The Role
Lead cybersecurity risk assessments across customer projects, identify and communicate security gaps, advise executive stakeholders, improve risk processes and reusable documentation, contribute to security strategies and standards, manage complex initiatives, engage vendors, and mentor risk assessors. The role requires extensive cybersecurity and GRC experience, technical risk assessment expertise, and familiarity with ISO, PCI, NIST, and Essential Eight frameworks.
Summary Generated by Built In
Urgent
requirement of Lead Risk Assessor - Contract - Australia
Requirements
Key Accountabilities
Include:
- Leading cybersecurity risk assessments across customer projects
- Collaborating with project teams to identify and address security gaps
- Communicating complex technical issues in clear business terms, including to executive
stakeholders, such as through the risk decisioning process.
- Making informed decisions and managing stakeholder expectations
- Leading the uplift of team processes, documentation, and engagement models
Additional information:
- Actively collaborate with business stakeholders, engineers, delivery teams, product vendors
and partners, as well as other Cyber Assurance stakeholders, to adequately understand and
convey the cyber risk of a delivered product or solution
- Define and document re-usable assets such as standardised findings and process
improvements to drive improved capability within the function
- Input into the creation and governance of security strategy, standards and frameworks to ensure
a coherent and optimised overall security policy within the customer.
- Identify and eƯectively communicate security risks to business stakeholders in a timely manner
- harvesting and harmonising insights from all relevant areas including privacy, legal, engineering
and operational stakeholders.
- Foster strategic relationships across industry and technology vendors to anticipate and plan for
emerging opportunities and threats to inform risk assessment.
- Mentor and be a role model for new and existing Risk Assessors and candidates on secondment, including shadowing, process guidance and providing feedback.
- Handle complex initiatives while simplifying them to support eƯective execution.
Essential:
- Minimum 15+ years of experience within Cybersecurity, with at least 8+ years of experience in GRC ot risk function.
- Practical experience in technical risk assessment.
- Familiarity with standards like ISO, PCI, NIST, and E8
- A collaborative mindset and ability to translate complex technical risks into clear, actionable business insights
- Experience working in large, complex environments
Highly Desirable:
- Prior experience within a non-cyber-related risk or GRC role.
- Industry certifications such as CRISC, CISSP, CISM or SABSA
- Experience in Agile and DevOps
Duration: 06 Months and
possible extension
Eligibility: Australian/NZ
Citizens/PR Holders only
Email: [email protected]
Skills Required
- 15+ years of experience in cybersecurity
- 8+ years of experience in governance, risk, and compliance or cybersecurity risk
- Practical experience conducting technical risk assessments
- Familiarity with ISO, PCI, NIST, and Essential Eight standards
- Ability to translate complex technical risks into clear business insights
- Experience working in large, complex environments
- Prior experience in non-cybersecurity risk or GRC
- CRISC, CISSP, CISM, or SABSA certification
- Experience with Agile and DevOps
- Australian or New Zealand citizenship or Australian permanent residency
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Hastha Solutions is an SAP solutions and enterprise technology company serving government and private organizations. It specializes in SAP Enterprise Asset Management (EAM), enterprise mobility, GIS integration, enterprise document management, digitization, cloud transformation, and consumer-application integration. The company uses an analytical, vendor-agnostic approach to design and deliver tailored, cost-effective solutions that connect enterprise systems with community and consumer needs for clients.








