Deloitte

Senior Consultant - Control Assurance

Deloitte

Sydney, New South Wales, Australia · Full Time

Be the first to apply

Experience
Any
Salary
Openings
1
Posted
1 ಗಂಟೆ ಹಿಂದೆ
Work mode
In office
Eligibility
Applicants must hold Australian citizenship to be eligible for this position.
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

This position is for a Senior Consultant within the Cyber Governance, Risk, and Compliance (GRC) team, located in Sydney with a hybrid work arrangement. The role involves leading control assurance and maturity assessments focused on enhancing clients' cybersecurity posture using frameworks such as ASD Essential Eight, ISO 27001, and NIST CSF. The consultant will evaluate control design and operational effectiveness by validating technical evidence from group policies, endpoint security, identity controls, and operational processes.

Responsibilities

The candidate is expected to lead comprehensive cyber risk and control assessments, translating risk findings into clear remediation strategies. This includes collaborating with stakeholders across technology teams, vendors, and senior management to prioritize security improvements aligned with risk tolerance and regulatory standards. Deliverables include presenting findings to governance bodies and producing auditable reports that facilitate informed decision-making. The role requires steering fieldwork operations and managing fast-paced programs with multiple stakeholders, while also supporting audit and compliance engagements.

About the Team

The Cyber GRC team specializes in helping organizations navigate cybersecurity risks by strengthening control environments and meeting increasing regulatory requirements. Their expertise spans governance, assurance, compliance, resilience, cloud security, identity management, third-party risk, and overall cyber maturity enhancement.

Candidate Profile

  • Australian citizenship is mandatory.
  • Proven experience in cyber GRC, risk assessment, assurance testing, or control validation with leadership capacity.
  • Demonstrated hands-on experience with ASD Essential Eight maturity evaluations and evidence validation.
  • In-depth knowledge of cybersecurity frameworks including ISO 27001, NIST CSF, CIS Controls, and applicable Australian regulations.
  • Experience engaging with infrastructure, cloud, endpoint, identity, and vendor teams to define realistic remediation plans.
  • Strong communication skills, adept at creating executive-level reports and delivering presentations to governance forums.
  • Pragmatic approach balancing security improvements with operational considerations.
  • Relevant professional certifications such as CISSP, CISM, CRISC or familiarity with ASD / IRAP frameworks are advantageous.

Work Environment & Benefits

The organization prioritizes inclusive culture, diversity, and equity. Flexible working arrangements support work-life balance, complemented by wellbeing initiatives, paid volunteer days, retail discounts, comprehensive parental leave, and career development coaching. The focus remains on delivering impactful work while nurturing employee growth in a supportive environment.

Additional Information

Applicants will go through a background screening process. The recruitment and evaluation align with established internal talent standards ensuring consistent candidate quality and growth potential.

Level

Senior

How they work

Communication Teamwork & Collaboration Problem Solving Leadership Decision Making
🤖
Online · instant AI help