About The Role
MyCISO is the SecurityOS helping organisations across ANZ and beyond run their security programs with clarity and control. Our managed service offerings —
- Foundations and Complete — put a dedicated security consultant alongside every customer, translating platform data into a structured, ongoing uplift journey. This is that role.
As a GRC Security Consultant you will own a portfolio of customers across both service tiers, acting as their embedded security advisor. You will guide each organisation from onboarding through to measurable improvement — using SecurityOS as the backbone of every engagement. You will run the cadence, own the roadmap, and be the person customers call when they need direction. The role is hybrid, typically 3 days per week in our Sydney CBD office.
What You'll Do
- p]:mb-0 [&>p]:inline">
- Onboard new Foundations and Complete customers onto SecurityOS — configuring their security program, mapping their applicable frameworks (Essential Eight, ISO 27001, NIST CSF, SOC 2), and establishing their baseline security posture.
- p]:mb-0 [&>p]:inline">
- Build and maintain a tailored security improvement roadmap for each customer — prioritising uplift actions based on their risk profile, obligations, and maturity targets.
- p]:mb-0 [&>p]:inline">
- Deliver regular advisory check-ins and monthly or quarterly business reviews — translating SecurityOS metrics, control gaps, and risk data into clear guidance customers can act on.
- p]:mb-0 [&>p]:inline">
- Guide customers through risk assessments, supplier reviews, culture and awareness programs,
and incident readiness — leveraging every module of the platform to drive continuous improvement.
- p]:mb-0 [&>p]:inline">
- Manage customer health proactively — monitoring adoption, identifying stalled progress, and intervening early before small gaps become renewal risks.
- p]:mb-0 [&>p]:inline">
- Support customers through board and executive reporting — helping them communicate security posture, progress, and investment to leadership with confidence.
- p]:mb-0 [&>p]:inline">
- Work with the Security Architect on complex customer engagements, escalated issues, and strategy design for Complete tier accounts.
- p]:mb-0 [&>p]:inline">
- Contribute to delivery playbooks, onboarding templates, and framework guidance that make the whole team more consistent and productive.
What You'll Bring
- p]:mb-0 [&>p]:inline"> 3+ years in a GRC, information security, or cybersecurity advisory role.
- p]:mb-0 [&>p]:inline">
- Solid working knowledge of at least one major framework —
- Essential Eight, ISO 27001, NIST CSF or SOC 2.
- p]:mb-0 [&>p]:inline">
Experience advising or managing security programs for SMB or mid-market organisations.
- p]:mb-0 [&>p]:inline">
- Comfortable in front of customers — able to explain security concepts clearly to both technical teams and non-technical executives.
- p]:mb-0 [&>p]:inline">
- Organised and proactive — able to manage a portfolio of concurrent customer engagements without dropping the ball.
- p]:mb-0 [&>p]:inline">
Experience with GRC or security management platforms is a strong plus.
- p]:mb-0 [&>p]:inline">
- CISSP, CISM, ISO 27001 Lead Auditor/Implementer, or ASD Essential Eight certification is an advantage.
Who You Are
- p]:mb-0 [&>p]:inline">
- A trusted advisor by nature — customers feel safer and more confident after talking to you.
- p]:mb-0 [&>p]:inline">
- Pragmatic and outcome-focused — you cut through complexity and help customers take the next right step, not the perfect theoretical one.
- p]:mb-0 [&>p]:inline">
- Self-directed and accountable — you own your portfolio and drive it forward without needing constant direction.
- p]:mb-0 [&>p]:inline">
- Genuinely curious about security and motivated by helping organisations build real resilience, not just tick boxes.
Why MyCISO We are the 2025 AISA Startup of the Year, growing fast across ANZ and into North America.
In this role you will work with a broad range of organisations across sectors, deepen your GRC expertise, and help shape how managed security services are delivered on a modern AI-native platform.
Your impact on customers is direct and visible.
To apply, send your CV and a brief note on why this role interests you to
[email protected]
📌 GRC Security Consultant (Sydney)
🏢 MYCISO
📍 Sydney