(Immediate Start) Cybersecurity GRC Consultant

19 hours ago


City of Melbourne, Australia Triskele Labs Full time

Overview

Triskele Labs are one of the leading providers of cybersecurity services in Australia. We assist clients to reduce their risk of a cyber compromise through the delivery of risk-considered controls.

Triskele Labs are one of the last remaining boutiques in Australia. We are currently the largest CREST Registered Penetration Testing company in Melbourne and one of the only boutiques to run a 24x7x365 Security Operations Team completely onshore.

Are you looking to work in cybersecurity consulting where real impact matters more than ticking boxes? Triskele Labs is seeking a Cybersecurity GRC Consultant to join our growing Advisory team in Melbourne.

In this hybrid client-facing role, you’ll work across industries to deliver clear, practical security assessments that help organisations meaningfully reduce risk. You’ll support implementation and uplift efforts aligned to frameworks like ISO 27001, NIST CSF, and the Essential Eight, working closely with both technical and non-technical stakeholders to drive change where it matters most.

We’re looking for someone who brings both security expertise and a questioning mindset — someone who is comfortable challenging assumptions, validating controls, and helping our clients cut through complexity. You’ll also have the opportunity to collaborate with other internal teams across offensive security, DFIR, and detection and response.

If you want to grow your GRC career in a role where the work is valued, varied, and grounded in the real world, this could be the perfect fit.

Key Responsibilities

- Conduct cybersecurity risk assessments aligned to ISO 27001, NIST CSF, Essential Eight and related frameworks
- Perform gap assessments and control maturity reviews for regulatory, compliance, and best-practice purposes
- Support the development and implementation of Information Security Management Systems (ISMS)
- Create board and executive-level reporting to communicate cyber risks and prioritise remediation
- Facilitate workshops and lead conversations with stakeholders across technical and business functions
- Work closely with internal experts in SOC, red teaming, and DFIR to ground recommendations in operational realities
- Build lasting relationships with clients and support them throughout their cyber maturity journey

Experience & Skills

- 2–4 years of experience in cybersecurity GRC, ideally across multiple sectors or clients
- Practical knowledge of ISO 27001, NIST CSF, and Essential Eight
- Experience conducting risk assessments and drafting core security documentation (e.g., risk registers, policies, reports)
- Strong communication and engagement skills with business and technical audiences
- A proactive, consultative approach to understanding and validating control environments
- Technical awareness of security operations and engineering concepts
- Willingness to learn, take initiative, and own deliverables in a collaborative team setting

Certifications

Required:

- ISO 27001 Lead Implementor or Auditor
- One or more of the following: CISSP, CISM, CISA (or working towards)

Preferred:

- SABSA or CRISC
- ITIL Foundations
- Additional governance or cloud-related security certifications

What We Look For

- Excellent written and verbal communication
- Strong attention to detail and structured thinking
- Ability to balance autonomy with teamwork in a fast-paced environment
- A genuine interest in helping organisations improve their security maturity
- Client-first mindset with professional integrity

KPI's

- Timely, high-quality delivery of client engagements
- Positive stakeholder feedback and repeat client engagements
- Development and contribution to internal documentation and toolkits
- 75–80% billable utilisation
- Active engagement in professional development

Reporting Line

Reports to: Senior GRC Consultant

Works with: Advisory team, technical practices, and clients

Team culture and benefits

Team culture is everything to Triskele Labs and it is the reason we exist. We are a forward-thinking company and always looking for ways to boost our team culture to ensure we are a destination employer. We continually undertake surveys to seek feedback from our team on ways we can improve our work environment and team member experience at Triskele Labs.

We provide our team a great range of additional benefits such as:

- Hybrid Flexibility: Work two days per week from our Melbourne CBD office, and remotely the rest of the week (subject to client needs)
- Varied Client Engagements: Collaborate with organisations of all sizes, across industries and maturity levels
- Career Development: Access ongoing mentorship, structured training pathways, and certification support
- Real-World Cybersecurity Exposure: Collaborate with our internal red team, SOC, and incident response units to deepen your practical understanding
- People & Culture: Participate in team events, offsites, and connection initiatives run by our dedicated People & Culture team

If you’ve made it this far, there’s a good chance you’re who we’re looking for

At Triskele Labs, we value initiative and attention to detail—so please include a cover letter addressed to Rob Barry, Chief Operating Officer, with your application. Applications without a cover letter will not be progressed.

