Cybersecurity Grc Specialist

3 days ago


Melbourne, Victoria, Australia Thales Full time

We're inventing the future, right here, right now, at Thales. We design the critical security solutions of tomorrow by combining the curiosity to explore, the intelligence to question and the vision to create. Together we solve complicated problems by combining our experience in the market with our leading research and development capabilities.

**About Your Role**:
**The Cybersecurity GRC Specialist will execute cybersecurity activities with a focus on cyber governance, risk, and compliance, to achieve a full Secure by Design lifecycle for the customer, and support the security objective of system accreditation.**:
**The main activities of the role**:

- **Develop the Statement of Applicability (SOA) to contain the derived system security requirements and support each of the sub-system engineering streams to embed the Security functional requirements in their product selection, design work and testing activities.**:

- **Analyse the ISM, PSPF and all applicable policies and standards to identify all relevant Security Engineering requirements to be captured in the SOA and forms the basis of the System Requirements Specifications (SRS).**:

- **Work closely with the lead engineers in every subsystem, to provide security guidance and ensure system security requirements are being implemented as per the ISM intent, are addressed in each of their system designs and solutions.**:

- **Contribute to the System Security Plan (SSP) of the subsystems' security design and solution and the functional security requirements.**:

- **Identification and assessment of the security risks, to be documented in the Security Risk Management Plan (SRMP) as well as proposing mitigation options to address them.**:

- **Contribute to test strategy and development of the detailed test procedures to achieve effective and re-usable testing methods for the verification of the security requirements for security accreditation.**:

- **Contribute to the preparation activities identified for the Security Engineering activities at each of the project reviews (SRR, IBR, CDR, C/DRR, IRD, ESV and SAT).**:

- **Support the development of security artefacts necessary to achieve the Security Accreditation of the system and support (Development and Test) system(s).**:

- **Support and contribute to the V&V testing activities across the range of subsystem engineering teams.**:

- **Facilitate the IRAP assessor engagement by assisting with the audit and review activities.**:

- **Engage and coordinate penetration testing activities, including the preparation of the activities, organisation of the facilities and system access.**:

- **Track and report remediation activities and effort.**:

- **Provide cybersecurity engineering support during the Operate and Maintain phase of the project, up to the system-of-system level.**:

- **Optimise processes and work activities, focusing on the efficiency of project execution (structure, roles, interfaces, artefacts, template, re-use. coordination).**:

- **Identify and review security risks and issues, and propose effective solutions; execute agreed mitigation actions and report on outcomes or cost savings and residual risks.**:
**How About You?**:

- **A tertiary qualification in Engineering, Computer Science, IT or other relevant qualification with a focus on cybersecurity, or can demonstrate a high level of competence through career experience and self-study**:

- **Demonstrated knowledge of the engineering life cycle, from concept design, requirements capture and management, system and subsystem design, system integration through to test strategies, acceptance and support phase.**:

- **Experience working in multi-skilled engineering teams within a matrix environment.**:

- **Strong appreciation and adherence to security engineering processes, and high-quality delivery.**:

- **Demonstrated ability to analyse and solve problems, working with a range of colleagues and stakeholders in a project context.**:

- **Proficient knowledge and use of DOORS.**:

- **Advanced knowledge of ISM, PSPF and NIST standards**:
**Good to Know**:
**Prior to offer you'll complete a pre-employment police and medical check.**:
Wellbeing matters at Thales, and where possible we encourage flexible working.



  • Melbourne, Victoria, Australia beBeeCybersecurity Full time $130,000 - $180,000

    Protect Critical Infrastructure from Cyber ThreatsAbout the RoleDevelop and implement cybersecurity policies, standards, and procedures to safeguard critical infrastructure.Support internal and external audits with expert recommendations to address cyber risks and compliance gaps.Conduct cybersecurity maturity assessments and identify areas for improvement...


  • Melbourne, Victoria, Australia Triskele Labs Full time

    At Triskele Labs, we believe cybersecurity should be built on practical experience, not just theory. We work with organisations to improve their cyber maturity through realistic, evidence-based advisory services that align with risk, regulation, and business priorities.We are now seeking a Head of Cybersecurity GRC to lead and grow our Governance, Risk and...


  • Melbourne, Victoria, Australia Triskele Labs Full time $150,000 - $200,000 per year

    At Triskele Labs, we believe cybersecurity should be built on practical experience, not just theory. We work with organisations to improve their cyber maturity through realistic, evidence-based advisory services that align with risk, regulation, and business priorities. We are now seeking a Head of Cybersecurity GRC to lead and grow our Governance, Risk and...


  • Melbourne, Victoria, Australia Triskele Labs Full time

    Overview Triskele Labs are one of the leading providers of cybersecurity services in Australia.We assist clients to reduce their risk of a cyber compromise through the delivery of risk-considered controls.Triskele Labs are one of the last remaining boutiques in Australia.We are currently the largest CREST Registered Penetration Testing company in Melbourne...


  • Melbourne, Victoria, Australia Triskele Labs Global Pty Full time

    Triskele Labs are one of the leading providers of cybersecurity services in Australia.We assist clients to reduce their risk of a cyber compromise through the delivery of risk-considered controls.Triskele Labs are one of the last remaining boutiques in Australia.We are currently the largest CREST Registered Penetration Testing company in Melbourne and one of...


  • Melbourne, Victoria, Australia Triskele Labs Global Pty Full time

    Triskele Labs are one of the leading providers of cybersecurity services in Australia.We assist clients to reduce their risk of a cyber compromise through the delivery of risk-considered controls.Triskele Labs are one of the last remaining boutiques in Australia.We are currently the largest CREST Registered Penetration Testing company in Melbourne and one of...


  • Melbourne, Victoria, Australia Triskele Labs Full time

    Join to apply for the Cybersecurity GRC Consultant role at Triskele Labs13 hours ago Be among the first 25 applicants Join to apply for the Cybersecurity GRC Consultant role at Triskele Labs Get AI-powered advice on this job and more exclusive features.Triskele Labs are one of the leading providers of cybersecurity services in Australia.We assist clients to...


  • Melbourne, Victoria, Australia Triskele Labs Full time

    Triskele Labs is a cybersecurity company focused on real outcomes, not just theoretical frameworks. Our Governance, Risk and Compliance (GRC) team partners with organisations to assess risk, improve security maturity, and build practical, evidence-based programs that work in real environments.We are looking for an Associate Cybersecurity GRC Consultant to...


  • Melbourne, Victoria, Australia Triskele Labs Full time

    OverviewTriskele Labs are one of the leading providers of cybersecurity services in Australia. We assist clients to reduce their risk of a cyber compromise through the delivery of risk-considered controls.Triskele Labs are one of the last remaining boutiques in Australia. We are currently the largest CREST Registered Penetration Testing company in Melbourne...


  • Melbourne, Victoria, Australia Triskele Labs Full time $90,000 - $120,000 per year

    Triskele Labs are one of the leading providers of cybersecurity services in Australia. We assist clients to reduce their risk of a cyber compromise through the delivery of risk-considered controls.Triskele Labs are one of the last remaining boutiques in Australia. We are currently the largest CREST Registered Penetration Testing company in Melbourne and one...