Senior Consultant - Control Assurance
Sydney, New South Wales, Australia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 2 घंटे पहले
- Work mode
- In office
- Eligibility
- Applicants must hold Australian citizenship to be eligible for this position.
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
This position is for a Senior Consultant within the Cyber Governance, Risk, and Compliance (GRC) team, located in Sydney with a hybrid work arrangement. The role involves leading control assurance and maturity assessments focused on enhancing clients' cybersecurity posture using frameworks such as ASD Essential Eight, ISO 27001, and NIST CSF. The consultant will evaluate control design and operational effectiveness by validating technical evidence from group policies, endpoint security, identity controls, and operational processes.
Responsibilities
The candidate is expected to lead comprehensive cyber risk and control assessments, translating risk findings into clear remediation strategies. This includes collaborating with stakeholders across technology teams, vendors, and senior management to prioritize security improvements aligned with risk tolerance and regulatory standards. Deliverables include presenting findings to governance bodies and producing auditable reports that facilitate informed decision-making. The role requires steering fieldwork operations and managing fast-paced programs with multiple stakeholders, while also supporting audit and compliance engagements.
About the Team
The Cyber GRC team specializes in helping organizations navigate cybersecurity risks by strengthening control environments and meeting increasing regulatory requirements. Their expertise spans governance, assurance, compliance, resilience, cloud security, identity management, third-party risk, and overall cyber maturity enhancement.
Candidate Profile
- Australian citizenship is mandatory.
- Proven experience in cyber GRC, risk assessment, assurance testing, or control validation with leadership capacity.
- Demonstrated hands-on experience with ASD Essential Eight maturity evaluations and evidence validation.
- In-depth knowledge of cybersecurity frameworks including ISO 27001, NIST CSF, CIS Controls, and applicable Australian regulations.
- Experience engaging with infrastructure, cloud, endpoint, identity, and vendor teams to define realistic remediation plans.
- Strong communication skills, adept at creating executive-level reports and delivering presentations to governance forums.
- Pragmatic approach balancing security improvements with operational considerations.
- Relevant professional certifications such as CISSP, CISM, CRISC or familiarity with ASD / IRAP frameworks are advantageous.
Work Environment & Benefits
The organization prioritizes inclusive culture, diversity, and equity. Flexible working arrangements support work-life balance, complemented by wellbeing initiatives, paid volunteer days, retail discounts, comprehensive parental leave, and career development coaching. The focus remains on delivering impactful work while nurturing employee growth in a supportive environment.
Additional Information
Applicants will go through a background screening process. The recruitment and evaluation align with established internal talent standards ensuring consistent candidate quality and growth potential.
Level
Senior