GRC Consultant

Cleared Recruitment

Canberra

On-site

AUD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Cleared Recruitment in Canberra is seeking an experienced Governance, Risk and Compliance (GRC) professional to join a Defence-focused cyber security team. You will help ensure Defence systems meet ISM/PSPF standards and accreditation requirements throughout the lifecycle.

As a GRC Consultant, you will assess cyber risk, guidance on governance obligations, and support accreditation activities while collaborating with security authorities and technical stakeholders in a highly secure environment.

Qualifications

  • Experience in governance, risk and compliance within secure or regulated environments.
  • Strong knowledge of PSPF, ISM and Defence security standards.
  • Experience producing security governance documentation (SSP, SRMP, IRP).
  • Exposure to accreditation or Authority to Operate (ATO) in Defence or Government.
  • Familiarity with IRAP or similar assurance frameworks.
  • Experience with cloud environments (AWS) and traditional enterprise infra.
  • Ability to operate across different classification levels with stakeholders.
  • Minimum two years in cyber security or GRC; higher levels available.

Responsibilities

  • Build and maintain relationships with Defence representatives, project teams and security partners.
  • Provide governance guidance on control implementation and risk treatment.
  • Lead activities related to system accreditation and authorisation processes.
  • Prepare and maintain security assessment documentation for ISM and IS standards.
  • Evaluate system compliance against Defence frameworks and ISM controls.
  • Conduct cyber risk assessments and present findings and treatment plans.
  • Collaborate with security, engineering and operations to embed security requirements.
  • Identify security dependencies and compliance obligations early in delivery lifecycles.
  • Monitor remediation actions and assure closure of findings.
  • Contribute to continuous governance and risk management improvements.

Skills

GRC experience
PSPF/ISM knowledge
ATO processes
IRAP familiarity
Cloud/AWS experience
Stakeholder engagement
Communication skills
Defence sector experience
Analytical thinking

Job description

Clearance Required
Active TSPV Security Clearance and willing to obtain DISA/OSA.

Company Overview

We are seeking experienced Governance, Risk and Compliance (GRC) professionals to join a Defence-focused cyber security team supporting nationally significant capabilities. These roles play an important part in strengthening security governance, managing cyber risk and supporting accreditation activities across a highly secure and complex operational environment.

Job Description

As a GRC Consultant, you will contribute to the delivery of cyber security governance outcomes within a major Defence program. Working closely with technical teams, project stakeholders and security authorities, you will be responsible for ensuring systems comply with Defence security standards and authorisation requirements.

The role involves providing governance guidance, assessing cyber security risks, supporting accreditation processes and maintaining key security artefacts throughout the lifecycle of Defence systems. You will be expected to operate autonomously while collaborating with a broad range of internal and external stakeholders.

Duties and Responsibilities

  • Build and maintain strong relationships with Defence representatives, project teams, business stakeholders and cyber security partners.
  • Provide guidance on security governance obligations, control implementation and risk treatment strategies.
  • Lead and coordinate activities associated with system accreditation and authorisation processes.
  • Prepare, review and maintain documentation required to support security assessment and authorisation activities.
  • Evaluate system compliance against Defence security frameworks, the Information Security Manual (ISM) and Essential Eight controls.
  • Conduct cyber risk assessments and present findings, recommendations and treatment plans to stakeholders.
  • Work collaboratively with cyber security, engineering and operations teams to ensure security requirements are embedded throughout delivery and sustainment activities.
  • Support project teams by identifying security dependencies, risks and compliance obligations early in the delivery lifecycle.
  • Monitor remediation activities and provide assurance that identified security issues are appropriately addressed.
  • Contribute to continuous improvement initiatives that enhance governance and risk management processes.

Knowledge / Skills Required

  • Demonstrated experience working within governance, risk and compliance functions in secure or regulated environments.
  • Strong understanding of the Protective Security Policy Framework (PSPF), Information Security Manual (ISM) and Defence security standards.
  • Experience producing and maintaining key security governance documentation, including System Security Plans, Security Risk Management Plans and Incident Response Plans.
  • Exposure to system accreditation, certification or Authority to Operate (ATO) processes within Defence, Government or Intelligence environments.
  • Familiarity with security assessment methodologies such as IRAP or comparable assurance frameworks.
  • Experience working within cloud-hosted environments, ideally AWS, as well as traditional enterprise infrastructure.
  • Understanding of security requirements across systems operating at different classification levels.
  • Strong analytical and risk assessment capabilities, with the ability to identify, articulate and manage security risks.
  • Excellent communication and stakeholder engagement skills, including the ability to influence technical and non-technical audiences.
  • A minimum of two years' relevant cyber security or GRC experience. More senior opportunities are available for candidates with extensive industry experience.
  • Opportunity to support a mission-critical Defence capability.
  • Multiple positions available across varying levels of experience.
  • Work within a highly skilled cyber security and governance team supporting Defence capabilities.
  • Opportunity to contribute to complex and nationally significant security outcomes.

Diversity and Inclusion
We value diversity and are committed to creating an inclusive environment for all employees.

Veterans
Defence and Federal Government industry experience is highly desirable. We strongly encourage veterans and individuals with Defence experience to apply. Your unique skills and background are highly valued, and we are committed to supporting your transition into this role.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC (Governance, Risk and Compliance) Lead
GRC (Governance, Risk and Compliance) Lead

Client 1 • Canberra

On-site
AUD 150,000 - 210,000
Defence projects
Secure environments
Career growth
+2
GRC Specialist
GRC Specialist

Cleared Recruitment • Canberra

On-site
AUD 110,000 - 150,000
14% superannuation
6 weeks annual leave
Mentoring and development
+2
GRC Specialist
GRC Specialist

Client 1 • Canberra

On-site
AUD 110,000 - 150,000
14% superannuation
6 weeks annual leave
Professional development
+2
Defence GRC Consultant — Clearance Required
Defence GRC Consultant — Clearance Required

Cleared Recruitment • Canberra

On-site
AUD 120,000 - 170,000
Cyber GRC Analyst
Cyber GRC Analyst

Client 1 • City of Brisbane

On-site
AUD 110,000 - 160,000
Private health insurance
Generous annual leave entitlements
Annual incentive programme
+5
Senior GRC Cyber Consultant – Defence ICT (TSPV)
Senior GRC Cyber Consultant – Defence ICT (TSPV)

Leidos • Canberra

On-site
AUD 150,000 - 210,000
Flex Your Way
Wellbeing program
Learning & development
Defence Cyber Security GRC Specialist
Defence Cyber Security GRC Specialist

C4I Solutions Pty • Sydney

Hybrid
AUD 140,000 - 190,000
GRC Analyst - 5 months
GRC Analyst - 5 months

Leidos Australia • Canberra

On-site
AUD 110,000 - 140,000
Cyber Security GRC
Cyber Security GRC

C4I Solutions Pty • Sydney

On-site
AUD 140,000 - 190,000
Cyber GRC Manager (PSTV Cleared)
Cyber GRC Manager (PSTV Cleared)

Sirius. • Canberra

On-site
AUD 120,000 - 160,000