XPT Software

Lead Risk Assessor - Cybersecurity

XPT Software

Perth, Western Australia, Australia · Full Time

Be the first to apply

Experience
15+ yrs
Salary
Openings
1
Posted
1 week ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Overview

We are seeking a seasoned cybersecurity risk professional to lead comprehensive risk evaluations and provide strategic guidance. This senior role demands effective communication of cybersecurity risks and opportunities to influence key business decisions.

Core Responsibilities

  • Direct cybersecurity risk assessments across various projects, products, and technology initiatives.
  • Partner with project teams to detect, evaluate, and mitigate security vulnerabilities and control weaknesses.
  • Translate intricate technical risks into accessible business language for stakeholders, including executives.
  • Make informed, risk-based decisions and manage stakeholder expectations effectively.
  • Enhance team processes, documentation, and engagement frameworks.

Additional Duties

  • Collaborate with business units, engineers, delivery teams, product vendors, partners, and cyber assurance personnel to understand and relay cyber risks.
  • Develop and maintain reusable assets such as standardized findings, templates, and process improvements.
  • Contribute to security strategies, standards, policies, and governance frameworks.
  • Identify and communicate security risks promptly while incorporating feedback from privacy, legal, engineering, and operations teams.
  • Build strategic alliances with industry and technology vendors to stay ahead of emerging threats and opportunities.
  • Mentor and coach risk assessors and temporary team members through feedback and knowledge sharing.
  • Manage complex initiatives by simplifying outcomes to enable efficient delivery and execution.

Qualifications and Experience

  • At least 15 years of experience in the cybersecurity field.
  • A minimum of 8 years in Governance, Risk and Compliance (GRC) or risk management roles.
  • Hands-on experience performing technical risk assessments.
  • Familiarity with industry standards such as ISO 27001, PCI-DSS, NIST, and enterprise security frameworks.
  • Strong skills in stakeholder engagement and the ability to convert technical risks into meaningful business insights.
  • Experience operating within large, complex enterprise settings.

Preferred Attributes

  • Background in non-cyber risk or other GRC areas.
  • Professional certifications like CRISC, CISSP, CISM, or SABSA.
  • Experience working in Agile and DevOps environments.

Level

Lead

How they work

Communication Teamwork & Collaboration Leadership Strategic Thinking

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer