21 Sep
|
Sharp & Carter Brisbane
|
Brisbane
21 Sep
Sharp & Carter Brisbane
Brisbane
We are currently seeking an experienced Cyber Security Governance & Assurance Specialist to join our Queensland local government client and play a key role in strengthening cyber security governance, risk and assurance across the organisation.
This role would suit a Cyber Security Governance, Risk & Compliance professional, Cyber Security Assurance Specialist, Information Security Specialist or similar, who enjoys providing trusted advice, working with stakeholders and improving cyber security maturity across an organisation.
The Opportunity:
Reporting to the Cyber Security Lead and working closely with stakeholders across the organisation, you will support a broad range of cyber security governance and assurance activities.
You will provide independent specialist advice on cyber governance, risk and compliance matters, translate complex technical security issues into practical business advice and help facilitate effective decision-making across leadership and governance forums.
The role will have a strong focus on control validation, cyber risk management, audit, compliance, governance reporting and information security frameworks.
Key responsibilities include:
- Provide specialist advice on cyber security governance, assurance, risk and compliance matters
- Interpret relevant legislation, regulatory requirements, standards and industry obligations and translate these into practical advice
- Support the maintenance and continuous improvement of cyber security policies, standards and guidelines
- Develop and maintain governance artefacts including control registers, compliance schedules and exception/waiver registers
- Coordinate cyber security governance forums, including preparation of reports, dashboards and action tracking
- Design,
manage and execute the organisation's cyber security control validation program
- Develop testing methodologies, conduct sampling and walkthroughs, review evidence and maintain a rolling testing plan
- Document control findings, root causes and remediation actions and track these through to closure
- Facilitate cyber risk assessments and maintain risk registers and treatment plans
- Support risk reporting and escalation to relevant stakeholders and governance forums
- Provide specialist support to internal and external cyber security audits, including evidence preparation and stakeholder coordination
- Support business continuity and disaster recovery activities, including disaster recovery testing and remediation
About You:
- 5-7 years' experience across IT, with at least 3 years' experience in an information security role
- Demonstrated experience across cyber security governance, risk, assurance and/or compliance
- Strong understanding of information security concepts, controls, risk principles and industry best practice
- Experience working with recognised security frameworks such as ISO 27001/2700x, NIST CSF or the ACSC Essential Eight
- Strong understanding of cyber security legislation, regulatory obligations and industry standards
- Experience designing or executing control validation, testing or assurance programs
- Experience supporting internal or external cyber security audits
- Strong experience facilitating cyber risk assessments, maintaining risk registers and tracking remediation activities
- Ability to provide independent specialist advice and influence outcomes across complex environments
- Excellent communication and stakeholder engagement skills, with the ability to work effectively with technical teams, project and application development teams, management and business stakeholders
- Strong analytical and problem-solving skills, with the ability to connect business requirements and risks to appropriate security controls
- A proactive approach to keeping up to date with the evolving cyber security and threat landscape
- Bachelor's degree in Cyber Security, Information Systems or a related discipline, or equivalent demonstrated experience
- Relevant certifications such as CISA, CRISC, CISSP or ISO 27001 will be highly regarded
- Postgraduate qualifications in cyber security, risk or governance will be highly regarded
The Perks:
Our client offers a comprehensive range of advantages, including:
- 5 weeks annual leave plus 17.5% leave loading
- 3 weeks personal/carer's leave
- 14 weeks paid parental leave
- Domestic and Family Violence Leave
- Natural Disaster Leave
- Up to 13.5% employer superannuation contribution for contributing members, subject to a minimum 6% employee contribution
- Annual wage progression
- Salary sacrifice opportunities
- Access to a range of learning and development opportunities, including on-the-job learning and formal training programs
- Fitness Passport with discounted membership to selected health and wellbeing facilities
- Employee Loyalty Program offering discounts at selected local businesses
- Employee Assistance Program
📌 Cyber Security Governance & Assurance Specialist (Brisbane)
🏢 Sharp & Carter Brisbane
📍 Brisbane