XPT Software Australia Pty Ltd

LeadRisk Assessor_Cybersecurity

XPT Software Australia Pty Ltd Victoria, Australia

IT Services and IT Consulting · 51-200 employees

8 h ago
security Principal (10+ yrs) Contractor Australia
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Lead Risk Assessor will lead cyber security risk assessments across projects and technology initiatives while providing strategic guidance to stakeholders. They are responsible for communicating complex technical risks in business terms and managing the uplift of team processes and documentation.

What they look for

Cyber Security Risk Assessment Governance, Risk and Compliance ISO 27001 PCI-DSS NIST Stakeholder Engagement Risk Management Security Strategy Technical Risk Assessment Agile DevOps CRISC CISSP CISM SABSA

Requirements

Candidates must have at least 15 years of experience in cyber security, with a minimum of 8 years specifically in GRC or risk management functions. Practical experience with industry frameworks like ISO 27001, NIST, and PCI-DSS is required, along with strong stakeholder communication skills.

Full description

Lead Risk Assessor

Role Summary Senior cyber security risk professional responsible for leading risk assessments, providing strategic risk guidance, and influencing business decisions through clear communication of cyber security risks and opportunities.

Key Accountabilities

· Lead cyber security risk assessments across projects, products, and technology initiatives.

· Collaborate with project teams to identify, assess, and address security gaps and control deficiencies.

· Communicate complex technical risks in clear business terms, including to executive stakeholders through risk decision-making processes.

· Make informed risk-based decisions and manage stakeholder expectations effectively.

· Lead the uplift of team processes, documentation, and engagement models.

Additional Responsibilities

· Collaborate with business stakeholders, engineers, delivery teams, product vendors, partners, and cyber assurance teams to understand and communicate cyber risk.

· Define and maintain reusable assets including standardised findings, templates, and process improvements.

· Contribute to the creation and governance of security strategy, standards, frameworks, and policies.

· Identify and communicate security risks in a timely manner while incorporating insights from privacy, legal, engineering, and operational stakeholders.

· Develop strategic relationships across industry and technology vendors to anticipate emerging threats and opportunities.

· Mentor and coach risk assessors and secondees through guidance, feedback, and knowledge sharing.

· Manage complex initiatives while simplifying outcomes to support effective delivery and execution.

Qualifications and Experience

· Minimum 15 years of experience within Cyber Security.

· At least 8 years of experience in a Governance, Risk and Compliance (GRC) or Risk Management function.

· Practical experience conducting technical risk assessments.

· Knowledge of industry frameworks and standards including ISO 27001, PCI-DSS, NIST, and enterprise security frameworks.

· Strong stakeholder engagement and communication skills with the ability to translate technical risks into business insights.

· Experience working within large and complex enterprise environments.

Highly Desirable

· Previous experience in a non-cyber risk or GRC role.

· Industry certifications such as CRISC, CISSP, CISM, or SABSA.

· Experience working within Agile and DevOps environments.

Similar roles