Senior GRC Consultant (NV1 Required)
12 Months
Canberra preferred, also open to Brisbane, Adelaide, Sydney and Melbourne
About the opportunity:
A leading national cyber security consultancy is growing its Governance, Risk and Compliance practice to support a solid pipeline of Defence and Federal Government work. They are looking for experienced GRC professionals from Senior Consultant through to Principal level to join long term engagements. You will help agencies understand, manage and reduce their cyber risk while working alongside a highly regarded team.
What you'll be doing:
Assessing systems against the ISM, PSPF and DSPF and documenting clear findings and recommendations
Writing and maintaining security documentation, including System Security Plans, Security Risk Management Plans and Incident Response Plans
Delivering Essential Eight maturity assessments and practical uplift roadmaps
Supporting clients through pre IRAP readiness, control remediation and documentation uplift
Advising senior stakeholders on cyber risk,
governance and compliance obligations
Producing high quality reports that translate complex security issues into practical outcomes
Mentoring other consultants and leading work packages, depending on level
What we need to see:
Current NV1 clearance or higher
3+ years in cyber security GRC, ideally within Defence or Federal Government
Robust working knowledge of the ISM, PSPF and Essential Eight
Proven experience writing technical security documentation for government systems
Confident stakeholder engagement and transparent written communication
Comfortable working on client site as engagements require
Bonus points:
ASD endorsed IRAP assessor
Experience leading IRAP or pre IRAP engagements
DSPF and Defence authorisation experience
Experience leading teams across multiple work packages
CISSP, CISM, CRISC or CISA
ISO 27001 Lead Auditor or Lead Implementer