23 Aug
|
Interceptica
|
Melbourne
23 Aug
Interceptica
Melbourne
We are looking for an experienced Lead Risk Assessor to join our team in Melbourne and lead cyber security risk assessments across complex projects, programs, and technology initiatives.
This is a senior role suited to a cyber security risk qualified who can operate confidently with senior and executive stakeholders , translate technical security risks into business language, and influence sound risk decisions across the organization.
The Role
You will lead cyber security risk assessments throughout the delivery lifecycle, partnering with technology, security, project, and business teams to identify, evaluate, and address security risks early.
You will also play an important role in maturing the risk assessment function through improved methodologies, processes, documentation, governance, and stakeholder engagement.
Key Responsibilities
- Lead cyber security risk assessments across projects, programs, and strategic initiatives.
- Identify, assess, and communicate security risks and appropriate treatment options.
- Translate complex technical security issues into clear, actionable business risks.
- Engage with senior leadership and executive stakeholders on risk findings and recommendations.
- Facilitate risk decisioning and support risk owners in making informed decisions.
- Partner with Agile and DevOps delivery teams to embed security risk practices into iterative delivery.
- Maintain risk registers and track treatment plans through resolution or formal acceptance.
- Develop and improve risk assessment methodologies, templates, standards, and playbooks.
- Drive improvements in team processes, documentation, and stakeholder engagement.
- Contribute to broader GRC reporting, governance, metrics, and continuous improvement.
- Stay current with emerging cyber threats, regulatory requirements, and industry best practice.
What We're Looking For
Essential:
- 8+ years of professional experience , with significant experience in cyber security risk, GRC, information security, or a closely related discipline.
- Proven experience leading cyber security risk assessments in complex enterprise environments.
- Strong understanding of frameworks including NIST, ISO 27001/31000, COSO , or equivalent.
- Demonstrated experience engaging with senior and executive stakeholders .
- Strong understanding of risk governance, risk treatment, and risk decisioning.
- Experience working across Agile and DevOps environments .
- Excellent written and verbal communication skills, with the ability to explain technical risk in business terms.
- Strong stakeholder management, influencing, analytical, and critical-thinking skills.
- Ability to operate independently and exercise sound judgement in ambiguous situations.
Highly Desirable Experience across broader risk disciplines such as:
- Enterprise Risk
- Operational Risk
- GRC
- Compliance
- Internal Audit
- Technology Risk
Relevant certifications such as CRISC, CISM, CISSP, ISO 27001 Lead Risk Manager , or equivalent are highly regarded. Why Join?
This is an opportunity to take a leading role in shaping how cyber security risk is identified, assessed, communicated, governed, and managed across a complex organization — with genuine influence over security and business outcomes.
📌 Lead Risk Assessor (Melbourne)
🏢 Interceptica
📍 Melbourne