Principal Consultant, Internal Governance, Risk and Compliance
7 days ago
As Head of Governance, Risk and Compliance, you will be the most senior specialist in Nexon's Cyber Compliance and Strategy team and the primary owner of our enterprise-wide Governance, Risk and Compliance (GRC) programme. You will form a key part of the Cybersecurity Centre of Excellence, under the CISO. This is a strategic, individual-contributor leadership position that carries significant influence across the organisation. You will drive the continual maturation of Nexon's internal GRC capabilities, translating complex regulatory obligations into operational excellence and measurable business value. The role is 100% internally focused - there are no client-facing consulting, delivery, or sales-support responsibilities.
Key Responsibilities
Lead and Deliver Internal GRC Initiatives
- Conduct comprehensive risk assessments, maturity and gap analyses, and develop practical, prioritised roadmaps and policies aligned with Australian regulations (including the SOCI Act, Privacy Act, APRA CPS 234, and ASD Essential Eight) and international standards (NIST CSF, ISO
- Facilitate internal control and compliance audits, driving sustained regulatory compliance, operational resilience, and continuous improvement of our security posture, liasing with compliance, penetration testing, and external partners to validate our posture.
- Perform rigorous security control and technical architecture reviews, benchmarking against recognised frameworks.
- Deliver clear, business-focused recommendations to remediate identified gaps and elevate Nexon's overall security posture.
- Translate complex technical risks into straightforward business impacts for senior stakeholders and the executive team.
Chair the Governance, Risk and Compliance Committee (GRC-C)
- Operationalise the cyber security strategy by translating executive direction into actionable policies, standards, controls, and risk treatment plans.
- Prepare and present high-quality reporting to the Cyber Executive Steering Committee and other governance bodies.
Develop and Manage Internal GRC Programmes
- Continuously build, refine, and mature Nexon's internal GRC frameworks, incorporating proactive risk management, policy enforcement, regulatory compliance monitoring, and improvement activities.
- Ensure operational processes remain fully aligned with legislative requirements and industry-leading practices, reinforcing Nexon's position as a trusted managed service provider.
- Provide expert guidance and reusable patterns to operational and technical teams responsible for implementing and monitoring controls.
- Serve as a standing member or chair of relevant security and risk committees.
Mentorship and Organisational Leadership
- Mentor and coach junior members of the cyber risk and compliance team, fostering a culture of high performance, knowledge sharing, and continuous learning.
- Design and deliver internal training and upskilling programmes that support our goal of maintaining Australia's strongest cybersecurity capability.
- Exercise enterprise-wide leadership by advising teams and steering the organisation toward high-quality, risk-aligned solutions.
Internal Enablement and Thought Leadership
- Design and facilitate internal workshops, compliance briefings, and executive advisory sessions that strengthen security awareness, advance GRC maturity, and embed a risk-first, human-centric security culture.
- Contribute internal thought leadership through published content, strategic roadmaps, and executive-level briefings.
Strategic Planning and Continuous Evolution
- Develop and maintain cybersecurity strategies and governance frameworks that align with business objectives and regulatory requirements.
- Create, review, and enforce cybersecurity policies and standards, ensuring they are clearly communicated and understood across the organisation.
- Support technical owners in developing detailed technical standards that enable policy compliance.
- Monitor the effectiveness of security controls, identify enhancement opportunities, and drive changes in response to emerging threats and regulatory developments.
Our Ideal Candidate
- At least five years of demonstrated success leading complex security and compliance programmes across diverse industry sectors.
- Deep expertise in Australian regulatory environments (SOCI Act, Privacy Act, APRA CPS 234, Essential Eight, etc.), risk management practices, and recognised security frameworks (ISO 27001, NIST CSF, ISM, CIS Controls).
- Proven ability to build trusted relationships with senior executives and translate technical risk into clear business impact.
- Strong leadership and mentoring skills with a genuine passion for developing people and organisational capability.
- Experience designing scalable security architectures, processes, and governance models in a managed-service or enterprise environment.
- Excellent analytical, problem-solving, and communication skills, with the ability to convey complex concepts to both technical and non-technical audiences.
