freehire launches on Product Hunt on 26 August.

Follow →

Cyber Security GRC Analyst

Summary

GRC analyst embeds cybersecurity requirements into projects and operations, aligning systems with Australian government security frameworks like ISM and PSPF.

  • Contract Length:12‑month initial contract, with further 12‑month extensions available
  • Security Clearance: Must be an Australian Citizen and hold a minimum NV1 security clearance
  • Location: Canberra, ACT based role with on-site requirement

What You Will Do

As a Cyber Security GRC Consultant, you will play a key role in supporting large-scale cyber resilience and security uplift initiatives within a highly regulated environment. You will work closely with business, technology, and security stakeholders to ensure security requirements are embedded throughout project delivery and operational activities.

Your responsibilities will include

  • Contribute to solution and architecture design by providing cyber security guidance and risk-based recommendations.
  • Review, analyse, and define security requirements aligned with industry and government security frameworks.
  • Develop high-quality security documentation, reports, and executive briefings to support informed decision-making.
  • Coordinate and support security assurance activities, including security assessments, audits, penetration testing, and independent assurance reviews.
  • Lead the creation and maintenance of governance, risk, and compliance (GRC) artefacts, policies, procedures, and security documentation.
  • Engage with stakeholders across business and technical teams to drive security outcomes and ensure compliance obligations are met.
  • Support risk management activities, including security risk identification, assessment, treatment, and reporting.
  • Provide cyber security expertise during critical operational periods and program delivery milestones.
You Should Have

  • Strong knowledge of the Australian Government Information Security Manual (ISM), Protective Security Policy Framework (PSPF), and Essential Eight.
  • Demonstrated experience performing Cyber Security Governance, Risk & Compliance (GRC) functions within complex enterprise environments.
  • Proven ability to develop, review, and maintain security governance and compliance documentation.
  • Experience supporting security assurance activities, including audits, assessments, penetration testing, and compliance reviews.
  • Strong stakeholder management skills with the ability to engage effectively across technical and non-technical audiences.
  • Experience preparing executive-level communications, presentations, and security reporting.
  • Excellent written and verbal communication skills.
  • Ability to work independently while collaborating effectively within multidisciplinary teams.
Nice to Have

  • 5+ years of experience in Cyber Security, Governance, Risk & Compliance, or related security disciplines.
  • Experience working within highly regulated industries or government environments.
  • Familiarity with security accreditation, assurance, and risk management frameworks.
  • Exposure to cyber resilience, security transformation, or uplift programs.
  • Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent.
  • Understanding of security architecture principles and secure-by-design methodologies.
  • Experience coordinating multiple stakeholders and managing competing priorities across large programs.

If you’re interested in applying, please submit your application today. The role closes on 27/08/2026 before 05:00 pm, don’t miss out!

Feel free to reach out to me for a confidential chat about the role.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available