Perks & Benefits
Job Description
About the role
The Senior GRC Security Consultant leads governance, risk and compliance (GRC) engagements for Spartans Security clients, providing expert advice and hands-on delivery across security strategies, control frameworks (e.g. ISO/IEC 27001, NIST CSF, ASD Essential Eight), risk assessment, incident response uplift, policy development, and security program roadmaps. The role operates in a CISO-as-a-Service capacity across multiple customers, building stakeholder trust, uplifting security posture and ensuring alignment with regulatory and industry requirements.
We are seeking an experienced Cyber Security Consultant to deliver governance, risk, compliance (GRC) and operational cyber security services across a diverse customer base. The role involves independently scoping and delivering security assessments, leading cyber risk and compliance activities, providing specialist advice to stakeholders, and supporting organisations in improving their overall cyber resilience.
The successful candidate will perform assessments against recognised frameworks and standards including ISO/IEC 27001, NIST CSF and ASD Essential Eight, develop remediation roadmaps and maturity uplift plans, and support customer compliance with regulatory obligations such as APRA CPS 234 and SOCI where applicable.
This position combines strategic, governance and hands-on cyber security responsibilities, including cyber architecture, incident response, Security Operations Centre (SOC) coordination, vulnerability management, security monitoring, threat hunting, identity and access management (IAM), cloud security and security governance across on-premises and cloud environments including Microsoft 365/Azure and AWS.
The role requires engagement with executives, project teams, vendors and service providers, acting as a trusted advisor on cyber risk, security strategy and governance. Responsibilities include maintaining Information Security Risk Registers, performing business impact analyses, defining methodologies for identifying critical information assets, supporting audits, developing policies and procedures, and producing high-quality reports, statements of applicability, dashboards and executive briefings.
The consultant will contribute to incident response planning and testing, disaster recovery initiatives, cyber awareness programs, service development activities, mentoring of junior consultants and pre-sales engagements including proposal development, level-of-effort estimations and solution design.
Key Responsibilities
Skill & Experience
Required Skills and Experience:
• Demonstrated experience delivering senior‑level GRC engagements across multiple industries (consulting or in‑house).
• Deep knowledge of security frameworks and regulatory standards (ISO/IEC 27001, NIST CSF, ASD Essential Eight, PCI DSS; desirable: APRA CPS 234, SOCI).
• Proficiency in security governance, risk assessment, control design, policy development and metrics/reporting.
• Strong stakeholder management, communication and influencing skills, including executive reporting.
• Hands‑on familiarity with enterprise and cloud environments (e.g., Microsoft AD, Microsoft 365/Azure, AWS) and common security controls (firewalls, EDR/SIEM, WAF, IAM).
• Ability to work independently across concurrent engagements, meeting deadlines and quality expectations.
Qualifications & Experience?
• Bachelor’s degree in information security, Computer Science, Information Systems or related discipline (or equivalent experience).
• 10+ years’ total experience in information security, including 4+ years in security consulting and/or GRC leadership roles.
• Experience working within international or multinational organisations (particularly in the telecommunications or banking sectors) is highly regarded.
• Exposure to global security standards and cross‑border GRC or cybersecurity programs across diverse geographic environments is strongly preferred.
• Must hold at least three of the following relevant certifications: CISSP, CISM, CRISC, CISA, ISO/IEC 27001 Lead Implementer, and ISO/IEC 27001 Lead Auditor.
• Evidence of continuing professional development and familiarity with current threat and compliance landscapes.
Right to Work Requirement:
Applicants must have the legal right to work in Australia at the time of application.
Working Conditions:
Hybrid work model (on‑site client meetings as required). Some interstate travel may be required based on client needs.
Job Location
Spartans Security
Founded since:
2018
Industry:
Information & Communication Technology
Location:
Cremorne VIC 3121
Jobs:
1 open position
Other jobs at Spartans Security
There are no similar listings