Powered by pgvector · cosine kNN
Spartans Security
Job Description The Senior GRC Security Consultant leads governance, risk and compliance (GRC) engagements for Spartans Security clients, providing expert advice and hands-on delivery across security strategies, contr…
Your match
See how you fit
Scored against this job in seconds
Your account
Sign in to apply
Your profile and your match for this job appear right here.
sign in above to apply · via Jora
About the role
Job Description
The Senior GRC Security Consultant leads governance, risk and compliance (GRC) engagements for Spartans Security clients, providing expert advice and hands-on delivery across security strategies, control frameworks (e.g. ISO/IEC 27001, NIST CSF, ASD Essential Eight), risk assessment, incident response uplift, policy development, and security program roadmaps. The role operates in a CISO-as-a-Service capacity across multiple customers, building stakeholder trust, uplifting security posture and ensuring alignment with regulatory and industry requirements.
We are seeking an experienced Cyber Security Consultant to deliver governance, risk, compliance (GRC) and operational cyber security services across a diverse customer base. The role involves independently scoping and delivering security assessments, leading cyber risk and compliance activities, providing specialist advice to stakeholders, and supporting organisations in improving their overall cyber resilience.
The successful candidate will perform assessments against recognised frameworks and standards including ISO/IEC 27001, NIST CSF and ASD Essential Eight, develop remediation roadmaps and maturity uplift plans, and support customer compliance with regulatory obligations such as APRA CPS 234 and SOCI where applicable.
This position combines strategic, governance and hands-on cyber security responsibilities, including cyber architecture, incident response, Security Operations Centre (SOC) coordination, vulnerability management, security monitoring, threat hunting, identity and access management (IAM), cloud security and security governance across on-premises and cloud environments including Microsoft 365/Azure and AWS.
The role requires engagement with executives, project teams, vendors and service providers, acting as a trusted advisor on cyber risk, security strategy and governance. Responsibilities include maintaining Information Security Risk Registers, performing business impact analyses, defining methodologies for identifying critical information assets, supporting audits, developing policies and procedures, and producing high-quality reports, statements of applicability, dashboards and executive briefings.
The consultant will contribute to incident response planning and testing, disaster recovery initiatives, cyber awareness programs, service development activities, mentoring of junior consultants and pre-sales engagements including proposal development, level-of-effort estimations and solution design.
The role operates in a CISO-as-a-Service capacity across multiple customers, building stakeholder trust, uplifting security posture and ensuring alignment with customer risk appetite, regulatory and industry requirements.
Key Responsibilities
• Deliver cyber security GRC engagements, including ISO/IEC 27001, NIST CSF and ASD Essential Eight assessments, remediation roadmaps and maturity uplift plans.
• Conduct cyber governance, risk and compliance activities, including risk assessments, control reviews, gap analyses and compliance reviews.
• Lead security assessments and develop standards, policies, procedures and guidelines.
• Investigate cyber incidents and breaches, perform root cause analysis and corrective actions.
• Monitor security alerts, threat intelligence, logs and events; perform threat hunting and vulnerability identification.
• Coordinate incident response, including containment, eradication, recovery and reporting.
• Develop secure cyber architecture across on-premises and cloud environments.
• Implement and uplift IAM, network, endpoint, vulnerability and cloud security controls.
• Coordinate SOC operations, including case management, SIEM/SOAR workflows and escalations.
• Provide cyber security advisory and CISOaaS functions, including governance, executive reporting and board briefings.
• Support audits, prepare audit evidence, maintain Information Security Risk Registers, perform business impact analysis, control mapping and remediation tracking.
• Deliver awareness training, support disaster recovery planning, manage security applications, contracts and SLAs.
• Engage with clients, vendors and partners; produce reports; mentor consultants; support service development, pre-sales and proposals.
Skill & Experience
Required Skills and Experience:
• Demonstrated experience delivering senior‑level GRC engagements across multiple industries (consulting or in‑house).
• Deep knowledge of security frameworks and regulatory standards (ISO/IEC 27001, NIST CSF, ASD Essential Eight, PCI DSS; desirable: APRA CPS 234, SOCI).
• Proficiency in security governance, risk assessment, control design, policy development and metrics/reporting.
• Strong stakeholder management, communication and influencing skills, including executive reporting.
• Hands‑on familiarity with enterprise and cloud environments (e.g., Microsoft AD, Microsoft 365/Azure, AWS) and common security controls (firewalls, EDR/SIEM, WAF, IAM).
• Ability to work independently across concurrent engagements, meeting deadlines and quality expectations.
Qualifications & Experience?
• Bachelor’s degree in information security, Computer Science, Information Systems or related discipline (or equivalent experience).
• 10+ years’ total experience in information security, including 4+ years in security consulting and/or GRC leadership roles.
• Experience working within international or multinational organisations (particularly in the telecommunications or banking sectors) is highly regarded.
• Exposure to global security standards and cross‑border GRC or cybersecurity programs across diverse geographic environments is strongly preferred.
• Must hold at least three of the following relevant certifications: CISSP, CISM, CRISC, CISA, ISO/IEC 27001 Lead Implementer, and ISO/IEC 27001 Lead Auditor.
• Evidence of continuing professional development and familiarity with current threat and compliance landscapes.
Right to Work Requirement:
Applicants must have the legal right to work in Australia at the time of application.
Working Conditions:
Hybrid work model (on‑site client meetings as required). Some interstate travel may be required based on client needs.
sign in above to apply · via Jora
Your job hunt, handled
Ask about any role and get a straight answer on your fit. Then stop searching: new matches land in your WhatsApp the moment they’re listed.
Free for jobseekers
CyberCX
About CyberCX CyberCX is the leading independent cyber security services organisation in Australia and New Zealand. We bring together the region’s most trusted cyber security companies to deliver end-to-end services t…
CyberCX
07th August, 2026 About CyberCX CyberCX is the leading independent cyber security services organisation in Australia and New Zealand. We bring together the region’s most trusted cyber security companies to deliver end…
CyberCX
07th August, 2026 About CyberCX CyberCX is the leading independent cyber security services organisation in Australia and New Zealand. We bring together the region’s most trusted cyber security companies to deliver end…
CyberCX
17th August, 2026 About CyberCX CyberCX is Australia and New Zealand’s leading cyber security services provider, trusted by private and public sector organisations to help manage cyber risk, respond to incidents, and …
ctrl:cyber
The Mission We are here to find those who strive for excellence, go the extra mile, and crave continuous growth. We’re an all-Australian cybersecurity firm helping some of the country’s biggest organisations stay ahea…
The Decipher Bureau
Setting the Scene Our client is part of a global portfolio of specialised software businesses operating across Australia, the UK, Canada and the US. With businesses operating at different levels of security and techni…