03 Oct
|
Spartans Security
|
Melbourne
03 Oct
Spartans Security
Melbourne
Job Description
The Senior GRC Security Consultant leads governance, risk and compliance (GRC) engagements for Spartans Security clients, providing expert advice and hands-on delivery across security strategies, control frameworks (e.g. ISO/IEC *****, NIST CSF, ASD Essential Eight), risk assessment, incident response uplift, policy development, and security program roadmaps. The role operates in a CISO-as-a-Service capacity across multiple customers, building stakeholder trust, uplifting security posture and ensuring alignment with regulatory and industry requirements.n
n
nWe are seeking an experienced Cyber Security Consultant to deliver governance, risk, compliance (GRC) and operational cyber security services across a diverse customer base. The role involves independently scoping and delivering security assessments, leading cyber risk and compliance activities, providing specialist advice to stakeholders, and supporting organisations in improving their overall cyber resilience.n
n
nThe successful candidate will perform assessments against recognised frameworks and standards including ISO/IEC *****, NIST CSF and ASD Essential Eight, develop remediation roadmaps and maturity uplift plans, and support customer compliance with regulatory obligations such as APRA CPS 234 and SOCI where applicable.n
n
nThis position combines strategic, governance and hands-on cyber security responsibilities, including cyber architecture, incident response, Security Operations Centre (SOC) coordination, vulnerability management, security monitoring, threat hunting, identity and access management (IAM), cloud security and security governance across on-premises and cloud environments including Microsoft 365/Azure and AWS.n
n
nThe role requires engagement with executives, project teams, vendors and service providers, acting as a trusted advisor on cyber risk, security strategy and governance. Responsibilities include maintaining Information Security Risk Registers, performing business impact analyses, defining methodologies for identifying critical information assets, supporting audits, developing policies and procedures, and producing high-quality reports, statements of applicability, dashboards and executive briefings.n
n
nThe consultant will contribute to incident response planning and testing,
disaster recovery initiatives, cyber awareness programs, service development activities, mentoring of junior consultants and pre-sales engagements including proposal development, level-of-effort estimations and solution design.n
n
nThe role operates in a CISO-as-a-Service capacity across multiple customers, building stakeholder trust, uplifting security posture and ensuring alignment with customer risk appetite, regulatory and industry requirements.n
n
nKey Responsibilitiesn
n
n• Deliver cyber security GRC engagements, including ISO/IEC *****, NIST CSF and ASD Essential Eight assessments, remediation roadmaps and maturity uplift plans.n
n• Conduct cyber governance, risk and compliance activities, including risk assessments, control reviews, gap analyses and compliance reviews.n
n• Lead security assessments and develop standards, policies, procedures and guidelines.n
n• Investigate cyber incidents and breaches, perform root cause analysis and corrective actions.n
n• Monitor security alerts, threat intelligence, logs and events; perform threat hunting and vulnerability identification.n
n• Coordinate incident response, including containment, eradication, recovery and reporting.n
n• Develop secure cyber architecture across on-premises and cloud environments.n
n• Implement and uplift IAM, network, endpoint, vulnerability and cloud security controls.n
n• Coordinate SOC operations, including case management, SIEM/SOAR workflows and escalations.n
n• Provide cyber security advisory and CISOaaS functions, including governance, executive reporting and board briefings.n
n• Support audits, prepare audit evidence, maintain Information Security Risk Registers, perform business impact analysis, control mapping and remediation tracking.n
n• Deliver awareness training, support disaster recovery planning, manage security applications, contracts and SLAs.n
n• Engage with clients, vendors and partners; produce reports; mentor consultants; support service development, pre-sales and proposals.n
n
nSkill & Experiencen
n
nRequired Skills and Experience:n
n
n• Demonstrated experience delivering senior‐level GRC engagements across multiple industries (consulting or in‐house).n
n
n• Deep knowledge of security frameworks and regulatory standards (ISO/IEC *****, NIST CSF, ASD Essential Eight, PCI DSS; desirable: APRA CPS 234, SOCI).n
n
n• Proficiency in security governance, risk assessment, control design, policy development and
metrics/reporting.n
n
n• Strong stakeholder management, communication and influencing skills, including executive reporting.n
n
n• Hands‐on familiarity with enterprise and cloud environments (e.g., Microsoft AD, Microsoft 365/Azure, AWS) and common security controls (firewalls, EDR/SIEM, WAF, IAM).n
n
n• Ability to work independently across concurrent engagements, meeting deadlines and quality expectations.n
n
nQualifications & Experience?n
n
n• Bachelor's degree in information security, Computer Science, Information Systems or related discipline (or equivalent experience).n
n
n• 10+ years' total experience in information security, including 4+ years in security consulting and/or GRC leadership roles.n
n
n• Experience working within international or multinational organisations (particularly in the telecommunications or banking sectors) is highly regarded.n
n
n• Exposure to global security standards and cross‐border GRC or cybersecurity programs across diverse geographic environments is strongly preferred.n
n
n• Must hold at least three of the following relevant certifications: CISSP, CISM, CRISC, CISA, ISO/IEC ***** Lead Implementer, and ISO/IEC ***** Lead Auditor.n
n
n• Evidence of continuing career development and familiarity with current threat and compliance landscapes.n
n
nRight to Work Requirement:n
n
nApplicants must have the legal right to work in Australia at the time of application. n
n
nWorking Conditions:n
n
nHybrid work model (on‐site client meetings as required). Some interstate travel may be required based on client needs.
📌 Senior Grc Security Consultant (Melbourne)
🏢 Spartans Security
📍 Melbourne