02 Oct
|
Xpt Software Australia
|
Melbourne
02 Oct
Xpt Software Australia
Melbourne
Job Description
n
XPT Software Australia Pty Ltd | Contract
n
Melbourne, Australia | Posted on 06/16/2026
n
n
XPT SoftwareAustralia PTY Ltd, incorporated in ****, is a Software Services company
n
XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and
Manufacturingdomains.
n
We have 120+technocrats in Australia working at our clientlocations.
n
XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
n
We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
n
Job Description n
Role Summary
n
We are seeking anexperienced
GRC Consultant – Cyber Lead
to drive governance and maturityof
non-OS vulnerability management
across enterprise application andplatform environments.
n
This role focuses on
cyberrisk oversight, exception management, and vulnerability treatment strategy
,ensuring risks are effectively assessed, governed, and aligned with enterprisesecurity standards—while remediation execution remains with delivery teams.
n
Key Responsibilities
n
Governance & Risk Oversight
n
n
Define and implement
non-OS vulnerability management
frameworks,policies,
and standards
n
Establish
governance forums, escalation paths, anddecision-making processes
n
Ensure compliance with
regulatory, audit, and enterprisesecurity requirements
n
n
Exception & Treatment Management
n
n
Manage
remediation exceptions and risk acceptance lifecycle
n
Validate
compensating controls and residual risks
n
Drive
risk-based treatment plans
with application andplatform teams
n
Perform
risk assessments for vulnerabilities that cannot beremediated
n
Enable
risk-based decision-making aligned to business riskappetite
n
Ensure proper
documentation, tracking, and periodic review ofaccepted risks
n
n
Tooling & Capability Uplift
n
n
Lead
tooling strategy, evaluation, and automation initiatives
n
Improve
vulnerability management maturity and processes
n
Support
training and adoption across delivery teams
n
n
Security Improvement & SDLC Integration
n
n
Oversee remediation outcomes from
pen tests, audits, andassessments
n
Promote
secure-by-design and DevSecOps practices
n
Ensure vulnerabilities are
identified and treated beforeproduction release
n
n
Stakeholder Management
n
n
Collaborate with
Cyber, Application, Infrastructure, andOperations teams
n
Provide
risk insights to senior leadership and governance forums
n
Influence prioritization based on
risk severity and businessimpact
n
n
Required Skills & Experience
n
n
Strong background in
GRC, cyber risk, and
vulnerabilitymanagement
n
Experience with
application/platform
vulnerabilities (non-OS)
n
Knowledge of frameworks:
ISO *****, NIST, CIS
n
Hands-on exposure to tools like
Qualys, Tenable, Snyk, orsimilar
n
Expertise in
risk assessment, exception management, andcompliance
n
Solid
stakeholder engagement and communication skills
n
Familiarity with
DevSecOps / SDLC security practices
n
n
Qualifications
n
n
Bachelor's degree in
IT / Cybersecurity or related field
n
n
#J-*****-Ljbffr
📌 Grc Consultant - Cyber Lead (Melbourne)
🏢 Xpt Software Australia
📍 Melbourne