GRC Consultant
Deliver ISO 27001, risk assessment and compliance programs for enterprise and government clients — from framework selection through audit.
The role
SPG's GRC practice helps organisations build governance, risk and compliance programs that stand up to audit and actually reduce risk. As a GRC Consultant you will work directly with client stakeholders across ISO 27001 implementation, risk assessments (ISO 27005, NIST 800-30), PCI-DSS compliance and policy development. You will also work with our Defend360 platform team to deliver continuous compliance monitoring for managed clients.
What you'll do
- Deliver ISO 27001 implementation and gap assessment engagements
- Facilitate risk assessments using ISO 27005 and NIST 800-30 methodologies
- Develop policies, procedures and governance documentation tailored to each client
- Support clients through internal and external audit processes
- Advise on PCI-DSS, Essential Eight and IRAP requirements where relevant
- Present findings and roadmaps to client executives and boards
What you'll bring
- 3+ years in a GRC, information security or audit role
- Working knowledge of ISO 27001, the NIST CSF and the Australian Government ISM
- Excellent written communication — you can write a policy a CFO will actually read
- Confidence facilitating workshops with technical and non-technical stakeholders
- Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CISM or CRISC (or working toward them)
Nice to have
- IRAP assessor experience or exposure
- Essential Eight maturity assessments
- Experience with GRC platforms and continuous compliance tooling