21 Aug
|
Xpt Software Australia
|
Victoria
21 Aug
Xpt Software Australia
Victoria
Job Description
XPT Software Australia Pty Ltd | Contract
n
Melbourne, Australia | Posted on 06/16/2026
n
n
XPT SoftwareAustralia PTY Ltd, incorporated in ****, is a Software Services company
n
XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and
Manufacturingdomains.
n
We have 120+technocrats in Australia working at our clientlocations.
n
XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
n
We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
n
n
Job Description
n
Role Summary
n
We are seeking anexperienced GRC Consultant – Cyber Lead to drive governance and maturityof non-OS vulnerability management across enterprise application andplatform environments.
n
This role focuses on cyberrisk oversight, exception management, and vulnerability treatment strategy,ensuring risks are effectively assessed, governed, and aligned with enterprisesecurity standards—while remediation execution remains with delivery teams.
n
Key Responsibilities
n
Governance & Risk Oversight
n
n
Define and implement non-OS vulnerability management
frameworks,policies,
and standards
n
Establish governance forums, escalation paths, anddecision-making processes
n
Ensure compliance with regulatory, audit, and enterprisesecurity requirements
n
n
Exception & Treatment Management
n
n
Manage remediation exceptions and risk acceptance lifecycle
n
Validate compensating controls and residual risks
n
Drive risk-based treatment plans with application andplatform teams
n
Perform risk assessments for vulnerabilities that cannot beremediated
n
Enable risk-based decision-making aligned to business riskappetite
n
Ensure proper documentation, tracking, and periodic review ofaccepted risks
n
n
Tooling & Capability Uplift
n
n
Lead tooling strategy, evaluation, and automation initiatives
n
Improve vulnerability management maturity and processes
n
Support training and adoption across delivery teams
n
n
Security Improvement & SDLC Integration
n
n
Oversee remediation outcomes from pen tests, audits, andassessments
n
Promote secure-by-design and DevSecOps practices
n
Ensure vulnerabilities are identified and treated beforeproduction release
n
n
Stakeholder Management
n
n
Collaborate with Cyber, Application, Infrastructure, andOperations teams
n
Provide risk insights to senior leadership and governance forums
n
Influence prioritization based on risk severity and businessimpact
n
n
Required Skills & Experience
n
n
Robust background in GRC, cyber risk, and
vulnerabilitymanagement
n
Experience with
application/platform
vulnerabilities (non-OS)
n
Knowledge of frameworks: ISO *****, NIST, CIS
n
Hands-on exposure to tools like Qualys, Tenable, Snyk, orsimilar
n
Expertise in risk assessment, exception management, andcompliance
n
Strong stakeholder engagement and communication skills
n
Familiarity with DevSecOps / SDLC security practices
n
n
Qualifications
n
n
Bachelor's degree in IT / Cybersecurity or related field
n
#J-*****-Ljbffr
📌 Grc Consultant - Cyber Lead (Victoria)
🏢 Xpt Software Australia
📍 Victoria