Senior GRC / Security Consultant

3Columns

Sydney

On-site

AUD 150,000 - 210,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

3Columns is seeking a Senior GRC/Cybersecurity Consultant to join our team in Sydney. The role focuses on delivering outcome-based engagements, improving Governance, Risk & Compliance capabilities, and leading projects from initiation through delivery.

You will become a trusted partner and help clients align cybersecurity with business objectives. The successful candidate will drive cyber risk initiatives, mentor teams, and contribute to customer success across diverse industries, using ISO/IEC

Qualifications

  • Proven track record in Information Security, IT Audit, Risk or Compliance.
  • Strong organisational skills and ability to manage multiple projects.
  • Experience in client-facing roles with executive audiences.
  • Ability to translate IT risks into business risk for C-Level and Board.

Responsibilities

  • Lead engagements and deliver outcome-based cybersecurity programs.
  • Develop and implement risk mitigation strategies for clients.
  • Build strong relationships and act as trusted security advisor.
  • Develop training materials and present to clients or at events.
  • Proactively research emerging security risks and controls.

Skills

ISO27001/NIST/ASD8 Audits
Cybersecurity frameworks
Risk assessment
Third-Party assessments
Business risk translation
Training & speaking
Governance & compliance
Client relationship building

Education

ISO27001 Lead Auditor/Lead Implementer
CISSP
CISA
CISM
CDPSE
PCI DSS QSA

Job description

3Columns is a specialist cybersecurity firm delivering a wide range of services, including Security Assurance, Security Governance, Professional Services, and Managed Services. We offer Managed Security Services, Offensive Security Services, Cyber Security Consulting, and professional services to help customers deploythe required controls. The SOC provides Managed Detection & Response and Incident Response.

About the Role:

3Columns is seeking a Senior GRC/ Cybersecurity Consultant to join the team. They will be responsible for delivering outcome-based engagements for a variety of clients and proactively improving Governance, Risk & Compliance capabilities within the organisations they engage with. The Senior Security Consultant will lead small to large projects, helping clients develop and implement cybersecurity risk mitigation strategies to support the business and drive the success of organisationalstrategies. The successful applicant will become an integral part of each client's cybersecurity strategy, developing strong relationships and becoming a trusted partner within each organisation.

Skills and Experience
  • Strong experience with ISO27001, NIST and ASD8Audits and policy documentation
  • Ability to apply and audit cybersecurity frameworks such as ISO/IEC 27001,31000, ASD8 and NIST.
  • Ability to take organisations on their cybersecurity journey
  • Good understanding of GDPR and PCI-DSS, ISM, RFFR, SOC 2
  • Experience in conducting Third-Party assessments.
  • Ability to develop and utilise the company’s methodologies to provide effective cybersecurity and risk advice.
  • Ability to articulate business implications and accurately calculate risks of findings in relation to the business.
  • Ability to develop and deliver training and/or speaking material for public and/or private events.
  • Proactively researching emerging security risks and controls.
Business Skills
  • Excellent written and verbal skills to clearly explain concepts in non-technical terms.
  • Consulting Skillswith a wide range of audiences
  • Strong communication and writing skills.
  • Ability to translate IT and technical risks into business risk for the C-Level and Board.
  • Strong understanding of commercial arrangements for small to large projects and able to demonstrate the value of service offerings to clients.
  • Identifying and articulating security advice aimed at employees, managers and executives.
Personal Skills
  • Must be forward-thinking in terms of vision for the business and team culture.
  • Must have experience in working with consulting companies and with multiple customers and projects at the same time.
  • Come up with innovative ideas to deliver services to the customer
  • Ability to speak about security and recommend security controls to experienced security professionals and executives confidently and accurately.
  • The ability to work as part of the team.
  • Flexibility and motivation to work across various types of engagements.
  • The ability to multitask and service multiple clients at once.
  • Is detail-oriented, self-motivated and can work independently.
Certifications

You will a proven track record in an Information Security, IT Audit, Risk or Compliance field. You will also be a strategic and innovative thinker with strong organisational skills and an understanding of a range of industries and sectors. Candidates will hold or be studying towards one or some of the following certifications or equivalent:

  • ISO 27001 Lead Auditor or Lead Implementer.
  • CISSP ( Desirable, not mandatory)
  • CISA
  • CISM ( Desirable, not mandatory)
  • CDPSE ( Desirable, not mandatory)
  • Associate PCI DSS QSA ( Desirable , not mandatory)
Past Experience
  • Previous or current experience working in a client-facing role is highly regarded.
  • Understanding ofthe PCI-DSS framework.
  • Experience working with, presenting to, and liaising with C-level and board members

Please note: We will not consider offshore candidates or anyone with less than 7 years of experience in the GRC consulting space.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC & Cybersecurity Consultant Lead Risk & Compliance
Senior GRC & Cybersecurity Consultant Lead Risk & Compliance

3Columns • Sydney

On-site
AUD 150,000 - 210,000
Cyber Security Consultant (GRC)
Cyber Security Consultant (GRC)

Anitech Pty Ltd • City of Melbourne

Hybrid
AUD 120,000 - 160,000
Cyber Security - GRC Consultant
Cyber Security - GRC Consultant

Infosys Consulting • Sydney

On-site
AUD 120,000 - 180,000
Senior Security Consultant
Senior Security Consultant

CSO Group • Sydney

On-site
AUD 120,000 - 180,000
Cyber Security Consultant - GRC
Cyber Security Consultant - GRC

Teamified • Canberra

On-site
AUD 70,000 - 110,000
Cyber Security Consultant - GRC
Cyber Security Consultant - GRC

Teamified • City of Melbourne

On-site
AUD 90,000 - 130,000
CyberCX - Senior Consultant - GRC
CyberCX - Senior Consultant - GRC

Accenture • Canberra

On-site
AUD 110,000 - 150,000
GRC Consultant - Cyber Lead
GRC Consultant - Cyber Lead

XPT Software Australia Pty Ltd • City of Melbourne

On-site
AUD 150,000 - 210,000
Senior Cyber GRC Specialist
Senior Cyber GRC Specialist

Emmbr • City of Melbourne

Hybrid
AUD 140,000 - 210,000
Cyber Security GRC Analyst
Cyber Security GRC Analyst

FourQuarters Recruitment • City of Melbourne

On-site
AUD 148,000 - 203,000