- Industry-recognised certifications such as CISSP, CISM, CRISC, SABSA, GIAC, or equivalent are highly regarded.
-
Principal Solicitor
2 weeks ago
Brisbane, Queensland, Australia Compliance & Risk Management Recruitment Full timePrincipal Lawyer – Brisbane - Remote Based RoleLead, grow, and thrive in a family-oriented practice with national backing Are you an experienced family lawyer ready to step into a Principal role where you can lead, grow, and shape the future of a practice – without the burden of running your own firm alone? This is your chance to join a firm that blends...
-
Principal Consultant
1 week ago
Brisbane, Queensland, Australia SourceIn Full timePrincipal Consultant / Principal Engineer Location: Australia (Hybrid / Flexible)Type: Full-timeLevel: Principal (10+ years experience) The OpportunityWe are seeking a Principal Consultant/Principal Engineer to serve as the primary technical authority and trusted advisor for complex, high-impact client engagements within large, regulated...
-
Principal Risk and Compliance Officer
2 days ago
South Brisbane, Queensland, Australia Metro South Health Full timeLead Enterprise-Wide Risk and Compliance in a Complex Health EnvironmentDrive robust, transparent and sustainable risk and compliance outcomes across a large, multidisciplinary health service. Partnering closely with clinical governance and state-wide stakeholders, this role ensures accurate, timely and insightful risk and compliance reporting to Executive...
-
Principal Project Officer
2 days ago
Brisbane, Queensland, Australia Department of Families, Seniors, Disability Services and Child Safety Full timeThe Principal Project Officer is a key position of the Governance and Risk team within Corporate Services. The team is responsible for providing leadership and high-level advice, expertise and technical support to senior management and stakeholders across the department, liaise with internal and external agencies, on a wide range of Governance and Risk...
-
Principal Adviser Governance
7 days ago
Brisbane, Queensland, Australia Queensland Corrective Services Full timeRoleQueensland Corrective Services invites applications for the position of Principal Adviser, Governance (AO7), based in Brisbane. This role is pivotal in developing and implementing robust governance frameworks, ensuring compliance with regulatory obligations, and providing strategic advice to senior leadership. The successful candidate will...
-
Principal Project Officer
2 days ago
Brisbane, Queensland, Australia Queensland Government Full timeThe Governance and Risk team (GR), within Corporate Services, has a purpose of coordinating centralised corporate governance and risk management for the department and operates within the external expectations of the Performance Management Framework and the Queensland Public Sector Strategic Management Planner.In keeping with the Financial Accountability Act...
-
Principal Governance and Board Officer
5 days ago
Brisbane, Queensland, Australia Queensland Government Full timeAct boldly with purpose | Pave the way, together | Be curious, be connectedEDQ is seeking an experienced Principal Governance and Board Officer (AO7) to support the effective operation of the Economic Development Board and its Committees.About EDQWe are invested in our people: At EDQ, we know that they are the key to achieving our vision for Queensland. We...
-
Principal Adviser Governance
7 days ago
Brisbane, Queensland, Australia Queensland Government Full time**Queensland Corrective Services (QCS) is seeking an accomplished professional to join our Corporate Governance and Risk Group as Principal Adviser, Governance (AO7). This pivotal role offers the opportunity to contribute to the safety and wellbeing of Queensland communities by shaping and strengthening governance practices within a dynamic public sector...
-
Risk and Compliance Lawyer
1 week ago
Brisbane, Queensland, Australia McCullough Robertson Full timeGood people. Good work. Great opportunities.McCullough Robertson is a commercially focused firm, working with high-calibre national and international clients. We work on big matters in small teams, approaching each day with dedication and professionalism.We provide exceptional opportunities for our employees to perform, grow and succeed, through extensive...
-
Brisbane, Queensland, Australia Queensland Department of Education Full timeThe Department of Education is committed to the health, safety and wellbeing of our employees, students and everyone involved in our schools and workplaces. With over 98,000 employees and approximately 1265 schools, creating safe and healthy work environments requires shared responsibility and active participation across the department.We are seeking to fill...