Powered by pgvector · cosine kNN
No similar jobs yet — embeddings have not been generated for this listing. Run npm run seed:embeddings with AI Gateway access (AI_GATEWAY_API_KEY) configured.
Master2Manage® Limited, Australia
Location: Canberra, ACT – applicants must be willing to work on-site where requiredEngagement: ContractCitizenship: Australian Citizenship mandatorySecurity Clearance: NV1 desirable or ability to achieve Company Descr…
Your match
See how you fit
Scored against this job in seconds
Your account
Sign in to apply
Your profile and your match for this job appear right here.
By continuing you agree to our Terms and Privacy Policy.
sign in above to apply · via LinkedIn
About the role
Location: Canberra, ACT – applicants must be willing to work on-site where requiredEngagement: ContractCitizenship: Australian Citizenship mandatorySecurity Clearance: NV1 desirable or ability to achieve
Company DescriptionMaster2Manage® Pty Limited is an Australian-owned management and technology consulting firm supporting government, regulated industries and private organisations to strengthen cyber resilience, deliver ICT initiatives, build workforce capability, and improve governance, compliance and assurance.Our cybersecurity capability spans governance, risk and compliance (GRC), cyber security assurance, Essential Eight, security risk assessment, security governance frameworks, security documentation, control assessment, audit readiness, security uplift and remediation planning.Master2Manage is an approved supplier under the BuyICT Digital Marketplace 2.0 and BuyNSW ICT Services Scheme and supports ICT, cybersecurity and digital transformation initiatives across government, defence, healthcare, critical infrastructure and commercial environments.
The RoleMaster2Manage is seeking experienced Cyber Security GRC & Assurance Consultants to support cybersecurity governance, risk, compliance and assurance engagements.This is not a general cyber analyst or SOC role. The work is focused on assessing security environments, interpreting security obligations, evaluating controls, developing practical security governance and assurance artefacts, identifying security gaps and supporting organisations through structured cyber security uplift.The successful consultant will be comfortable working independently with senior business, technology and security stakeholders and translating complex security requirements into practical, evidence-based recommendations.
Key ResponsibilitiesDepending on the engagement, responsibilities may include:Conduct cyber security governance, risk and compliance assessments against applicable security frameworks and organisational requirements.Assess the design, implementation and effectiveness of security controls and identify control gaps, weaknesses and improvement opportunities.Perform security risk assessments covering systems, technology environments, projects, business processes and third-party services.Apply and interpret frameworks and guidance including the Australian Government Information Security Manual (ISM), Protective Security Policy Framework (PSPF), Essential Eight, NIST Cybersecurity Framework, ISO/IEC 27001 and related standards.Review existing cyber security governance arrangements, policies, standards, procedures, plans and supporting security documentation.Develop and improve cyber security policies, standards, procedures, control frameworks and governance artefacts.Develop or contribute to Security Risk Management Plans, System Security Plans, security assessments, control matrices, treatment plans, compliance registers and assurance documentation.Conduct security control evidence reviews and determine whether evidence adequately demonstrates control implementation and effectiveness.Facilitate security risk and control workshops with business owners, system owners, technical teams and senior stakeholders.Identify security deficiencies and develop prioritised, risk-based remediation recommendations rather than purely compliance-driven findings.Support cyber security maturity assessments and structured security uplift programs.Establish and maintain security risk, issue, exception and remediation registers.Support internal and external security audits, assurance reviews and compliance activities.Assess third-party and supplier cyber security risks and security obligations.Prepare concise executive-level cyber risk and assurance reports that clearly communicate exposure, priorities and recommended actions.Track remediation activities and independently validate closure of identified security findings where required.Work with security architects, engineers, technical specialists and penetration testers to translate technical findings into governance, risk and assurance outcomes.
Essential ExperienceCandidates should demonstrate strong practical experience across several of the following areas:Cyber Security Governance, Risk and Compliance (GRC).Cyber security risk assessment and treatment.Security control assessment and assurance.Information security governance frameworks.ISM and/or PSPF control environments.Essential Eight requirements and maturity concepts.Security policies, standards and procedures.System and organisational security documentation.Security audit and compliance readiness.Security findings, remediation and risk acceptance processes.Stakeholder workshops and evidence-based security assessments.Communicating technical cyber security risks to non-technical and executive stakeholders.Applicants should have experience performing substantive GRC and assurance work rather than primarily operational SOC, service desk or general IT support duties.
Qualifications and CertificationsA relevant tertiary qualification in Cyber Security, Information Technology, Computer Science, Engineering, Information Systems, Risk Management or a related discipline is desirable.Relevant professional certifications will be highly regarded, including:CISSPCISMCISACRISCISO/IEC 27001 Lead Auditor or Lead ImplementerCGRC or equivalent GRC certificationEssential Eight related assessment experience or trainingIRAP-related experienceOther recognised cyber security, risk or assurance certificationsEquivalent substantial professional experience will also be considered.
Highly DesirablePrevious cybersecurity GRC or assurance experience within Australian Commonwealth, State Government, Defence, critical infrastructure or similarly regulated environments.Strong working knowledge of the Australian Government ISM and PSPF.Experience conducting Essential Eight assessments or supporting Essential Eight maturity uplift.Experience preparing or reviewing System Security Plans, Security Risk Management Plans and related security artefacts.Experience assessing ICT systems against defined security control frameworks.Experience supporting system accreditation, authorisation, certification or security assurance processes.Experience working alongside IRAP assessors or supporting IRAP readiness and remediation activities.Experience conducting cyber security maturity or gap assessments and developing practical remediation roadmaps.Current Australian Government NV1, NV2 or higher security clearance.
Work Location and AvailabilityApplicants must be Australian citizens and ordinarily resident in Australia.Consultants must be prepared to work on-site as required by the engagement, at client premises.Depending on the nature, security requirements and delivery phase of an engagement, hybrid working arrangements may subsequently be available and agreed as part of the engagement arrangements. Some engagements may require travel or regular attendance in Canberra.
What to Include With Your ApplicationPlease send your application to careers@master2manage.com with the subject:Cyber Security GRC & Assurance ConsultantPlease include:Current CV.Current city and state of residence.Australian citizenship confirmation.Current security clearance NV1/NV2.Clearance status/validity.Relevant professional certifications.Brief summary of Commonwealth, Defence, State Government, critical infrastructure or equivalent regulated-environment experience.Availability / notice period.Preferred work arrangement and ability to work on-site.Indicative hourly and/or daily contract rate, inclusive of superannuation applicable.Please do not include sensitive or classified information regarding previous engagements, systems or security environments.
ImportantThis role is suited to experienced practitioners who can independently perform cyber security governance, risk and assurance activities and produce high-quality client-ready deliverables.Applicants with predominantly SOC monitoring, helpdesk, network administration or general IT support experience without substantive cyber GRC or assurance experience are unlikely to be suitable.Engagement requirements, duration, location and working arrangements may vary according to assignment requirements.
sign in above to apply · via LinkedIn
Your job hunt, handled
Ask about any role and get a straight answer on your fit. Then stop searching: new matches land in your WhatsApp the moment they’re listed.
Free for jobseekers