Powered by pgvector · cosine kNN
MinterEllison
Location: Brisbane, Melbourne, Sydney Contract Type: Permanent MinterEllison is one of Australia’s largest independent law and consulting firms. With a heritage of almost 200 years, we are known for our excellence, an…
Your match
See how you fit
Scored against this job in seconds
Your account
Sign in to apply
Your profile and your match for this job appear right here.
sign in above to apply · via career10.successfactors.com
About the role
Location: Brisbane, Melbourne, Sydney
Contract Type: Permanent
MinterEllison is one of Australia’s largest independent law and consulting firms. With a heritage of almost 200 years, we are known for our excellence, and our authentic and enduring relationships with our clients, our people and our communities. Clients seek out MinterEllison to help them solve complex problems every day. We do this by our full-service legal offering and complementary consulting offering.
We offer opportunities to work on industry-leading mandates for top-tier clients, while being part of a high-performing and collaborative team that values excellence, diversity of thought, curiosity, and inclusion. We value our people and empower them to achieve their ambitions - with the support, trust and autonomy to grow their careers in meaningful ways.
At MinterEllison, we're leading the way with AI and other emerging technologies, powering innovation right across our firm. You will have the opportunity to engage with AI tools we've built, and other external AI tools, to enhance efficiencies and excellence internally and with our clients.
We support sustainable ways of working regarding how, when and where you work and offer a wide range of social, financial and health benefits (see https://www.minterellison.com/-/media/Minter-Ellison/Files/Careers/MinterEllison-Employee-Benefits-Dec_2025.pdf)
Your Role
Our IT Security team is looking for an IT Security Consultant to deliver technical security risk analysis and assurance activities across MinterEllison's technology environment. The role spans two core functions: (1) technical security risk analysis – including threat and risk assessments, security architecture reviews, and vulnerability analysis; and (2) assurance coordination – including client questionnaires, supply chain security, penetration testing oversight, user awareness, and compliance with security standards.
This is an internal role reporting into the IT Security GRC Manager. You will work closely with the broader IT Security team, IT Architecture, IT Operations, IT Procurement, and managed services providers.
Key Responsibilities
Conduct threat and risk assessments for new and existing systems, applications, and AI solutions, producing structured risk reports with prioritised remediation recommendations
Perform security architecture reviews on proposed and existing solutions against MinterEllison standards and applicable frameworks
Provide security risk input into IT projects at key stages, ensuring security is embedded by design
Analyse vulnerability scan results, triage findings by risk severity, and track remediation to closure
Coordinate penetration testing activities including scoping, third-party coordination, and remediation tracking
Respond to client questionnaires, audits, security program enquiries, and RFPs
Perform supply chain security reviews and maintain the risk register
Contribute to the IT Security awareness program and coordinate with broader training teams
Assist with maintaining ISO27001 and other compliance certification programs
Maintain MinterEllison's Security Trust Centre with regular updates
Run quarterly audits on privileged access, user access, mobile device compliance, and asset inventory
Assist with security incident response during and after business hours
Knowledge, Skills and Experience
At least 2 years' experience in information security or IT risk, with hands-on exposure to technical security assessments
Demonstrated ability to conduct structured threat and risk assessments using recognised methodologies (e.g. STRIDE, OCTAVE, NIST RMF)
Practical exposure reviewing security architectures including cloud security (Azure/M365) and hybrid infrastructure
Familiarity with vulnerability management tooling (e.g. Qualys, Tenable, CrowdStrike)
Excellent knowledge of security frameworks such as ISO27001, SSAE16, APRA CPS234, ASD Essential 8, and NIST v2.0
Expert coordination skills with ability to maintain programs on schedule
Demonstrated experience writing high quality executive reports/briefings
Experience running internal IT audits and supplier assessments
Agile mindset with ability to manage tasks independently
Relevant certifications highly desirable (CISSP, CISM, CISA, CompTIA Security+, or cloud security certifications)
Personal Attributes
High integrity and professionalism with excellent communication skills across all levels
Self-starter with strong analytical and problem-solving abilities
Excellent organisational and time management skills with attention to detail
Strategic focus ensuring daily activities add commercial value to the business
How to apply
We encourage applications from people of all ages, abilities, cultural backgrounds, genders (including trans or gender diverse), LGBTQ+ people and those with carer responsibilities. We particularly encourage Aboriginal and Torres Strait Islander people to apply.
We prefer to connect with people directly, so please submit your CV by clicking on the 'Apply' button. We encourage all applications, including if you do not meet all the criteria listed for the role. Your application will also enable us to consider you for other opportunities that may be available at MinterEllison.
If you are currently a MinterEllison employee, please apply through the internal careers page.
If you would like further information, require any adjustments throughout the recruitment process or for a confidential discussion, please contact lisa.fleming@minterellison.com.
sign in above to apply · via career10.successfactors.com
BAE Systems
BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation state…
Hastha Solutions
Requirements Key Accountabilities Include: Leading cybersecurity risk assessments across customer projects Collaborating with project teams to identify and address security gaps Communicating complex technical issues …
Swinburne University
Seeking an experienced Cyber Governance & Risk Analyst Full-time, fixed-term position (until 2029) based at our Hawthorn campus Hew 7 salary + 17% super and staff benefit About the Role We have an exciting opportunity…
Protiviti
JOB REQUISITION IT Audit & Technology Assurance Senior Consultant LOCATION SYDNEY ADDITIONAL LOCATIONS JOB DESCRIPTION Are you ready to step up and shape the future of technology audit and assurance advisory? Protivit…
Protiviti
JOB REQUISITION IT Audit & Technology Assurance Senior Consultant LOCATION SYDNEY ADDITIONAL LOCATIONS JOB DESCRIPTION Are you ready to step up and shape the future of technology audit and assurance advisory? Protivit…
KBR
Title: Cyber Security Consultant Shape the future of critical infrastructure security Are you passionate about helping organisations tackle complex cyber security challenges in some of Australia's most significant pro…
Your job hunt, handled
Ask about any role and get a straight answer on your fit. Then stop searching: new matches land in your WhatsApp the moment they’re listed.
Free for jobseekers