GRC Consultant
Employee Perk
Work from a light filled, modern office.
Employee Perk
Company celebrations at half and full year.
Employee Perk
Complimentary snacks, drinks, and ham & cheese toasties.
Employee Perk
Office is close to North Sydney public transport.
Employee Perk
Nice people in a growing business.
Careers in Cyber Security with Insicon Cyber
Cybersecurity affects every organisation, every board, and every person whose data sits inside a system someone else is responsible for protecting. That is not a small thing. And the people doing the work to make organisations genuinely safer deserve to do it somewhere that takes both the work and the people seriously.
That is what we have tried to build at Insicon Cyber.
Founded in 2013, we are a specialist cybersecurity advisory and managed services firm working with mid-market organisations across Australia and New Zealand. Our clients operate in financial services, aged care, healthcare, and government. The stakes are real. The problems are complex. And the work we do alongside our clients has direct consequences for the people and communities they serve.
We have built a practice that spans board advisory, fractional CISO leadership, managed compliance, AI security and governance, and 24/7 managed security operations. That breadth means our team works across genuinely varied challenges, not just one narrow slice of the security stack.
We are growing across Australia and New Zealand. If you want to work in a team where your thinking is valued, your development is taken seriously, and the work you do actually matters to the organisations relying on you, we would like to hear from you.
Insicon Cyber is only able to accept applications from individuals with the right to work in Australia.
Job Brief - GRC Consultants
We're seeking passionate GRC Consultants to join our growing team and help Australian businesses strengthen their cybersecurity posture while maintaining regulatory compliance. This is your chance to work with some of the country's most forward-thinking organisations, delivering practical solutions that make a real difference to their risk management capabilities.
Role Purpose:
GRC Consultants at Insicon serve as trusted cybersecurity advisors who bridges the gap between complex technical security requirements and executive business decision-making.
Core Mission: Help Australian business leaders understand, implement, and maintain robust cybersecurity governance frameworks that protect their organisations while ensuring regulatory compliance.
Key Focus Areas:
- Executive Advisory - Translate cybersecurity risks into business language for C-suite and board consumption
- Regulatory Compliance - Guide organisations through Australian cybersecurity regulations and industry frameworks
- Risk Management - Implement practical governance structures that align security initiatives with business objectives
- Strategic Implementation - Lead the deployment of internationally recognised frameworks (ISO 27001, IRAP/ISM, SOC 2, NIST, CSF, Essential Eight) tailored to Australian business contexts
Ultimate Goal: Empower Australian enterprises to confidently navigate their digital transformation by making cybersecurity governance accessible, actionable, and strategically aligned with business success.
Duties and Responsibilities:
- Deliver your engagements autonomously and ensure clients experience high professionalism, care, ownership, and punctuality.
- Manage and resolve delivery escalation whilst ensuring the best customer experience possible.
- Attend industry events regularly to learn, earmark potential recruits, network and generate interest.
- Write and QA reports and material as required or assigned to you.
Qualifications:
- 3-5 years of hands-on GRC experience, ideally within consulting, financial services, government, or large enterprise environments
- Proven track record delivering cybersecurity governance and compliance projects in Australian regulatory contexts
- Strong understanding of Australian privacy legislation, government security frameworks, and industry-specific compliance requirements
- Experience with risk assessment methodologies and governance framework implementations
Technical Capabilities:
- Deep knowledge of cybersecurity frameworks (ISO 27001, NIST, Essential Eight, COBIT)
- Understanding of Australian regulatory landscape including APRA, ACCC, OAIC requirements
- Experience with GRC tools and platforms
- Familiarity with cloud security governance and emerging technology risk management
Professional Qualifications:
- Relevant industry certifications strongly preferred: CISSP, CISM, ISO 27001 Lead Auditor/Implementer, CRISC, or CGRC
- Bachelor's degree in Information Security, Business, Risk Management, or related field
- Eligibility for Australian security clearances (beneficial for government work)
- Valid Australian working rights and current driver’s licence.
What we offer:
- Nice, modern and bright offices close to transport in North Sydney.
- Complimentary snacks, drinks, and ham & cheese toasties!
- Company celebrations at half and full year.
- Nice people in a growing business.