GRC Consultant - Cyber Lead

Posted Yesterday
Be an Early Applicant
Melbourne, Victoria, AUS
In-Office
Entry level
Information Technology • Software • Consulting
The Role
Leads governance and maturity for non-OS vulnerability management across application and platform environments. Responsibilities include defining policies and standards, managing exceptions and risk acceptance, assessing residual risk, developing treatment strategies, overseeing tooling and automation, integrating security into the SDLC, and reporting risk insights to leadership. The role collaborates across cyber, application, infrastructure, and operations teams while ensuring alignment with regulatory, audit, and enterprise security requirements.
Summary Generated by Built In

Role Summary

We are seeking an experienced GRC Consultant – Cyber Lead to drive governance and maturity of non-OS vulnerability management across enterprise application and platform environments.

This role focuses on cyber risk oversight, exception management, and vulnerability treatment strategy, ensuring risks are effectively assessed, governed, and aligned with enterprise security standards—while remediation execution remains with delivery teams.


Key Responsibilities

Governance & Risk Oversight

  • Define and implement non-OS vulnerability management frameworks, policies, and standards
  • Establish governance forums, escalation paths, and decision-making processes
  • Ensure compliance with regulatory, audit, and enterprise security requirements

Exception & Treatment Management

  • Manage remediation exceptions and risk acceptance lifecycle
  • Validate compensating controls and residual risks
  • Drive risk-based treatment plans with application and platform teams

Cyber Risk Management

  • Perform risk assessments for vulnerabilities that cannot be remediated
  • Enable risk-based decision-making aligned to business risk appetite
  • Ensure proper documentation, tracking, and periodic review of accepted risks

Tooling & Capability Uplift

  • Lead tooling strategy, evaluation, and automation initiatives
  • Improve vulnerability management maturity and processes
  • Support training and adoption across delivery teams

Security Improvement & SDLC Integration

  • Oversee remediation outcomes from pen tests, audits, and assessments
  • Promote secure-by-design and DevSecOps practices
  • Ensure vulnerabilities are identified and treated before production release

Stakeholder Management

  • Collaborate with Cyber, Application, Infrastructure, and Operations teams
  • Provide risk insights to senior leadership and governance forums
  • Influence prioritization based on risk severity and business impact

Required Skills & Experience

  • Strong background in GRC, cyber risk, and vulnerability management
  • Experience with application/platform vulnerabilities (non-OS)
  • Knowledge of frameworks: ISO 27001, NIST, CIS
  • Hands-on exposure to tools like Qualys, Tenable, Snyk, or similar
  • Expertise in risk assessment, exception management, and compliance
  • Strong stakeholder engagement and communication skills
  • Familiarity with DevSecOps / SDLC security practices

Qualifications

  • Bachelor’s degree in IT / Cybersecurity or related field

Certifications (Preferred)

Core

  • CISSP / CISM / CRISC

GRC & Risk

  • ISO 27001 Lead Implementer / Auditor
  • FAIR Certification

Optional (Good to Have)

  • CCSP (Cloud Security)
  • CEH / GIAC (Security testing awareness)
  • ITIL / Agile certifications

 



Skills Required

  • Strong background in GRC, cyber risk, and vulnerability management
  • Experience with application and platform vulnerabilities, including non-OS vulnerabilities
  • Knowledge of ISO 27001, NIST, and CIS frameworks
  • Hands-on exposure to Qualys, Tenable, Snyk, or similar tools
  • Expertise in risk assessment, exception management, and compliance
  • Strong stakeholder engagement and communication skills
  • Familiarity with DevSecOps and SDLC security practices
  • Bachelor's degree in IT, Cybersecurity, or a related field
  • CISSP, CISM, or CRISC certification
  • ISO 27001 Lead Implementer or Lead Auditor certification
  • FAIR certification
  • CCSP certification
  • CEH or GIAC certification
  • ITIL or Agile certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
120 Employees
Year Founded: 2016

What We Do

XPT Software Australia Pty Ltd is a technology consulting and software services company serving clients across banking, financial services and insurance, telecommunications, mining, retail, energy, and manufacturing. It provides software development, IT management consulting, business analysis, project and program management, infrastructure support, and offshore development through onsite-offshore delivery. The company also works with cloud computing, big data, mobile applications, UI/UX, algorithms, and IoT.

Similar Jobs

Square Logo Square

Mid-market Account Executive

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Hybrid
Melbourne, Victoria, AUS
12000 Employees

Block Logo Block

Mid-market Account Executive

Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
In-Office
Melbourne, Victoria, AUS
12000 Employees

Ericsson Logo Ericsson

Mission Critical Networks Services Expert

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
5 Locations
88000 Employees

Ericsson Logo Ericsson

Head of EHS MOAI

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office or Remote
9 Locations
88000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account