Senior Cyber Security Governance Analyst - GRC NV1 - Essential Eight Governance
Summary
Senior GRC analyst embeds security requirements into government solutions, writes security artefacts, and coordinates assurance activities under the ISM/PSPF/Essential Eight framework.
Salary: Rates Negotiable - Contract up to 24 months
- Competitive Market Rates – Negotiable
- Immediate Start
- Canberra ACT – full-time onsite
- Initial 12-month contract + 12-month extension option
- NV1 security clearance required
- Cyber Security GRC, assurance and security documentation
This is a senior Governance, Risk and Compliance (GRC) role with a strong security assurance and documentation focus. You will work closely with cyber security, technical and business stakeholders to embed security requirements into solutions, coordinate assurance activities and produce high-quality security artefacts for technical and executive audiences.
This is not a SOC operations or incident-response position. We are looking specifically for candidates with substantial cyber security governance, risk, compliance and assurance experience.
Essential experience
- Cyber Security Governance, Risk and Compliance (GRC)
- Current NV1 security clearance or higher is strongly preferred
- Strong knowledge and practical application of the Australian Government Information Security Manual (ISM)
- Strong knowledge of the Protective Security Policy Framework (PSPF)
- Strong understanding of the ACSC Essential Eight
- Developing high-quality cyber security GRC documentation and security artefacts
- Reviewing solutions and identifying relevant security requirements and controls
- Providing security recommendations during solution design
- Managing senior stakeholders and client interactions to achieve security outcomes
- Producing clear documentation and recommendations for senior executive decision-making
- Security assurance activities, risk assessment and control assessment
- 5+ years' experience in cyber security, GRC, security assurance or closely related roles
- Experience working within complex enterprise or government ICT environments
- Strong experience producing formal security risk, compliance and assurance documentation
- Experience working across security accreditation, assessment or authorisation processes
- Ability to translate complex technical security issues into clear business and executive recommendations
Working within a cyber security resilience uplift program, you will be responsible for activities including:
- Contributing security considerations to solution design
- Reviewing and recommending security requirements and controls
- Developing formal cyber security and GRC documentation
- Supporting cyber security risk and assurance activities
- Coordinating IRAP assessments and penetration testing
- Working with technical teams to address security findings and recommendations
- Preparing security documentation and communications for senior executives
- Supporting additional cyber security requirements during periods of heightened operational activity
Location: Canberra ACT
Working arrangement: Full-time onsite, with temporary work-from-home arrangements considered only on a case-by-case basis
Contract: Initial 12 months
Extension: One further 12-month extension option
Hours: Standard 37.5-hour week, with additional hours potentially required during periods of heightened operational activity
Clearance: NV1 required prior to commencement
Rate: Competitive hourly contract rate, dependent on experience
This role supports a high-profile Federal Government environment where cyber resilience, security assurance and the quality of security governance are critical.
To apply
Please apply with your current CV and include:
- Your current security clearance
- Your availability to work onsite in Canberra
- Your earliest available start date
- Your expected hourly rate
- A brief summary of your experience with ISM, PSPF, Essential Eight and cyber GRC documentation