Consultant – Cyber Risk Consulting

Jobtailor

Sydney

On-site

AUD 90,000 - 130,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor is seeking a cyber risk consultant to join our Sydney team. You will support engagements including risk assessments, maturity reviews, control reviews, incident response readiness, and tabletop exercises.

You will evaluate security controls, collaborate with clients, and help develop governance, policies, and resilience roadmaps while communicating complex concepts to non-technical audiences. Visa/work rights in Australia required; certifications such as CISM/CISSP encouraged; 2–4

Qualifications

  • 2–4 years of experience in cyber security or related consulting.
  • Experience in risk assessments, security reviews, incident response planning, and/or cyber resilience work.
  • Sound understanding of cyber security concepts, frameworks, and control domains, including governance, vulnerability management, identity and access management, cloud security, and third-party risk
  • Professional certifications such as CISM, CISSP, CRISC, or equivalent
  • Ability to manage competing priorities, work well in a team, and operate effectively in a client-facing environment
  • Commercial awareness and interest in developing advisory and consulting skills
  • Appropriate approval to work in Australia
  • Successful completion of a Criminal & Bankruptcy check prior to commencing employment

Responsibilities

  • Support delivery of cyber risk consulting engagements, including cyber risk assessments, maturity reviews, control reviews, incident response readiness, and tabletop exercises
  • Assess cyber security risks, vulnerabilities, impacts, and control gaps across people, process, technology, and third-party environments
  • Assist in preparing incident response plans, playbooks, and board- or executive-level workshop materials
  • Contribute to client advisory work on cyber governance, policies, security frameworks, and resilience uplift roadmaps
  • Review and analyse security controls against ISO 27001, NIST, CPS 234, and ASD Essential Eight
  • Support evaluation of security technologies, vendors, and implementation approaches
  • Help quantify cyber risk and communicate findings to support decision-making and investment prioritisation
  • Build client and internal relationships
  • Support business development activities and contribute to proposals, thought leadership, and marketing initiatives
  • Work collaboratively with senior team members and provide guidance to junior colleagues where appropriate

Skills

Cyber Security
Risk Assessment
Control Review
Vulnerability Management
Identity And Access Management
Cloud Security
Third-Party Risk
Security Frameworks
Analytical Skills
Problem-Solving

Tools

CISM
CISSP
CRISC
CISA

Job description


  • Support delivery of cyber risk consulting engagements, including cyber risk assessments, maturity reviews, control reviews, incident response readiness, and tabletop exercises

  • Assess cyber security risks, vulnerabilities, impacts, and control gaps across people, process, technology, and third-party environments

  • Assist in preparing incident response plans, playbooks, and board- or executive-level workshop materials

  • Contribute to client advisory work on cyber governance, policies, security frameworks, and resilience uplift roadmaps

  • Review and analyse security controls against ISO 27001, NIST, CPS 234, and ASD Essential Eight

  • Support evaluation of security technologies, vendors, and implementation approaches

  • Help quantify cyber risk and communicate findings to support decision-making and investment prioritisation

  • Build client and internal relationships

  • Support business development activities and contribute to proposals, thought leadership, and marketing initiatives

  • Work collaboratively with senior team members and provide guidance to junior colleagues where appropriate


Requirements


  • 2–4 years of experience in cyber security, cyber risk, technology risk, or a related consulting role

  • Experience in risk assessments, security reviews, incident response planning, and/or cyber resilience work

  • Sound understanding of cyber security concepts, frameworks, and control domains, including governance, vulnerability management, identity and access management, cloud security, and third-party risk

  • Strong written and verbal communication skills, including ability to explain technical matters to non-technical audiences

  • Strong analytical, problem-solving, and stakeholder management skills

  • Knowledge of and experience working with ISO 27001, NIST, CPS 234, and ASD Essential Eight

  • Professional certifications such as CISM, CISSP, CRISC, CISA, or equivalent

  • Ability to manage competing priorities, work well in a team, and operate effectively in a client-facing environment

  • Commercial awareness and interest in developing advisory and consulting skills

  • Appropriate approval to work in Australia

  • Successful completion of a Criminal & Bankruptcy check prior to commencing employment


Core Competencies

Demonstrates expertise in cyber risk assessments, incident response planning, and security frameworks, with a strong ability to communicate complex technical concepts to diverse audiences. Proven experience in managing client relationships and contributing to business development in a consulting environment.


Highest-signal resume keywords


  • Cyber Risk Assessment

  • Incident Response Planning

  • ISO 27001

  • NIST

  • CISM


Hard Skills


  • Cyber Security

  • Risk Assessment

  • Control Review

  • Vulnerability Management

  • Identity And Access Management

  • Cloud Security

  • Third-Party Risk

  • Security Frameworks

  • Analytical Skills

  • Problem-Solving


Soft Skills


  • Written Communication

  • Verbal Communication

  • Stakeholder Management
  • Team Collaboration

  • Client-Facing Skills


Certifications & Qualifications


  • CISM

  • CISSP

  • CRISC

  • CISA


Industry Keywords


  • Cyber Risk

  • Cyber Governance

  • Security Controls

  • Incident Response Readiness

  • Resilience Uplift Roadmaps

  • ASD Essential Eight

  • CPS 234

  • Commercial Awareness

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Consultant
Senior Security Consultant

CSO Group • Sydney

On-site
AUD 120,000 - 180,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Jobtailor • Sydney

On-site
AUD 110,000 - 150,000
Cyber Risk Specialist
Cyber Risk Specialist

Talent International • Sydney

Hybrid
AUD 90,000 - 130,000
Lead Cyber Analysts
Lead Cyber Analysts

Clicks IT Recruitment • City of Brisbane

On-site
AUD 120,000 - 170,000
Senior Consultant - Cyber Security Strategy & Data Privacy
Senior Consultant - Cyber Security Strategy & Data Privacy

CyberCX • Adelaide

On-site
AUD 120,000 - 180,000
Generous leave benefits
Health, wellbeing and lifestyle perks
Career development and recognition
Senior Consultant - Cyber Security Strategy & Data Privacy
Senior Consultant - Cyber Security Strategy & Data Privacy

CyberCX • City of Melbourne

On-site
AUD 120,000 - 180,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Data#3 • Sydney

Hybrid
AUD 120,000 - 180,000
Senior Consultant - Cyber Security Strategy & Data Privacy
Senior Consultant - Cyber Security Strategy & Data Privacy

CyberCX • City of Brisbane

On-site
AUD 120,000 - 190,000
Generous leave benefits
Health & wellbeing benefits
Career development
+1
Cyber GRC Analyst
Cyber GRC Analyst

Client 1 • City of Brisbane

On-site
AUD 110,000 - 160,000
Private health insurance
Generous annual leave entitlements
Annual incentive programme
+5
Cyber Governance Risk and Compliance Specialist
Cyber Governance Risk and Compliance Specialist

RGIT Australia • Sydney

On-site
AUD 130,000 - 170,000