GRC & Compliance

GRC Consultant

Deliver ISO 27001, risk assessment and compliance programs for enterprise and government clients — from framework selection through audit.

The role

SPG's GRC practice helps organisations build governance, risk and compliance programs that stand up to audit and actually reduce risk. As a GRC Consultant you will work directly with client stakeholders across ISO 27001 implementation, risk assessments (ISO 27005, NIST 800-30), PCI-DSS compliance and policy development. You will also work with our Defend360 platform team to deliver continuous compliance monitoring for managed clients.

What you'll do

  • Deliver ISO 27001 implementation and gap assessment engagements
  • Facilitate risk assessments using ISO 27005 and NIST 800-30 methodologies
  • Develop policies, procedures and governance documentation tailored to each client
  • Support clients through internal and external audit processes
  • Advise on PCI-DSS, Essential Eight and IRAP requirements where relevant
  • Present findings and roadmaps to client executives and boards

What you'll bring

  • 3+ years in a GRC, information security or audit role
  • Working knowledge of ISO 27001, the NIST CSF and the Australian Government ISM
  • Excellent written communication — you can write a policy a CFO will actually read
  • Confidence facilitating workshops with technical and non-technical stakeholders
  • Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CISM or CRISC (or working toward them)

Nice to have

  • IRAP assessor experience or exposure
  • Essential Eight maturity assessments
  • Experience with GRC platforms and continuous compliance tooling