The Cyber GRC Manager leads the organisations information system authorisation activities through embedding governance, risk, and regulatory compliance practices that are aligned to Australian Government frameworks – particularly the Information Security Manual (ISM), Protective Security Policy Framework (PSPF), and Essential 8. Working as part of the broader cybersecurity team, this role leads the implementation, monitoring, and continuous improvement of security controls to ensure compliance, maturity uplift, and informed risk management is in line with organisational objectives and Government standards.
Responsibility
- Lead the development, delivery, submission and maintenance of security authorisation documentation (e.g., System Security Plans, Security Risk Management Plans, and Cyber Incident Response Plans) to support Government processes.
- Lead the implementation of security standards, ISM, Essential 8, NIST, etc
- Provide cyber security advice that assists with the monitoring of infrastructure components, the design of infrastructure, identify areas for improvements and assist with the implementation of upgrades, or enhancements as required.
- Provide SME advice into cyber security measures for greenfield projects and the modernisation of legacy systems and enterprise applications.
- Lead cyber security risk assessments to identify and evaluate potential threats and vulnerabilities.
- Develop comprehensive security policies to address and mitigate risks.
- Support the DCISO and CISO to achieve technical objectives and assist them in briefing the Executive on security matters and priorities.
- Minimum 7 years working as a Cyber Security or GRC Analyst.
- Knowledge of security standards and frameworks such as PSPF, ISM, Essential 8, NIST.
- Ability to identify risks, provide risk reduction strategies, and collaborate with business teams to secure stakeholders’ approval and support.
- Experience working within an enterprise security environment.
- Previously worked in heavily regulated environments such as federal government, telco, energy, etc.
- Excellent communication skills and ability to communicate with stakeholders varying in seniority and technical understanding.
- Desirable: ISO27000 series, NIST 800 series, CIS.
Security Required: NV2 Security Clearance required
Location - Canberra
How to Apply - Please upload your resume to apply. Candidates will need to be willing to undergo pre-employment screening checks which may include, ID and work rights, security clearance verification and any other client requested checks
Closing date: Thursday 27 August by 9am
Call Joanne Finchett on 0480 002454 or email Joanne@whizdom.com.au for any further information


