25 Aug
|
Xpt Software Australia
|
Victoria
25 Aug
Xpt Software Australia
Victoria
Job Description
Lead Risk Assessor
n
Role Summary
n
Senior cyber security risk professional responsible for leading risk assessments, providing strategic risk guidance, and influencing business decisions through explicit communication of cyber security risks and opportunities.
n
Key Accountabilities
n
n
Lead cyber security risk assessments across projects, products, and technology initiatives.
n
Collaborate with project teams to identify, assess, and address security gaps and control deficiencies.
n
Communicate complex technical risks in clear business terms, including to executive stakeholders through risk decision-making processes.
n
Make informed risk-based decisions and manage stakeholder expectations effectively.
n
Lead the uplift of team processes, documentation, and engagement models.
n
n
Additional Responsibilities
n
n
Collaborate with business stakeholders, engineers, delivery teams, product vendors, partners, and cyber assurance teams to understand and communicate cyber risk.
n
Define and maintain reusable assets including standardised findings, templates, and process improvements.
n
Contribute to the creation and governance of security strategy, standards, frameworks, and policies.
n
Identify and communicate security risks in a timely manner while incorporating insights from privacy,
legal, engineering, and operational stakeholders.
n
Develop strategic relationships across industry and technology vendors to anticipate emerging threats and opportunities.
n
Mentor and coach risk assessors and secondees through guidance, feedback, and knowledge sharing.
n
Manage complex initiatives while simplifying outcomes to support effective delivery and execution.
n
n
Qualifications And Experience
n
n
Minimum 15 years of experience within Cyber Security.
n
At least 8 years of experience in a Governance, Risk and Compliance (GRC) or Risk Management function.
n
Practical experience conducting technical risk assessments.
n
Knowledge of industry frameworks and standards including ISO *****, PCI-DSS, NIST, and enterprise security frameworks.
n
Strong stakeholder engagement and communication skills with the ability to translate technical risks into business insights.
n
Experience working within large and complex enterprise environments.
n
n
Highly Desirable
n
n
Previous experience in a non-cyber risk or GRC role.
n
Industry certifications such as CRISC, CISSP, CISM, or SABSA.
n
Experience working within Agile and DevOps environments.
n
#J-*****-Ljbffr
📌 Leadrisk Assessor_Cybersecurity (Victoria)
🏢 Xpt Software Australia
📍 Victoria