Cyber GRC Manager

Whizdom

Canberra

On-site

AUD 162,000 - 198,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Whizdom in Canberra seeks a Cyber GRC Manager to lead authorisation activities under Australian frameworks including the ISM, PSPF and Essential 8. The role embeds governance, risk, and regulatory compliance across information systems, guiding the implementation, monitoring, and improvement of security controls to meet government standards.

You will collaborate with the cyber security team, provide SME guidance on greenfield projects and legacy modernization, conduct risk assessments, develop

Qualifications

  • Minimum 7 years working as a Cyber Security or GRC Analyst.
  • Knowledge of PSPF, ISM, Essential 8, NIST.
  • Ability to identify risks and propose risk reduction strategies.
  • Experience in enterprise security environments.
  • Desirable: ISO27000 series, NIST 800 series, CIS.

Responsibilities

  • Lead the development, submission and maintenance of security authorisation documentation (e.g., System Security Plans, Security Risk Management Plans, Cyber Incident Response Plans).
  • Lead the implementation of security standards ISM, Essential 8, NIST.
  • Provide cyber security advice to monitor infrastructure, designs and upgrades.
  • Advise on cyber security for greenfield projects and legacy modernisation.
  • Lead cyber risk assessments to identify threats and vulnerabilities.
  • Develop comprehensive security policies to address risks.
  • Support DCISO and CISO and briefing Executives on security priorities.

Skills

GRC experience
Security frameworks (PSPF/ISM/NIST)
Stakeholder communication
Enterprise security
NV2 clearance

Job description

Seeking a Cyber GRC Manager knowledge of PSPF, ISM, Essential 8, NIST.

The Cyber GRC Manager leads the organisations information system authorisation activities through embedding governance, risk, and regulatory compliance practices that are aligned to Australian Government frameworks – particularly the Information Security Manual (ISM), Protective Security Policy Framework (PSPF), and Essential 8. Working as part of the broader cybersecurity team, this role leads the implementation, monitoring, and continuous improvement of security controls to ensure compliance, maturity uplift, and informed risk management is in line with organisational objectives and Government standards.

Responsibility
  • Lead the development, delivery, submission and maintenance of security authorisation documentation (e.g., System Security Plans, Security Risk Management Plans, and Cyber Incident Response Plans) to support Government processes.
  • Lead the implementation of security standards, ISM, Essential 8, NIST, etc
  • Provide cyber security advice that assists with the monitoring of infrastructure components, the design of infrastructure, identify areas for improvements and assist with the implementation of upgrades, or enhancements as required.
  • Provide SME advice into cyber security measures for greenfield projects and the modernisation of legacy systems and enterprise applications.
  • Lead cyber security risk assessments to identify and evaluate potential threats and vulnerabilities.
  • Develop comprehensive security policies to address and mitigate risks.
  • Support the DCISO and CISO to achieve technical objectives and assist them in briefing the Executive on security matters and priorities.
Skills / Abilities
  • Minimum 7 years working as a Cyber Security or GRC Analyst.
  • Knowledge of security standards and frameworks such as PSPF, ISM, Essential 8, NIST.
  • Ability to identify risks, provide risk reduction strategies, and collaborate with business teams to secure stakeholders’ approval and support.
  • Experience working within an enterprise security environment.
  • Previously worked in heavily regulated environments such as federal government, telco, energy, etc.
  • Excellent communication skills and ability to communicate with stakeholders varying in seniority and technical understanding.
  • Desirable: ISO27000 series, NIST 800 series, CIS.

Permanent role - $180k + Super

Security Required: NV2 Security Clearance required

Location - Canberra

Closing date: Thursday 27 August by 9am

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber GRC Analyst
Cyber GRC Analyst

Whizdom • Canberra

On-site
AUD 139,000 - 191,000
GRC Manager
GRC Manager

Client 1 • Canberra

On-site
AUD 140,000 - 180,000
14% superannuation
6 weeks paid annual leave
Hands-on leadership role
+3
Cyber GRC Lead - ISM/PSPF/Essential 8/NIST
Cyber GRC Lead - ISM/PSPF/Essential 8/NIST

Whizdom • Canberra

On-site
AUD 162,000 - 198,000
Cyber Security GRC Analyst
Cyber Security GRC Analyst

Interpro • Canberra

On-site
AUD 120,000 - 180,000
Cyber GRC Analyst - ISM/NIST, PSPF, Canberra
Cyber GRC Analyst - ISM/NIST, PSPF, Canberra

Whizdom • Canberra

On-site
AUD 139,000 - 191,000
Cyber GRC Manager
Cyber GRC Manager

HorizonOne Recruitment • Canberra

On-site
AUD 140,000 - 200,000
Six weeks paid annual leave
Superannuation 14.0%
Free onsite car parking
+2
Senior Cyber Security Governance Analyst
Senior Cyber Security Governance Analyst

eSync Solutions • Canberra

On-site
AUD 90,000 - 130,000
GRC Manager
GRC Manager

Cleared Recruitment • Canberra

On-site
AUD 140,000 - 190,000
Competitive salary
Senior Cyber Security GRC & Governance Analyst
Senior Cyber Security GRC & Governance Analyst

IT Alliance Australia • Canberra

On-site
AUD 120,000 - 180,000
Cyber GRC Manager (PSTV Cleared)
Cyber GRC Manager (PSTV Cleared)

Sirius. • Canberra

On-site
AUD 120,000 - 160,000