Lead Risk Assessor - Cybersecurity
Perth, Western Australia, Australia · Full Time
Be the first to apply
- Experience
- 15+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We are seeking a seasoned cybersecurity risk professional to lead comprehensive risk evaluations and provide strategic guidance. This senior role demands effective communication of cybersecurity risks and opportunities to influence key business decisions.
Core Responsibilities
- Direct cybersecurity risk assessments across various projects, products, and technology initiatives.
- Partner with project teams to detect, evaluate, and mitigate security vulnerabilities and control weaknesses.
- Translate intricate technical risks into accessible business language for stakeholders, including executives.
- Make informed, risk-based decisions and manage stakeholder expectations effectively.
- Enhance team processes, documentation, and engagement frameworks.
Additional Duties
- Collaborate with business units, engineers, delivery teams, product vendors, partners, and cyber assurance personnel to understand and relay cyber risks.
- Develop and maintain reusable assets such as standardized findings, templates, and process improvements.
- Contribute to security strategies, standards, policies, and governance frameworks.
- Identify and communicate security risks promptly while incorporating feedback from privacy, legal, engineering, and operations teams.
- Build strategic alliances with industry and technology vendors to stay ahead of emerging threats and opportunities.
- Mentor and coach risk assessors and temporary team members through feedback and knowledge sharing.
- Manage complex initiatives by simplifying outcomes to enable efficient delivery and execution.
Qualifications and Experience
- At least 15 years of experience in the cybersecurity field.
- A minimum of 8 years in Governance, Risk and Compliance (GRC) or risk management roles.
- Hands-on experience performing technical risk assessments.
- Familiarity with industry standards such as ISO 27001, PCI-DSS, NIST, and enterprise security frameworks.
- Strong skills in stakeholder engagement and the ability to convert technical risks into meaningful business insights.
- Experience operating within large, complex enterprise settings.
Preferred Attributes
- Background in non-cyber risk or other GRC areas.
- Professional certifications like CRISC, CISSP, CISM, or SABSA.
- Experience working in Agile and DevOps environments.
Level
Lead
Industry
Software DevelopmentSkills
How they work
Communication
Teamwork & Collaboration
Leadership
Strategic Thinking