GRC CONSULTANT

CyberCX · Canberra ACT 2600 · Full time
Posted 24d ago

GRC CONSULTANT

KEY POINTS WE FOUND
  • Support complex cyber security projects in Governance, Risk and Compliance domain.
  • Assist clients in identifying and managing cyber security risks.
  • Develop and maintain security documentation and support certification processes.

17th August, 2026

About CyberCX

CyberCX is Australia and New Zealand’s leading cyber security services provider, trusted by private and public sector organisations to help manage cyber risk, respond to incidents, and build resilience in an increasingly complex threat landscape.

With a workforce of over 1,400 professionals, CyberCX delivers end-to-end cyber capabilities across consulting and advisory, governance, risk and compliance, incident response, penetration testing, cloud and infrastructure solutions, identity and access management, and managed security services.

About the role

As a GRC Consultant, you’ll have the opportunity to work in Multi-Disciplinary Teams (MDT) that cover our end-to-end services, solving our clients most challenging cyber security problems across diverse technology environments. You’ll help our clients proactively Identify, Protect, Detect, Respond, and Recover from threats.

What You'll Do

  • Support complex, cyber security projects in the Governance, Risk and Compliance domain
  • Work with our customer base to assist them in identifying and effectively managing cyber security risk.
  • Develop, implement and maintain the Security SRMP, SSP’s, SRAs (assist with) documentation, supporting certification and accreditation for the service being delivered.
  • Maintain and improve the system security documentation package.


What You'll Bring

  • Broad knowledge across a range of compliance frameworks (ISO 27001, PCI DSS, NIST, GDPR, etc.)
  • Experience with ISM, Essential Eight, DSPF, or PSPF is highly desirable.
  • Experience working with Defence or the Defence Industry preferred
  • Demonstrated experience in developing security documentation such as Security Risk Management Plans (SRMP), and System Security Plans (SSP).
  • Minimum 12 months of experience dealing with a diverse range of Information Technology & Communications projects or challenges.
  • Experience with the ISM or implementing and/or auditing an ISO 27001 ISMS.  
  • Networks and Systems Administrators who have experience in implementation of complex systems wishing to shift focus to GRC.

Due to the nature of the work, an NV1 clearance is required.

Why CyberCX?

  • Joining CyberCX means being part of a passionate, purpose-driven team working to make Australia and New Zealand the safest places to connect online. You’ll enjoy:
  • Access to industry-leading experts and professional development opportunities.
  • A supportive, flexible, and collaborative workplace culture.
  • Competitive salary and benefits package.

Ready to make an impact?
Apply now and join a team that’s helping shape the future of cyber resilience.

We kindly request no agency submissions for this role.  Unsolicited CV’s will not be accepted, and no fees will be payable.

Apply For Job

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 16 matched
Complex systems implementationCompliance frameworksCyber securityGdprGovernanceIsmIso 27001Iso 27001 ismsNetwork and systems administrationNistPci dssSecurity certification (nv1 clearance)Security documentationSecurity risk management plansSystem security plansTrading

Perks & benefits

0 of 3 matched
Access to industry-leading expertsProfessional development opportunitiesSupportive and flexible workplace culture

CyberCX

More details

Expiring date