Leads governance and maturity for non-OS vulnerability management across application and platform environments. Responsibilities include defining policies and standards, managing exceptions and risk acceptance, assessing residual risk, developing treatment strategies, overseeing tooling and automation, integrating security into the SDLC, and reporting risk insights to leadership. The role collaborates across cyber, application, infrastructure, and operations teams while ensuring alignment with regulatory, audit, and enterprise security requirements.
Role Summary
We are seeking an
experienced GRC Consultant – Cyber Lead to drive governance and maturity
of non-OS vulnerability management across enterprise application and
platform environments.
This role focuses on cyber
risk oversight, exception management, and vulnerability treatment strategy,
ensuring risks are effectively assessed, governed, and aligned with enterprise
security standards—while remediation execution remains with delivery teams.
Key Responsibilities
Governance & Risk Oversight
- Define and implement non-OS vulnerability management frameworks,
policies, and standards
- Establish governance forums, escalation paths, and
decision-making processes
- Ensure compliance with regulatory, audit, and enterprise
security requirements
Exception & Treatment Management
- Manage remediation exceptions and risk acceptance lifecycle
- Validate compensating controls and residual risks
- Drive risk-based treatment plans with application and
platform teams
Cyber Risk Management
- Perform risk assessments for vulnerabilities that cannot be
remediated
- Enable risk-based decision-making aligned to business risk
appetite
- Ensure proper documentation, tracking, and periodic review of
accepted risks
Tooling & Capability Uplift
- Lead tooling strategy, evaluation, and automation initiatives
- Improve vulnerability management maturity and processes
- Support training and adoption across delivery teams
Security Improvement & SDLC Integration
- Oversee remediation outcomes from pen tests, audits, and
assessments
- Promote secure-by-design and DevSecOps practices
- Ensure vulnerabilities are identified and treated before
production release
Stakeholder Management
- Collaborate with Cyber, Application, Infrastructure, and
Operations teams
- Provide risk insights to senior leadership and governance forums
- Influence prioritization based on risk severity and business
impact
Required Skills & Experience
- Strong background in GRC, cyber risk, and vulnerability
management
- Experience with application/platform vulnerabilities (non-OS)
- Knowledge of frameworks: ISO 27001, NIST, CIS
- Hands-on exposure to tools like Qualys, Tenable, Snyk, or
similar
- Expertise in risk assessment, exception management, and
compliance
- Strong stakeholder engagement and communication skills
- Familiarity with DevSecOps / SDLC security practices
Qualifications
- Bachelor’s degree in IT / Cybersecurity or related field
Certifications (Preferred)
Core
- CISSP / CISM / CRISC
GRC & Risk
- ISO 27001 Lead Implementer / Auditor
- FAIR Certification
Optional (Good to Have)
- CCSP (Cloud Security)
- CEH / GIAC (Security testing awareness)
- ITIL / Agile certifications
Similar Jobs
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Own the full outbound sales cycle for mid-market merchants, including prospecting, pipeline development, discovery, demos, negotiation, and closing. Build tailored multi-product solutions, acquire net-new business, manage complex multi-stakeholder deals, forecast accurately in Salesforce, and consistently exceed revenue targets. Collaborate with business development, product, marketing, implementation, and operations teams while serving as a trusted consultative advisor.
Top Skills:
Salesforce
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Lead sales enablement and end-to-end professional services for Mission Critical Networks (MCN). Act as single point of contact for commercial submissions, align integration and division of responsibility with SIs and partners, manage CoE systems and PoCs, develop E2E portfolio readiness, support CFRs on scope, timelines, and approvals, and provide early visibility of customer and SI requirements to inform roadmap and readiness.
Top Skills:
5GAutomationLteMission Critical Networks (Mcn)
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Lead regional EHS for Network Operations across MOAI: set strategy, prevent serious injuries, govern psychosocial risks, manage workers' compensation, ensure environmental compliance, strengthen contractor governance, and develop a specialist team while influencing senior stakeholders and embedding EHS into commercial decisions.
What you need to know about the Melbourne Tech Scene
Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.


