-end delivery of engagements, from scoping and planning through to fieldwork, analysis, reporting and client presentation.
The role combines technical understanding with strong consulting and stakeholder management skills.
You'll need to understand the technology behind the controls, identify where weaknesses genuinely create risk and translate your findings into clear, practical recommendations.Key responsibilities:Lead and contribute to IT audit, information security and technology risk engagementsCoordinate the delivery and project management of lower-risk engagementsContribute to medium and high-risk audits and assurance engagementsAssess information security controls, practices and processesIdentify control gaps, risks and opportunities for improvementAnalyse existing mitigating controls and determine the significance of identified findingsConduct research, investigation and analysis across client environmentsPrepare high-quality audit reports, working papers and presentationsDevelop clear, evidence-based recommendationsPresent and discuss findings directly with clientsRespond confidently when clients challenge or question audit observationsExplain technical issues and risk implications to both technical and non-technical stakeholdersSupport engagement scoping, planning, resourcing and deliveryReview working papers and contribute to quality assurance across engagementsWork with subject matter experts where specialist technical input is requiredApply relevant audit, assurance and information security methodologiesMaintain strong client relationships throughout engagementsContribute to continuous improvement of internal methodologies, tools and approachesStay current with emerging information security risks, technologies and industry practicesLead and contribute to IT audit, information security and technology risk engagementsCoordinate the delivery and project management of lower-risk engagementsContribute to medium and high-risk audits and assurance engagementsAssess information security controls, practices and processesIdentify control gaps,
risks and opportunities for improvementAnalyse existing mitigating controls and determine the significance of identified findingsConduct research, investigation and analysis across client environmentsPrepare high-quality audit reports, working papers and presentationsDevelop clear, evidence-based recommendationsPresent and discuss findings directly with clientsRespond confidently when clients challenge or question audit observationsExplain technical issues and risk implications to both technical and non-technical stakeholdersSupport engagement scoping, planning, resourcing and deliveryReview working papers and contribute to quality assurance across engagementsWork with subject matter experts where specialist technical input is requiredApply relevant audit, assurance and information security methodologiesMaintain strong client relationships throughout engagementsContribute to continuous improvement of internal methodologies, tools and approachesStay current with emerging information security risks, technologies and industry practicesWhat you'll bring2+ years' experience in IT audit, information security, cybersecurity, GRC, technology risk or a closely related disciplineRelevant tertiary degree in Information Technology, Cyber Security, Business, Commerce, Accounting or a related fieldSound understanding of IT audit, risk, assurance and information security principlesStrong critical thinking and analytical skillsAbility to investigate issues rather than simply follow a predefined checklistStrong problem-solving skills and the ability to form evidence-based conclusionsExcellent report writing and documentation skillsStrong communication and stakeholder management capabilitiesConfidence engaging directly with clients and defending audit findingsAbility to have challenging conversations while maintaining positive client relationshipsKnowledge or experience with Active Directory, Microsoft Entra ID, databases and enterprise security concepts is highly regardedUnderstanding of internal controls and assurance frameworks is advantageousExperience across ERP systems, operating systems, databases or network environments is highly regardedCISA or CISSP certification is highly regardedCPA Australia or CAANZ membership, or progress towards membership, is advantageousAustralian working rights are required2+ years' experience in IT audit, information security, cybersecurity, GRC, technology risk or a closely related disciplineRelevant tertiary degree in Information Technology, Cyber Security, Business, Commerce, Accounting or a related fieldSound understanding of IT audit, risk,
assurance and information security principlesStrong critical thinking and analytical skillsAbility to investigate issues rather than simply follow a predefined checklistStrong problem-solving skills and the ability to form evidence-based conclusionsExcellent report writing and documentation skillsStrong communication and stakeholder management capabilitiesConfidence engaging directly with clients and defending audit findingsAbility to have challenging conversations while maintaining positive client relationshipsKnowledge or experience with Active Directory, Microsoft Entra ID, databases and enterprise security concepts is highly regardedUnderstanding of internal controls and assurance frameworks is advantageousExperience across ERP systems, operating systems, databases or network environments is highly regardedCISA or CISSP certification is highly regardedCPA Australia or CAANZ membership, or progress towards membership, is advantageousAustralian working rights are requiredThe type of person we're looking forWe're looking for someone who is curious, analytical and genuinely interested in their work.
You'll need to be comfortable asking "why?", challenging what you're seeing and digging into an issue rather than simply working through an audit checklist.
The role involves regular client interaction, and your findings won't always be accepted immediately.
You need to be able to explain your rationale, have robust conversations with stakeholders and stand behind your recommendations while maintaining strong professional relationships.
This is particularly suited to someone coming from an IT audit, cyber security, GRC or technical risk background who wants to develop their career further within a specialist assurance workplace.What's in it for you?
Join a specialist technology risk and information security advisory teamWork across varied client environments and complex technology landscapesExposure to IT audit, information security, GRC and technology risk engagementsDevelop your technical, consulting and stakeholder management skillsWork alongside an experienced and collaborative team of approximately 10 professionalsOpportunity to take ownership of client engagements and develop your careerBrisbane CBD location,4–5 days per week in the office with 1 day working from homeCompetitive remuneration packageWork with clients who genuinely value independent risk and security adviceOpportunity to build a career across technology risk, information security and assuranceJoin a specialist technology risk and information security advisory teamWork across varied client environments and complex technology landscapesExposure to IT audit, information security, GRC and technology risk engagementsDevelop your technical, consulting and stakeholder management skillsWork alongside an experienced and collaborative team of approximately 10 professionalsOpportunity to take ownership of client engagements and develop your careerBrisbane CBD location,4–5 days per week in the office with 1 day working from homeCompetitive remuneration packageStrong professional development opportunitiesWork with clients who genuinely value independent risk and security adviceOpportunity to build a career across technology risk, information security and assurance
#J-*****-Ljbffr
📌 Senior Specialist - Is Risk (Brisbane)
🏢 The Decipher Bureau
📍 Brisbane