02 Oct
|
Client 1
|
Canberra
Role Title
GRC (Governance, Risk and Compliance) Lead
Location
Canberra, ACT
Working Arrangement
Permanent
Clearance Required
Active AGSVA TSPV required, NV2 may be considered with the willingness to uplift to TSPV.
Company Overview
Join a highly regarded Australian technology organisation delivering advanced capability to Defence and Government customers. Operating at the forefront of national security, the organisation is renowned for developing complex, mission-critical systems that directly contribute to Australia's defence capability.
You’ll be joining a high-performing cyber security function where governance, risk and compliance play a critical role in protecting sensitive environments and enabling the delivery of cutting-edge technology programs. This is an prospect to have genuine influence, work alongside respected cyber professionals, and contribute to projects of national importance.
Job Description
We are seeking an experienced Governance, Risk and Compliance Cyber Lead to drive cyber governance, risk management, compliance and system authorisation activities across a complex technology environment.
Reporting into cyber security leadership, you will act as a trusted advisor to stakeholders, ensuring systems meet cyber security requirements, regulatory obligations and accreditation standards. You will lead Assessment and Authorisation activities, support cyber risk management processes and contribute to strengthening the organisation's overall cyber security posture.
Duties and Responsibilities
- Lead cyber governance, risk and compliance activities across the organisation.
- Drive cyber security risk assessment and risk treatment activities.
- Manage and support system Assessment and Authorisation (A&A;) processes.
- Develop and maintain cyber security policies, procedures and supporting documentation.
- Support accreditation and assurance activities for internal and external stakeholders.
- Work closely with technology, operations and security teams to improve cyber security outcomes.
- Contribute to the implementation of security architectures and cyber security controls.
- Maintain cyber risk registers and support enterprise risk management activities.
- Provide governance reporting, metrics and insights to leadership.
- Engage with government agencies, authorisation bodies, Defence stakeholders and vendors as required.
Education / Certifications Required
Desirable certifications include:
- CISSP
- CISM
- CRISC
- ISO 27001 Lead Implementer or Lead Auditor
- Other relevant cyber security, governance or risk management certifications
Knowledge / Skills Required
- Demonstrated experience within Cyber Governance, Risk and Compliance.
- Strong understanding of Assessment and Authorisation frameworks and methodologies.
- Experience developing security documentation,
including policies, procedures, risk assessments and accreditation artefacts.
- Knowledge of the Defence Security Principles Framework (DSPF).
- Strong understanding of the Information Security Manual (ISM) and Essential Eight.
- Experience conducting cyber security risk assessments and managing remediation activities.
- Excellent stakeholder engagement and communication skills.
- Ability to work with both technical and non-technical audiences.
- Strong analytical and critical thinking capabilities.
- Knowledge of the MITRE ATT&CK; Framework is highly regarded.
- Experience supporting Defence-accredited environments will be highly regarded.
Employment Benefits
- Opportunity to work on nationally significant Defence and Government programs.
- Exposure to complex and highly secure technology environments.
- Career growth within a mature and respected cyber security function.
- Work alongside experienced industry leaders and subject matter experts.
- Long-term career stability with a growing Australian organisation.
- Competitive remuneration package.
Diversity and Inclusion
We are committed to creating an inclusive workplace where diversity is valued and respected. We encourage applications from people of all backgrounds, cultures, identities, abilities and experiences.
Veterans
Veterans and ex-serving Australian Defence Force personnel are strongly encouraged to apply. Your experience, leadership and understanding of complex environments are highly valued.
#J-18808-Ljbffr
📌 GRC (Governance, Risk and Compliance) Lead (Canberra)
🏢 Client 1
📍 Canberra