Senior Security Advisor (Queensland)

Senior Security Advisor (Queensland)

24 Aug
|
Decipher Bureau
|
Queensland

24 Aug

Decipher Bureau

Queensland

Our client is part of a global portfolio of specialised software businesses operating across Australia, the UK, Canada and the US. With businesses at varying levels of security and technical maturity, they are continuing to build a central cyber security function that provides practical guidance, expertise and support across the portfolio. They are looking for a Senior Security Advisor who can bridge the gap between technical security, GRC and business advisory. This is not a traditional compliance role, you'll need to understand how security controls work in practice, assess risk in context and work with technical and business stakeholders to implement solutions that are proportionate to the organisation. Importantly, this is an influence-led role. You won't always have direct authority, budget or a dedicated security team, so the ability to build relationships, challenge constructively and bring stakeholders along on the security journey will be critical
The Role
Reporting to the CISO, you'll work across the global portfolio, partnering with CTOs, engineering teams, developers and business leaders to improve security maturity across a diverse range of software businesses. You'll operate across approximately 60% technical security and 40% GRC/advisory, providing practical guidance across security architecture, engineering, risk, governance and compliance.
Key Responsibilities
Provide security architecture and engineering guidance across cloud, identity, network, endpoint and application environments
Translate security risks into practical, proportionate and achievable controls
Partner with CTOs, developers, architects and technical leads to embed Secure by Design principles




Assess security risks across businesses with different levels of technical and security maturity
Operationalise security frameworks, policies and processes across the portfolio
Support GRC activities aligned to NIST, ISO *****, SOC 2 and relevant international requirements
Conduct third-party and vendor security risk assessments
Support security uplift and integration activities across newly acquired businesses
Identify opportunities to improve security processes, reporting and compliance automation
Provide clear security reporting, risk insights and recommendations to senior leadership and board-level stakeholders
Challenge security decisions where required, while avoiding a one-size-fits-all approach
Build strong relationships across the portfolio and influence security outcomes without relying on formal authority
What You'll Bring
We're looking for someone who can comfortably move between a technical discussion with an engineer and a risk conversation with a senior business stakeholder.
You'll ideally bring:
Strong experience across cyber security advisory and GRC
Practical understanding of security frameworks including NIST, ISO ***** and/or SOC 2
Hands-on security experience across areas such as cloud, identity, network, endpoint or application security




Experience conducting security risk assessments and translating findings into practical remediation
Strong advisory, consulting and stakeholder management skills
The ability to communicate effectively with technical teams, executives and business leaders
A pragmatic approach to risk, understanding that the right control depends on the business, its maturity, resources and risk appetite
Confidence to challenge stakeholders and push back when required, without becoming a blocker
Experience working across multiple businesses, consulting environments, software organisations or M&A;/acquisition environments is highly desirable
Certifications such as CISSP, CISM or ISO ***** Lead Auditor are advantageous but not essential. We're more interested in your ability to apply security frameworks and risk principles in the real world than simply having them listed on your CV.
What's in it for You?
Genuine opportunity to shape cyber security across a diverse global software portfolio
Exposure to businesses operating across Australia, the UK, Canada and the US
Opportunity to work across technical security, GRC, risk and advisory
Clear pathway towards future security leadership as the function grows
Strong investment in training, certifications and professional development
Opportunities to attend industry conferences
Exposure to international security, GRC and regulatory environments
Hybrid working, with a minimum of 3 days per week in the office
Chance to work across the Melbourne and Sydney offices where required
A collaborative environment that values critical thinking, initiative and pragmatic security advice
#J-*****-Ljbffr

📌 Senior Security Advisor (Queensland)
🏢 Decipher Bureau
📍 Queensland

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior security advisor (queensland) / queensland

Subscribe to this job alert:

Get the latest job offers by email for: senior security advisor (queensland) / queensland