Working Arrangements

The role is full time, Monday to Friday in our Collins St Melbourne office, with hybrid working arrangements: two days in-office, three days remote (client needs may vary). Occasional interstate travel may be required.

#J-18808-Ljbffr



  • Melbourne, Australia Triskele Labs Full time

    Triskele Labs are one of the leading providers of cybersecurity services in Australia. We assist clients to reduce their risk of a cyber compromise through the delivery of risk-considered controls. Triskele Labs are one of the last remaining boutiques in Australia. We are currently the largest CREST Registered Penetration Testing company in Melbourne and...


  • Melbourne, Australia Triskele Labs Full time

    Triskele Labs is a cybersecurity company focused on real outcomes, not just theoretical frameworks. Our Governance, Risk and Compliance (GRC) team partners with organisations to assess risk, improve security maturity, and build practical, evidence-based programs that work in real environments. We are looking for an Associate Cybersecurity GRC Consultant to...


  • Melbourne, Australia Triskele Labs Full time

    At Triskele Labs, we believe cybersecurity should be built on practical experience, not just theory. We work with organisations to improve their cyber maturity through realistic, evidence-based advisory services that align with risk, regulation, and business priorities. We are now seeking a Head of Cybersecurity GRC to lead and grow our Governance, Risk and...


  • Melbourne, Australia Triskele Labs Global Pty Full time

    Triskele Labs are one of the leading providers of cybersecurity services in Australia. We assist clients to reduce their risk of a cyber compromise through the delivery of risk-considered controls. Triskele Labs are one of the last remaining boutiques in Australia. We are currently the largest CREST Registered Penetration Testing company in Melbourne and...


  • City of Brisbane, Australia InfoTrust Co. Full time

    Spirit Managed Services is now branded Infotrust. SOCEmergency Number: 1300 554 798 GRC Security Consultant Brisbane, QLD Home Careers GRC Security Consultant Let’s Get STARTED CONTACTUS CALLUS The Security Consultant will work with the wider Consulting team, responsible for the development and delivery of Governance, Risk and Compliance services....

  • Senior GRC Consultant

    2 weeks ago


    Greater Melbourne Area, Australia Sekuro Full time $120,000 - $150,000 per year

    About Us:AtSekuro, we're redefining how organisations approach cybersecurity. As a trusted partner to some of Australia's leading enterprises, we combine innovation, deep expertise, and collaboration to deliver outcomes that matter. Our people are our strength — passionate, curious, and driven to make an impact. If you're looking to join a company that's...


  • Council of the City of Sydney, Australia ROBERT WALTERS AUSTRALIA Full time

    Prior consulting experience is highly regarded. Recent experience across ISM/Essential 8, NIST, and ISO27001 is a must. Responsibilities: - Develop and implement solutions to reduce cybersecurity risks across networks and systems - Interpret and apply security controls from government and industry frameworks, such as ISM (Information Security Manual) and...


  • Melbourne, Victoria, Australia Aurec Full time $104,000 - $130,878 per year

    Cyber Security GRC Consultant6 month contractMelbourne CBDHybridCritical role responsible for driving key cybersecurity initiatives and supporting strategic decision making. You will be a key contributor to the organisation's cyber resilience, working to uplift security maturity, develop critical documentation, and shape future policy. This is a unique...


  • City of Melbourne, Australia Consultant Full time

    ClearPlan is hiring consulting positions nationwide. Founded in 2013, we have grown to more than 200 employees operating in over 30 states, providing Project Management Service Professionals to industries focused on Aerospace and Defense, Energy, Construction, and Healthcare/IT. Join a team that was just recertified as a Great Places to Work 2021, 2022,...

  • Grc Consultant

    1 week ago


    Melbourne, Australia Aurec Full time

    **GRC Consultant** GRC Consultant job in Melbourne. One of Australia's leading manufacturing organisations is looking for a talented GRC Consultant to join their growing team in Melbourne. It is a 12-month contract with extensions Are you looking for your next role? My client's primary focus is to deliver smart solutions and strengthen our communities....