Location: Canberra, ACT
Employment Type: Contract (12 Months)
Extension: 12-Month Extension Available
Work Arrangement: Full-Time Onsite (Temporary WFH may be considered on a case-by-case basis)
Hours: Up to 45 Hours Per Week
Security Clearance: Must hold or be able to obtain Negative Vetting Level 1 (NV1) (Candidates who already hold an active NV1 clearance will be highly regarded.)
About the Opportunity
SkyDB is seeking an experienced Senior Cyber Security GRC Specialist to join a high-performing cyber security team supporting a large-scale Australian Government cyber resilience and security uplift program. This is an exciting opportunity for an experienced Governance, Risk and Compliance (GRC) professional to contribute to the protection of nationally significant ICT systems and critical digital infrastructure.
The successful candidate will play a pivotal role in ensuring cyber security requirements are embedded throughout the solution lifecycle, supporting governance activities, coordinating security assurance engagements, and developing security documentation that enables informed executive decision-making.
In addition to supporting long-term cyber resilience initiatives, the successful candidate will also assist during major operational events where maintaining the integrity, availability and security of critical systems is essential. This role offers the opportunity to work alongside experienced cyber security professionals while influencing enterprise-wide security outcomes across a complex government environment.
About the Role
As the Senior Cyber Security GRC Specialist, you will provide expert advice across Governance, Risk and Compliance activities while working closely with project teams, architects, technical specialists, security practitioners and senior stakeholders.
You will be responsible for ensuring new and existing ICT solutions align with Australian Government cyber security standards and frameworks, while helping deliver secure, compliant and resilient technology outcomes.
You will also support security assurance activities including IRAP assessments, penetration testing, risk management, security documentation and accreditation processes.
The ideal candidate will have strong experience interpreting Australian Government cyber security frameworks and translating security requirements into practical outcomes for technical and business teams.
Key Responsibilities
As part of this role, you will:
- Provide cyber security governance, risk and compliance (GRC) expertise across enterprise ICT projects and operational initiatives.
- Review solution designs and provide recommendations to ensure appropriate cyber security controls are incorporated from the outset.
- Identify security risks and develop practical mitigation strategies that align with organisational policies and Australian Government standards.
- Develop and maintain a broad range of security documentation including:
- Security Risk Assessments
- Security Requirements
- Security Plans
- System Security Documentation
- Executive Briefing Papers
- Governance Reports
- Coordinate and support security assurance activities including:
- IRAP Assessments
- Penetration Testing
- Security Reviews
- Remediation Tracking
- Work closely with technical teams to ensure security recommendations are effectively implemented.
- Prepare clear, concise documentation and reports to support senior executive decision-making.
- Support security accreditation and compliance activities throughout project delivery.
- Engage with internal and external stakeholders to ensure security obligations are understood and achieved.
- Contribute to continuous improvement initiatives across cyber governance, assurance and risk management processes.
- Provide additional cyber security support during critical operational periods and major organisational events.
Key Skills & Experience
The successful candidate will possess strong experience across several of the following areas:
Cyber Security Governance & Compliance
- Extensive experience performing Cyber Security Governance, Risk and Compliance (GRC) functions within complex ICT environments.
- Strong understanding of security governance principles, risk management methodologies and compliance frameworks.
- Experience interpreting security policies and translating them into practical technical and business requirements.
Australian Government Security Frameworks
Demonstrated knowledge and practical experience working with:
- Information Security Manual (ISM)
- Protective Security Policy Framework (PSPF)
- Essential Eight Maturity Model
- Australian Government cyber security standards and assurance processes
Security Assurance
Experience supporting or coordinating activities including:
- IRAP Assessments
- Penetration Testing
- Security Reviews
- Security Accreditation
- Risk Assessments
- Compliance Reporting
- Security Control Validation
Documentation & Governance
Strong experience producing high-quality security documentation including:
- Security Risk Assessments
- Governance Artefacts
- Security Plans
- Policies & Standards
- Security Requirements
- Executive Reports
- Compliance Documentation
Stakeholder Engagement
- Experience working with business, technical and executive stakeholders.
- Ability to communicate complex cyber security concepts to both technical and non-technical audiences.
- Excellent written communication and presentation skills.
Professional Skills
- Strong analytical and critical thinking ability.
- Excellent problem-solving skills.
- Ability to prioritise competing workloads.
- High attention to detail.
- Self-motivated with the ability to work independently.
- Strong collaboration and teamwork skills.
Essential Requirements
To be successful in this role you should demonstrate:
- Proven experience in a Cyber Security Governance, Risk & Compliance (GRC) role.
- Strong working knowledge of the Information Security Manual (ISM), Protective Security Policy Framework (PSPF) and Essential Eight.
- Experience developing cyber security governance documentation and security artefacts.
- Experience coordinating or supporting security assurance activities such as IRAP assessments and penetration testing.
- Strong stakeholder engagement and communication skills.
- Ability to obtain a Negative Vetting Level 1 (NV1) Security Clearance prior to commencement.
Highly Desirable
Candidates will be highly regarded if they possess:
- Current Negative Vetting Level 1 (NV1) Security Clearance.
- Five or more years’ experience working within Cyber Security GRC.
- Experience supporting Australian Government departments or agencies.
- Experience working within highly regulated or mission-critical ICT environments.
- Experience contributing to enterprise cyber resilience or security uplift programs.
Why Apply?
This is an opportunity to work on nationally significant cyber security initiatives that directly support the resilience of Australia’s critical government systems.
You will join an experienced team delivering meaningful work within a complex enterprise environment, while gaining exposure to large-scale security assurance programs, governance initiatives and strategic cyber security projects.
If you are passionate about cyber governance, security assurance and strengthening organisational cyber resilience, we encourage you to apply.
Apply today or contact SkyDB for a confidential discussion.
Pay: $95,000.00 – $175,000.00 per year
Work Location: In person