You are a cyber security professional with experience in risk assessments, controls assurance, compliance and governance. You have a good understanding of cyber security control frameworks, in particular the SCF framework, compliance requirements and security best practices, and enjoy analysing complex environments to identify control gaps and opportunities for improvement.
You combine strong analytical and problem-solving skills with excellent communication and stakeholder engagement capabilities. You are detail-oriented, collaborative and proactive, with the ability to translate technical findings into practical recommendations that support business and security objectives. You are also committed to continuous learning and staying informed about emerging threats, technologies and regulatory developments.
• Tertiary qualification in Information Technology, Cyber Security, Risk Management or a related field. Certifications such as CRISC, CISM or ISO 27001 are highly desirable.
• 3+ years’ experience in cyber security, governance, risk management or compliance-related roles.
• Experience assessing and validating cyber security controls and supporting controls assurance activities.
• Knowledge of cyber security frameworks and standards including SCF, NIST Cybersecurity Framework, NIST SP 800-53 and CIS Controls.
• Experience with control testing, evidence review, gap analysis and remediation tracking.
• Understanding of continuous control monitoring, compliance reporting and security assurance practices.
• Strong analytical, problem-solving and risk assessment capabilities.
• Excellent written and verbal communication skills with the ability to engage technical and non-technical stakeholders.
• Strong documentation and reporting skills with exceptional attention to detail.
• Proven ability to collaborate effectively across teams and contribute to organisation-wide cyber security and governance initiatives.