About Yira Yarkiny Security Services
Yira Yarkiny Security Services is part of the Yira Yarkiny Group, a 100% Aboriginal-owned and Supply Nation Certified organisation headquartered in Ascot, Western Australia. Founded by a Badimaya Yamatji man from the Murchison region, the Group delivers physical security, cybersecurity and managed IT services to government and private sector clients, including some of Australia's largest resources and infrastructure organisations.
We combine professional service delivery with a genuine commitment to Aboriginal economic participation, employment pathways and community development. Our team operates to certified management system standards across quality, safety and information security, and we hold ourselves and our people to a high standard of integrity, accountability and client care.
About the role
We are seeking an experienced Cyber GRC Specialist to strengthen the Group's cybersecurity governance, risk and compliance capability. Reporting to senior management, you will support Yira Yarkiny Security Services and its external clients, taking ownership of security frameworks, audits, risk management and compliance activities across the business.
This is a hands-on role suited to someone who can move comfortably between governance documentation, technical cloud security reviews and client-facing advisory work.
Key responsibilities
- Review and continuously improve the cybersecurity posture of the business and its clients.
- Develop, implement and maintain cybersecurity policies, procedures, standards and control frameworks.
- Conduct cybersecurity audits, risk assessments, compliance reviews and control-gap assessments.
- Prepare audit reports, risk treatment plans, remediation recommendations and control measures.
- Support compliance and alignment with ISO/IEC 27001, the NIST Cybersecurity Framework, Australian Signals Directorate (ASD) cybersecurity standards and guidance, and applicable Australian regulatory requirements.
- Maintain risk registers, compliance records, audit evidence and remediation trackers.
- Review security controls and risks across Microsoft Azure and Amazon Web Services (AWS) environments.
- Assess internal and client IT requirements and recommend suitable technologies, services and security controls.
- Assist with designing and implementing secure cloud and IT solutions.
- Evaluate cybersecurity products and improve the Group's cybersecurity services and product offerings.
- Develop and deliver cybersecurity awareness training, guidelines and professional development pathways.
- Prepare clear reports for management, clients and other stakeholders.
- Provide ad hoc cybersecurity, IT and GRC support to internal and external stakeholders.
Qualifications and experience
- Master's degree in Cybersecurity, Information Technology or a closely related discipline.
- Minimum three years of relevant experience in cybersecurity governance, risk, compliance or auditing.
- At least two years of experience working within the security industry.
- Hands-on experience with Microsoft Azure and Amazon Web Services environments.
- Practical knowledge of ISO/IEC 27001, NIST CSF and ASD cybersecurity standards and guidance.
- Experience conducting cybersecurity audits, risk assessments, control-gap analyses and remediation activities.
- Experience developing cybersecurity policies, procedures and governance documentation.
- Strong analytical, technical-writing, communication and stakeholder-management skills.
- Ability to support multiple companies and manage competing priorities.
Pay: $80,000.00 – $90,000.00 per year
Benefits:
- Professional development assistance
Work Location: In person