We are seeking an experienced Cyber Security GRC Specialist to support cyber security governance, risk and compliance activities within a major resilience uplift program.
n
The role will work closely with cyber security teams and stakeholders to strengthen security governance, assurance and documentation. During electoral events, the successful candidate may also support election-specific cyber security requirements.
n
Key Responsibilities
n
n
- Contribute to solution design with a focus on cyber security considerations.
n
- Review and provide recommendations on security requirements.
n
- Support cyber security governance, risk and compliance activities.
n
- Develop clear communications and documentation for senior executive decision-making.
n
- Coordinate security assurance activities, including IRAP assessments and penetration testing.
n
- Lead the development and maintenance of formal cyber security documentation.
n
- Engage with stakeholders and clients to identify requirements and achieve agreed outcomes.
n
- Support the delivery of cyber security resilience and assurance initiatives.
n
n
Essential Skills & Experience
n
n
- Strong knowledge of the Information Security Manual (ISM), Protective Security Policy Framework (PSPF) and Essential Eight.
n
- Demonstrated experience working in a Cyber Security GRC role.
n
- Proven ability to manage stakeholder and client relationships and achieve successful outcomes.
n
- Demonstrated experience developing GRC policies, processes, reports and security documentation.
n
- Strong written and verbal communication skills, including the ability to communicate security matters to senior executives.
n
- Current NV1 security clearance is mandatory.
n
n
Desirable
n
n
- Minimum 5 years' experience in cyber security, GRC, security assurance or related roles.
n
- Experience supporting government cyber security programs.
n
- Experience with IRAP, penetration testing and security assurance activities.
n
- Understanding of cyber resilience and risk management within complex environments.
n
n
We are looking for a cyber security qualified with strong GRC, assurance and stakeholder management skills who can translate security requirements into practical outcomes and produce high-quality documentation for technical and executive audiences.
n
If you have strong cyber security GRC experience, government security framework knowledge and an NV1 clearance, we would like to hear from you.