freehire launches on Product Hunt on 26 August.

Follow →

Cyber GRC Analyst

Summary

Cyber GRC Analyst to support governance, risk, and compliance activities for the Australian Electoral Commission’s resilience program.

Azooa is preparing a response for LH-07441 – Senior Cyber Security Governance Analyst with the Australian Electoral Commission (AEC) and is seeking a suitably qualified cyber security professional for this opportunity.
OverviewThe Australian Electoral Commission is seeking a Senior Cyber Security Governance Analyst – APS6 equivalent to support cyber security Governance, Risk and Compliance activities within the AEC’s resilience uplift program.The role reports to AEC Cyber Security and will also support election-specific cyber security requirements during electoral events.This is a surge position linked to the delivery of electoral events and requires a consultant who can work confidently across security governance, assurance, executive documentation and stakeholder engagement in a high-assurance government environment.Core Purpose
The successful candidate will support the AEC’s cyber security resilience uplift by strengthening governance, security assurance and formal GRC documentation.The role will contribute security considerations to solution design, develop and review security requirements, coordinate assurance activities such as IRAP and penetration testing, and prepare documentation supporting senior executive decision-making.
Scope / Responsibilities Contribute security considerations to solution design Review and provide recommendations for the development of security requirements Develop communications and documentation for senior executive decision-making Support coordination of security assurance processes Support IRAP activities Support coordination of penetration testing Lead the development of formal cyber security documentation Support broader cyber security GRC activities within the resilience uplift program Provide additional support for election-specific cyber security requirements during electoral events.
Essential Criteria✅ Knowledge of the Information Security Manual (ISM), Protective Security Policy Framework (PSPF) and Essential Eight✅ Demonstrated experience and capability performing a cyber security GRC role✅ Demonstrated experience managing stakeholder or client interactions to achieve an outcome✅ Demonstrated experience developing GRC documentation.
Desirable Criteria⭐ Minimum 5 years’ experience in related roles.
Strong Candidate ProfileCandidates are likely to be particularly well positioned where they can demonstrate experience across: Australian Government cyber security GRC ISM compliance PSPF Essential Eight Security governance and risk management Security requirements development IRAP coordination or remediation Penetration testing coordination Security assurance Cyber resilience uplift programs Formal security documentation Executive briefs and decision papers Stakeholder and client engagement Security risk assessments Working within classified Commonwealth environments
Engagement Details RFQ ID: LH-07441 Role: Senior Cyber Security Governance Analyst Buyer: Australian Electoral Commission Experience Level: Senior – APS6 equivalent Location: ACT Working Arrangement: Full-time onsite Estimated Start: 1 September 2026 Initial Contract: 12 months Extension: 1 x 12 months Candidate Limit: Maximum 1 candidate per seller Security Clearance: NV1 required prior to commencement⏰ RFQ Closing: 11:59pm, Friday 28 August 2026 Canberra timeWorking ArrangementThe role is full-time onsite in the ACT.
Temporary work-from-home arrangements may be considered on a case-by-case basis, but the AEC has confirmed that onsite presence in the ACT is required.The normal working pattern is 7.5 hours per day, Monday to Friday, equating to 37.5 hours per week.
Additional hours may be required during electoral events or other periods of heightened activity, with 45 hours per week being a notional maximum where operationally required. Extended hours and weekend work may also be required during key event periods.Clearance Requirements
An active NV1 clearance is required prior to commencement.Although the original listing states that the candidate must be able to obtain NV1, the AEC subsequently clarified in the RFQ Q&A that candidates must be NV1 cleared before commencing because the role requires access to classified information.
The AEC has also stated that candidates who already possess NV1 are strongly preferred. Candidates without the required clearance during interview may be removed from further consideration.
Azooa recommends structuring the pitch around clear evidence of: ISM, PSPF and Essential Eight application Hands-on cyber security GRC delivery Security governance and assurance IRAP and penetration testing coordination Development of formal GRC and security documentation Senior stakeholder management Practical outcomes achieved in government or comparable regulated environmentsSpecific examples with measurable outcomes will generally provide stronger evidence than broad capability statements.
RFQ RelevanceA strong submission should demonstrate more than general cyber security experience.The AEC is specifically seeking someone with practical Governance, Risk and Compliance capability who can operate across both technical security assurance and senior-level documentation.
Strong candidates should make their experience visible across: Cyber security governance Risk and compliance ISM PSPF Essential Eight IRAP Penetration testing assurance Security requirements Executive communications Formal GRC documentation Stakeholder management Cyber resilience uplift
Given the candidate limit of one, Azooa will be focusing on a strongly aligned profile with active NV1 clearance and clear evidence against all essential criteria.
Rate Guidance Azooa recommended value-for-money PAYG range: $132–$138/hour including super Azooa recommended value-for-money Pty Ltd range: $134–$140/hour + GST Preferred PAYG target: approximately $135/hour including super Preferred Pty Ltd target: approximately $137/hour + GST Azooa recommended maximum PAYG rate: $145/hour including super Azooa recommended maximum Pty Ltd rate: $147/hour + GSTAzooa recommends bidding around $135/hour PAYG including super or $137/hour + GST via Pty Ltd where commercially workable.
This should create a strong value-for-money position while recognising the specialist requirements of the role, including active NV1 clearance, Commonwealth cyber GRC experience and the onsite ACT requirement.
Around $132–$138/hour PAYG / $134–$140/hour + GST Pty Ltd: strongest value-for-money positioning and potentially a higher chance of winning where the candidate demonstrates strong role fit
Around $139–$145/hour PAYG / $141–$147/hour + GST Pty Ltd: may still be competitive where supported by strong Australian Government GRC experience, active NV1, IRAP exposure and excellent ISM / PSPF / Essential Eight capability
Above $145/hour PAYG / $147/hour + GST Pty Ltd: less competitive unless niche cyber security expertise, clearance, domain fit or exceptional Federal Government experience clearly justifies the higher rate
Higher rates may still be considered where niche cyber security skills, clearance, domain fit or strong program relevance outweigh rate competitiveness.
The RFQ itself does not publish a maximum hourly rate, so these figures are Azooa’s recommended pricing guidance, not buyer-set caps.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available