Back to search
XPT Software Linkedin · Posted 3d ago

LeadRisk Assessor_Cybersecurity

Australia

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Lead Risk Assessor

Role Summary
Senior cyber security risk professional responsible for leading risk assessments, providing strategic risk guidance, and influencing business decisions through clear communication of cyber security risks and opportunities.

Key Accountabilities

· Lead cyber security risk assessments across projects, products, and technology initiatives.

· Collaborate with project teams to identify, assess, and address security gaps and control deficiencies.

· Communicate complex technical risks in clear business terms, including to executive stakeholders through risk decision-making processes.

· Make informed risk-based decisions and manage stakeholder expectations effectively.

· Lead the uplift of team processes, documentation, and engagement models.

Additional Responsibilities

· Collaborate with business stakeholders, engineers, delivery teams, product vendors, partners, and cyber assurance teams to understand and communicate cyber risk.

· Define and maintain reusable assets including standardised findings, templates, and process improvements.

· Contribute to the creation and governance of security strategy, standards, frameworks, and policies.

· Identify and communicate security risks in a timely manner while incorporating insights from privacy, legal, engineering, and operational stakeholders.

· Develop strategic relationships across industry and technology vendors to anticipate emerging threats and opportunities.

· Mentor and coach risk assessors and secondees through guidance, feedback, and knowledge sharing.

· Manage complex initiatives while simplifying outcomes to support effective delivery and execution.

Qualifications and Experience

· Minimum 15 years of experience within Cyber Security.

· At least 8 years of experience in a Governance, Risk and Compliance (GRC) or Risk Management function.

· Practical experience conducting technical risk assessments.

· Knowledge of industry frameworks and standards including ISO 27001, PCI-DSS, NIST, and enterprise security frameworks.

· Strong stakeholder engagement and communication skills with the ability to translate technical risks into business insights.

· Experience working within large and complex enterprise environments.

Highly Desirable

· Previous experience in a non-cyber risk or GRC role.

· Industry certifications such as CRISC, CISSP, CISM, or SABSA.

· Experience working within Agile and DevOps environments.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search