
Cybersecurity GRC Consultant
- Melbourne, VIC
- $100,000-115,000 per year
- Permanent
- Full-time
- Conduct cybersecurity risk assessments aligned to ISO 27001, NIST CSF, Essential Eight and related frameworks
- Perform gap assessments and control maturity reviews for regulatory, compliance, and best-practice purposes
- Support the development and implementation of Information Security Management Systems (ISMS)
- Create board and executive-level reporting to communicate cyber risks and prioritise remediation
- Facilitate workshops and lead conversations with stakeholders across technical and business functions
- Work closely with internal experts in SOC, red teaming, and DFIR to ground recommendations in operational realities
- Build lasting relationships with clients and support them throughout their cyber maturity journey
- 2–4 years of experience in cybersecurity GRC, ideally across multiple sectors or clients
- Practical knowledge of ISO 27001, NIST CSF, and Essential Eight
- Experience conducting risk assessments and drafting core security documentation (e.g., risk registers, policies, reports)
- Strong communication and engagement skills with business and technical audiences
- A proactive, consultative approach to understanding and validating control environments
- Technical awareness of security operations and engineering concepts
- Willingness to learn, take initiative, and own deliverables in a collaborative team setting
- ISO 27001 Lead Implementor or Auditor
- One or more of the following: CISSP, CISM, CISA (or working towards)
- SABSA or CRISC
- ITIL Foundations
- Additional governance or cloud-related security certifications
- Excellent written and verbal communication
- Strong attention to detail and structured thinking
- Ability to balance autonomy with teamwork in a fast-paced environment
- A genuine interest in helping organisations improve their security maturity
- Client-first mindset with professional integrity
- Timely, high-quality delivery of client engagements
- Positive stakeholder feedback and repeat client engagements
- Development and contribution to internal documentation and toolkits
- 75–80% billable utilisation
- Active engagement in professional development
- Hybrid Flexibility: Work two days per week from our Melbourne CBD office, and remotely the rest of the week (subject to client needs)
- Varied Client Engagements: Collaborate with organisations of all sizes, across industries and maturity levels
- Career Development: Access ongoing mentorship, structured training pathways, and certification support
- Real-World Cybersecurity Exposure: Collaborate with our internal red team, SOC, and incident response units to deepen your practical understanding
- People & Culture: Participate in team events, offsites, and connection initiatives run by our dedicated People & Culture team