Cyber Governance, Risk & Compliance Specialist

Onset Group · Brisbane QLD 4000 · Full time
Posted 2d ago

Cyber Governance, Risk & Compliance Specialist

KEY POINTS WE FOUND
  • Join a large-scale managed services environment supporting a major enterprise customer.
  • Develop and maintain information security policies and conduct cyber security risk assessments.
  • Support compliance against Australian Government security standards and coordinate security audits.

Job Description

Cyber Governance, Risk & Compliance Specialist

Location: Brisbane CBD
Contract: 12 months
Rate: Up to $110 per hour including super
Security Clearance: NV1 required

We are seeking an experienced Cyber Governance, Risk & Compliance (GRC) Specialist to join a large-scale managed services environment supporting a major enterprise customer.

This is a hands-on cyber security role spanning governance, risk, compliance and security operations, with a strong focus on Australian Government security standards. You will work closely with technology, engineering and business stakeholders to strengthen security controls, manage cyber risk and support ongoing compliance initiatives.

What you'll be doing

  • Develop and maintain information security policies, standards, procedures and guidelines.
  • Conduct cyber security risk assessments across applications, technology assets and third-party vendors.
  • Identify security risks and coordinate remediation, tracking and reporting.
  • Support compliance against the Australian Government Information Security Manual (ISM) and other relevant security frameworks.
  • Coordinate internal and external security audits, including evidence gathering and remediation activities.
  • Support third-party security risk management, vendor assessments and ongoing monitoring.
  • Assist with the implementation and validation of controls across IAM, encryption, logging, vulnerability management, patching, network security and endpoint protection.
  • Develop security risk and compliance reporting for senior stakeholders.
  • Support security incident response, root-cause analysis and continuous improvement of controls.
  • Partner with technical teams to provide security and compliance guidance for new solutions and integrations.

These responsibilities reflect the governance, risk, audit, third-party risk, control validation and secure-design responsibilities in the supplied brief.

What we're looking for

  • 3+ years' experience across cyber security governance, risk and/or compliance.
  • Strong knowledge of the Australian Government ISM.
  • Experience with security frameworks such as NIST, ISO 27001 or CIS Controls.
  • Understanding of security controls across identity and access management, vulnerability management, secure configuration and cryptography.
  • Exposure to security monitoring and incident response.
  • Familiarity with technologies such as SIEM, IDS/IPS and endpoint security solutions.
  • Strong analytical, documentation and stakeholder communication skills.
  • Ability to work effectively across technical and non-technical teams.
  • Relevant cyber security certifications are advantageous.

The technical requirements above come directly from the role brief, including ISM, NIST, ISO 27001, CIS, SIEM, incident response and endpoint security.

Security clearance

Applicants must be Australian Citizens and hold an NV1 security clearance.

This is a 12-month contract opportunity based in Brisbane CBD, offering exposure to a complex enterprise cyber security environment with a broad mix of governance, risk, compliance and operational security responsibilities.

Rate: Up to $110/hour including super.

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 15 matched
Australian government ismComplianceCyber security governanceSecurity audit coordinationSecurity certifications (e.g., cissp, cism)Security clearance (nv1)Security controls (iam, encryption, logging, vulnerability management, patching, network security, endpoint protection)Security frameworks (nist, iso 27001, cis controls)Security incident responseSecurity monitoring (siem, ids/ips)Security policies and procedures developmentSecurity risk assessmentStakeholder communicationTradingVendor risk management

Onset Group Pty Ltd