LeadRisk Assessor_Cybersecurity
XPT Software Australia Pty Ltd Victoria, Australia
IT Services and IT Consulting · 51-200 employees
About the role
The Lead Risk Assessor will lead cyber security risk assessments across projects and technology initiatives while providing strategic guidance to stakeholders. They are responsible for communicating complex technical risks in business terms and managing the uplift of team processes and documentation.
What they look for
Requirements
Candidates must have at least 15 years of experience in cyber security, with a minimum of 8 years specifically in GRC or risk management functions. Practical experience with industry frameworks like ISO 27001, NIST, and PCI-DSS is required, along with strong stakeholder communication skills.
Full description
Lead Risk Assessor
Role Summary Senior cyber security risk professional responsible for leading risk assessments, providing strategic risk guidance, and influencing business decisions through clear communication of cyber security risks and opportunities.
Key Accountabilities
· Lead cyber security risk assessments across projects, products, and technology initiatives.
· Collaborate with project teams to identify, assess, and address security gaps and control deficiencies.
· Communicate complex technical risks in clear business terms, including to executive stakeholders through risk decision-making processes.
· Make informed risk-based decisions and manage stakeholder expectations effectively.
· Lead the uplift of team processes, documentation, and engagement models.
Additional Responsibilities
· Collaborate with business stakeholders, engineers, delivery teams, product vendors, partners, and cyber assurance teams to understand and communicate cyber risk.
· Define and maintain reusable assets including standardised findings, templates, and process improvements.
· Contribute to the creation and governance of security strategy, standards, frameworks, and policies.
· Identify and communicate security risks in a timely manner while incorporating insights from privacy, legal, engineering, and operational stakeholders.
· Develop strategic relationships across industry and technology vendors to anticipate emerging threats and opportunities.
· Mentor and coach risk assessors and secondees through guidance, feedback, and knowledge sharing.
· Manage complex initiatives while simplifying outcomes to support effective delivery and execution.
Qualifications and Experience
· Minimum 15 years of experience within Cyber Security.
· At least 8 years of experience in a Governance, Risk and Compliance (GRC) or Risk Management function.
· Practical experience conducting technical risk assessments.
· Knowledge of industry frameworks and standards including ISO 27001, PCI-DSS, NIST, and enterprise security frameworks.
· Strong stakeholder engagement and communication skills with the ability to translate technical risks into business insights.
· Experience working within large and complex enterprise environments.
Highly Desirable
· Previous experience in a non-cyber risk or GRC role.
· Industry certifications such as CRISC, CISSP, CISM, or SABSA.
· Experience working within Agile and DevOps environments.
Similar roles
-
Vice President, Institutional Sales (financial technology, digital assets, blockchain, cybersecurity..)
Ant-Tech United States · $140K–$220K/yr
-
Senior Security Engineer
The Lottery Corporation Brisbane, Queensland, Australia
-
Security Engineer II, Stores AppSec
Amazon Austin, Texas, United States · $159K–$202K/yr
-
Security Engineer II, Stores Application Security, SDO AppSec, Stores Security
Amazon New York, New York, United States · $159K–$213K/yr
-
Senior Content Security Engineer, GME Security
Amazon London, England, United Kingdom
-
Senior Hardware Security Engineer
Microsoft Redmond, Washington, United States · $120K–$261K/yr