Role Title
Cyber GRC Specialist
Location
Canberra
Working Arrangement
On-site
Clearance required
Positive Vetting (PV)
Company overview
Our client is seeking a Cyber GRC Specialist to join their Security team in Canberra. Working within a broader cyber security function, this role supports the implementation, monitoring and continuous improvement of governance, risk and compliance activities aligned to Australian Government cyber security frameworks.
Job Description
The Cyber GRC Specialist supports information system authorisation activities by embedding governance, risk and compliance practices aligned to Australian Government frameworks, including the Information Security Manual (ISM), Protective Security Policy Framework (PSPF) and ASD Essential Eight. Working closely with the Cyber GRC Manager, you will contribute to security compliance, risk management, security documentation and continuous cyber security maturity uplift initiatives.
Duties and Responsibilities
- Develop, deliver and maintain security authorisation documentation, including System Security Plans, Security Risk Management Plans and Cyber Incident Response Plans.
- Support Government Accreditation to Operate (ATO) processes.
- Implement and maintain security standards and frameworks including ISM, ASD Essential Eight and NIST.
- Provide cyber security advice to support infrastructure monitoring, design improvements, upgrades and enhancements.
- Conduct cyber security risk assessments to identify and evaluate threats and vulnerabilities.
- Provide subject matter expertise on compliance and regulatory requirements.
- Assist with the development and maintenance of security policies and procedures.
- Collaborate with internal stakeholders to improve cyber security posture and risk management outcomes.
- Support continuous improvement initiatives across governance, risk and compliance functions.
Education/Certifications required
- Relevant cyber security, information technology or related qualifications.
- Desirable certifications or knowledge relating to ISO 27000 series, NIST 800 series or CIS frameworks.
Knowledge/Skills required
- Minimum three years' experience working as a Cyber Security Analyst or GRC Analyst.
- Strong knowledge of PSPF, ISM, ASD Essential Eight and NIST frameworks.
- Experience conducting cyber security risk assessments and developing risk mitigation strategies.
- Ability to engage with stakeholders of varying technical and seniority levels.
- Experience working within enterprise security environments.
- Previous experience within highly regulated industries such as Federal Government, telecommunications, energy or similar sectors.
- Strong written and verbal communication skills.
- Australian Citizenship with the ability to hold and maintain a PV security clearance.
Employment benefits
- 14% superannuation.
- 6 weeks paid annual leave.
- Opportunity to work on significant cyber security and compliance initiatives.
- Exposure to government-aligned security frameworks and accreditation activities.
- Mentoring and professional development opportunities.
- Career growth through continuous learning and development.
- Collaborative environment working alongside cyber security and technology professionals.
Diversity and Inclusion
We value diversity and are committed to creating an inclusive environment for all employees.
Veterans
Defence and Federal Government industry experience is highly desirable. We strongly encourage veterans and individuals with Defence experience to apply. Your unique skills and background are highly valued, and we are committed to supporting your transition into this role.