Consultant - Cyber Risk Consulting
Indexed description
As a Consultant, you will support clients to improve cyber resilience by assessing cyber risk, strengthening governance and controls, supporting incident readiness, and advising on practical risk management improvements. You will work closely with senior consultants and client stakeholders across a range of industries, translating technical cyber issues into clear business advice and helping deliver high-quality consulting outputs.
We will count on you to:
- Support delivery of cyber risk consulting engagements, including cyber risk assessments, maturity reviews, control reviews, incident response readiness, and tabletop exercises.
- Assess cyber security risks, vulnerabilities, impacts, and control gaps across people, process, technology, and third-party environments.
- Assist in preparing incident response plans, playbooks, and board- or executive-level workshop materials.
- Contribute to client advisory work on cyber governance, policies, security frameworks, and resilience uplift roadmaps.
- Review and analyse security controls against relevant frameworks and standards such as ISO 27001, NIST, CPS 234, and ASD Essential Eight.
- Support the evaluation of security technologies, vendors, and implementation approaches that improve client security posture.
- Help quantify cyber risk and communicate findings in a way that supports decision-making and investment prioritisation.
- Build strong client and internal relationships, support business development activities, and contribute to proposals, thought leadership, and marketing initiatives.
- Work collaboratively with senior team members and provide guidance to junior colleagues where appropriate.
- 2–4 years of experience in cyber security, cyber risk, technology risk, or a related consulting role.
- Experience in risk assessments, security reviews, incident response planning, and/or cyber resilience work.
- Sound understanding of key cyber security concepts, frameworks, and control domains, including governance, vulnerability management, identity and access management, cloud security, and third-party risk.
- Strong written and verbal communication skills, including the ability to explain technical matters to non-technical audiences.
- Strong analytical, problem-solving, and stakeholder management skills.
- Knowledge of and experience working with frameworks and standards such as ISO 27001, NIST, CPS 234, and ASD Essential Eight.
- Professional certifications such as CISM, CISSP, CRISC, CISA, or equivalent.
- Ability to manage competing priorities, work well in a team, and operate effectively in a client-facing environment.
- Commercial awareness and an interest in developing advisory and consulting skills.
- We help you be your best through professional development opportunities, interesting work and supportive leaders.
- We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients and communities.
- Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.
Marsh is committed to creating a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age, background, disability, ethnic origin, family duties, gender orientation or expression, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law. Applications will only be considered from candidates who have the appropriate approval to work in Australia. Successful applicants will be required to complete a Criminal & Bankruptcy check prior to commencing of employment.
Marsh is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person.
R_362266
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search