Lead Cybersecurity Risk Assessor
Carlton, Victoria, Australia · Full Time
Be the first to apply
- Experience
- 15+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 days ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We are seeking a seasoned senior cybersecurity risk professional to lead comprehensive risk assessments and offer strategic guidance on cybersecurity risks. This role requires influencing organizational decisions by clearly articulating both cybersecurity risks and opportunities in business terms.
Core Responsibilities
- Lead detailed cybersecurity risk evaluations for various projects, products, and technological initiatives.
- Partner closely with project teams to uncover, evaluate, and remediate security vulnerabilities and control shortcomings.
- Translate intricate technical risks into understandable business language for diverse stakeholders, including executive leadership during risk-related decision processes.
- Make strategically informed risk-based decisions and manage stakeholder expectations proactively.
- Drive enhancements in team workflows, documentation standards, and engagement methodologies.
Additional Duties
- Collaborate with business units, engineering and delivery teams, product vendors, partners, and cyber assurance groups to grasp and convey cybersecurity risks effectively.
- Establish and maintain reusable assets such as standardised findings, templates, and implement process optimizations.
- Contribute to developing and governing security strategies, standards, frameworks, and policies.
- Identify and communicate security risks promptly, integrating insights from privacy, legal, engineering, and operational departments.
- Foster strategic partnerships with industry and technology vendors to anticipate evolving threats and viable opportunities.
- Mentor and support risk assessors and guiding secondees through constructive feedback and knowledge dissemination.
- Manage complex projects by simplifying outcomes to facilitate smooth delivery and execution.
Qualifications and Experience
- At least 15 years of professional experience in Cybersecurity.
- A minimum of 8 years working within Governance, Risk and Compliance (GRC) or Risk Management roles.
- Hands-on experience in performing technical risk assessments.
- Well-versed in industry standards and frameworks such as ISO 27001, PCI-DSS, NIST, and broader enterprise security frameworks.
- Excellent stakeholder engagement capabilities and communication proficiency to convert technical risk details into actionable business insights.
- Proven experience operating within large-scale, complex enterprise environments.
Preferred Qualifications
- Experience in roles outside the traditional cyber risk or GRC domains is a plus.
- Relevant industry certifications like CRISC, CISSP, CISM, or SABSA are highly valued.
- Familiarity with Agile and DevOps workflows and environments.
Level
Lead
Industry
Software DevelopmentSkills
How they work
Communication
Problem Solving
Leadership
Strategic Thinking