M

IT Security Consultant - Assurance

MinterEllison

Sydney, New South Wales, Australia · Full Time

Be the first to apply

Experience
2+ yrs
Salary
Openings
1
Posted
1 week ago
Work mode
In office
Eligibility
Open to candidates from all age groups, abilities, cultural and gender identities, including trans and gender diverse individuals and those with caregiving duties. Aboriginal and Torres Strait Islander peoples are strongly encouraged to apply.
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About MinterEllison

MinterEllison is among Australia's largest independent legal and consulting firms, boasting nearly two centuries of heritage. Renowned for excellence and authentic client relationships, the firm assists clients in solving complex challenges through comprehensive legal and consulting services.

Team members engage in industry-leading projects for premier clients within a collaborative, high-performing environment that values diversity of thought, curiosity, and inclusion. MinterEllison empowers its people with autonomy, trust, and support to advance their careers meaningfully.

The firm integrates AI and emerging technologies to drive innovation internally and for clients, providing staff opportunities to utilize proprietary and external AI tools to enhance efficiency and quality.

Sustainable working practices regarding schedule and location are supported alongside a broad array of social, financial, and health benefits.

Role Overview

The IT Security Consultant will execute technical security risk analyses and assurance functions across MinterEllison's technology landscape. This dual-role focuses on (1) conducting threat and risk assessments, security architecture reviews, and vulnerability analyses; and (2) coordinating assurance activities such as client questionnaires, supply chain security evaluation, penetration testing oversight, user awareness initiatives, and ensuring compliance with security standards.

Reporting to the IT Security GRC Manager, this position collaborates with teams including IT Security, IT Architecture, IT Operations, IT Procurement, and external managed service providers.

Responsibilities

  • Carry out threat and risk assessments for new and existing systems, applications, and AI technologies, producing structured risk reports with prioritized mitigation recommendations.
  • Review security architectures of proposed and current solutions to ensure alignment with MinterEllison standards and relevant frameworks.
  • Provide security risk insights during key IT project stages to embed security by design.
  • Manage penetration testing processes including defining scope, liaising with third parties, and tracking remediation efforts.
  • Respond to client security questionnaires, audits, program inquiries, and RFPs.
  • Conduct supply chain security reviews and maintain the associated risk register.
  • Support the IT Security awareness program in coordination with training teams.
  • Assist in maintaining certifications such as ISO27001 and other compliance programs.
  • Maintain the Security Trust Centre with regular updates.
  • Conduct quarterly audits on privileged access, user access, mobile device compliance, and asset inventories.

Requirements and Experience

  • Minimum 2 years of experience in information security or IT risk with practical expertise in security assessments.
  • Proven ability to apply structured threat and risk assessment methodologies such as STRIDE, OCTAVE, or NIST RMF.
  • Experience conducting security architecture reviews, including cloud environments (Azure/M365) and hybrid infrastructures.
  • Familiarity with security frameworks including ISO27001, SSAE16, APRA CPS234, ASD Essential 8, and NIST v2.0.
  • Strong coordination skills to maintain security programs on schedule.
  • Capability to craft high-level executive reports and briefings.
  • Experience performing internal IT audits and supplier assessments.
  • Comfort with an agile work environment and ability to manage tasks independently.
  • Relevant security certifications are advantageous, such as CISSP, CISM, CISA, CompTIA Security+, or cloud security certs.

Personal Attributes

  • Demonstrates high integrity and professional communication across organizational levels.
  • Self-motivated with strong analytical and problem-solving skills.
  • Excellent organization, time management, and attention to detail.
  • Strategic mindset focused on delivering commercial value through daily activities.

Diversity & Application

The firm welcomes applications from candidates of all backgrounds including age, ability, culture, gender identity, sexual orientation, and those with caregiving responsibilities. Aboriginal and Torres Strait Islander individuals are especially encouraged to apply.

How they work

Problem Solving Attention to Detail Time Management Independence Strategic Thinking

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer