Vectiq is looking for an experienced Security / GRC SME to help design and embed an enterprise Vulnerability Management capability within a complex, security-focused environment.
This is a specialist advisory role for someone who can connect technical vulnerabilities with business risk, governance and executive-level assurance.
The Role
You’ll work closely with the CISO, security leadership, IT Operations and business stakeholders to:
- Design and operationalise an enterprise Vulnerability Management framework
- Establish risk-based prioritisation, remediation, escalation and exception management
- Translate technical vulnerability data into business risk and executive reporting
- Align security controls with PSPF, ISM, regulatory and audit requirements
- Work with tools such as Tenable or equivalent, CMDB/asset repositories and ITSM workflows
- Define governance, operating models, responsibilities and transition into BAU
- Contribute to the organisation’s broader GRC and cyber security uplift
About You We’re looking for a specialist rather than a generalist security resource, with:
- Strong enterprise Vulnerability Management experience
- Solid GRC, cyber risk and security assurance expertise
- Knowledge of ISM, PSPF or equivalent frameworks
- Experience with Tenable, Qualys, Rapid7 or similar
- Understanding of CMDB, asset management and ITSM processes
- Confidence advising CISO and senior leadership stakeholders
- Federal Government or highly regulated setting experience highly regarded
Permanent or Contract – You Choose! We’re open to engaging the right person on either a permanent or contract basis, depending on your preference.
If you’re a Vulnerability Management and GRC specialist looking for an opportunity where you can shape the capability, not just operate it, we’d love to hear from you.
Apply now, or send your resume to
[email protected]
📌 Security / GRC SME (Canberra)
🏢 Vectiq
📍 Canberra