XPT Software Australia Pty Ltd Logo

XPT Software Australia Pty Ltd

GRC Consultant - Cyber Lead

Posted 21 Days Ago
Be an Early Applicant
In-Office
Melbourne, Victoria, AUS
Entry level
In-Office
Melbourne, Victoria, AUS
Entry level
Leads governance and maturity for non-OS vulnerability management across application and platform environments. Responsibilities include defining policies and standards, managing exceptions and risk acceptance, assessing residual risk, developing treatment strategies, overseeing tooling and automation, integrating security into the SDLC, and reporting risk insights to leadership. The role collaborates across cyber, application, infrastructure, and operations teams while ensuring alignment with regulatory, audit, and enterprise security requirements.
The summary above was generated by AI

Role Summary

We are seeking an experienced GRC Consultant – Cyber Lead to drive governance and maturity of non-OS vulnerability management across enterprise application and platform environments.

This role focuses on cyber risk oversight, exception management, and vulnerability treatment strategy, ensuring risks are effectively assessed, governed, and aligned with enterprise security standards—while remediation execution remains with delivery teams.


Key Responsibilities

Governance & Risk Oversight

  • Define and implement non-OS vulnerability management frameworks, policies, and standards
  • Establish governance forums, escalation paths, and decision-making processes
  • Ensure compliance with regulatory, audit, and enterprise security requirements

Exception & Treatment Management

  • Manage remediation exceptions and risk acceptance lifecycle
  • Validate compensating controls and residual risks
  • Drive risk-based treatment plans with application and platform teams

Cyber Risk Management

  • Perform risk assessments for vulnerabilities that cannot be remediated
  • Enable risk-based decision-making aligned to business risk appetite
  • Ensure proper documentation, tracking, and periodic review of accepted risks

Tooling & Capability Uplift

  • Lead tooling strategy, evaluation, and automation initiatives
  • Improve vulnerability management maturity and processes
  • Support training and adoption across delivery teams

Security Improvement & SDLC Integration

  • Oversee remediation outcomes from pen tests, audits, and assessments
  • Promote secure-by-design and DevSecOps practices
  • Ensure vulnerabilities are identified and treated before production release

Stakeholder Management

  • Collaborate with Cyber, Application, Infrastructure, and Operations teams
  • Provide risk insights to senior leadership and governance forums
  • Influence prioritization based on risk severity and business impact

Required Skills & Experience

  • Strong background in GRC, cyber risk, and vulnerability management
  • Experience with application/platform vulnerabilities (non-OS)
  • Knowledge of frameworks: ISO 27001, NIST, CIS
  • Hands-on exposure to tools like Qualys, Tenable, Snyk, or similar
  • Expertise in risk assessment, exception management, and compliance
  • Strong stakeholder engagement and communication skills
  • Familiarity with DevSecOps / SDLC security practices

Qualifications

  • Bachelor’s degree in IT / Cybersecurity or related field

Certifications (Preferred)

Core

  • CISSP / CISM / CRISC

GRC & Risk

  • ISO 27001 Lead Implementer / Auditor
  • FAIR Certification

Optional (Good to Have)

  • CCSP (Cloud Security)
  • CEH / GIAC (Security testing awareness)
  • ITIL / Agile certifications

 



HQ

XPT Software Australia Pty Ltd Melbourne, Victoria, AUS Office

Melbourne, Australia

Similar Jobs

4 Hours Ago
In-Office
Melbourne, Victoria, AUS
Senior level
Senior level
Software
Leads technical presales engagements for New Relic’s observability platform. Partners with account executives to qualify opportunities, conduct discovery workshops, deliver demonstrations and proofs of concept, resolve technical objections, and align solutions to customer business outcomes. Builds executive and stakeholder relationships, supports revenue goals, provides product feedback, and contributes to marketing activities and competitive positioning.
Top Skills: .NetAiopsAWSAzureCC++Ci/CdCloud ArchitectureData AnalyticsData VisualizationDevOpsElkGCPGrafanaInfrastructure As CodeJavaJavaScriptNetworkingNew RelicOpencensusPrometheusPythonReactRubyServerless Computing
Yesterday
In-Office
Melbourne, Victoria, AUS
Expert/Leader
Expert/Leader
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Leads customer-facing security advisory and sales support for Ericsson’s telecom solutions. Responsibilities include advising customers on cybersecurity, privacy, business continuity, risk assessment, governance, data management, product security, ISO 27001 controls, vulnerability assessment, and regulatory requirements. The role serves as the primary security contact, ensures contractual security commitments are addressed, drives internal security projects and gap closure, and coordinates cross-functional cybersecurity stakeholders across pre-sales and post-sales activities.
Top Skills: CybersecurityDistributed CloudIso 27001Network SlicingOpen RanService Based ArchitectureXaas
Yesterday
Hybrid
Melbourne, Victoria, AUS
Entry level
Entry level
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Owns the Customer Service and Logistics digital improvement pipeline, delivering dashboards, automations, analytics, and reporting tools that generate measurable savings and service improvements. Leads the National Distribution Control Tower project, including requirements, solution design, testing, integration, and hypercare. Builds digital capability through training, monitors infrastructure risks, supports Lean Six Sigma initiatives, and maintains safety reporting tools. The role requires collaboration across supply chain functions and accountability for validated digital benefits.
Top Skills: DatabricksPower AutomatePower BIPythonSAP

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account