Epicareer Might not Working Properly
Learn More

GRC Consultant/Senior Consultant

Salary undisclosed

Apply on


Original
Simplified

The Role (Consultant/Senior Consultant)

Our team is made up of Information Security professionals coming from all types of professional and personal backgrounds - we have a unique, international environment to grow in.

We offer benefits to help you in your career progression such as training and certification opportunities, flexible hours, a great workplace environment, and a culture focused on helping you become a T-shaped consultant while working in a technically strong, diverse team.

Our Strategy, Governance, Risk and Compliance Consultants work with key stakeholders to drive the design, development and implementation of strategies, policies and standards around cybersecurity. They help to ensure cybersecurity is aligned and supports the business objectives of the organisation.

Job Responsibility:

Formulate Information Security policies, procedures and standards;

Conduct cybersecurity gap and risk assessments; monitor compliance against policies and various industry and global standards; identify and assess information security risks; recommend and devise appropriate and effective risk treatment plans and mitigating controls;

Perform technical evaluation on IT systems across both cloud and traditional environments;

Plan and conduct IT Security awareness training for client’s employees and senior management;

Maintain and provide advisory support for clients in the management of information and technology risks;

Present and report on cybersecurity items to key organisational stakeholders;

Work closely with stakeholders to managing cybersecurity for the organisation;

Work on specific verticals such as IT Assurance and Audit, Technical Governance, and GRC Strategy;

A suitable candidate would have some or most of the following attributes:

3 or more years of working experience in Information Security, IT Risk Management or Controls, or GRC, or in IT Operations preferred.

Good with both business and technology stakeholders. Comfortable to report and present to both customer-facing and internal management.

Maturity in project and stakeholder management skills.

Team player and ability to work independently when the need arise.

An excellent communicator, with strong presentation and writing skills.

Strong understanding of PCI-DSS, ISO 27001 / 27002, NIST CSF, and relevant standards / regulations that impact cybersecurity;

Professional Industry / Cloud Certifications (e.g. CISSP, CISM, CISA, CIPP, CIPM, AWS/Azure/GCP certifications).

Experience in data privacy (Philippines Data Privacy Act, GDPR) is advantageous.

Experience in implementing/operating security products (e.g., Firewalls, PIAM, SIEM) is advantageous.

Working experience with SOC2 certification is advantageous.

What's in it for you?

Work in a dynamic and modern company with a great culture and great people;

Increased responsibilities in a client-facing role to boost your career. We will support you but not hide you behind a Managing or Principal Consultant;

Get exposure to a wide range of businesses across all industries;

Grow your skillset across the entire engagement lifecycle;

Flexible work arrangements when practical;

Training and certification opportunities;

Support for your charitable or technical causes you may lead outside or work;

Opportunities to travel

The Team

Our team is made up of Information Security professionals coming from all types of professional and personal backgrounds - we have a unique, international environment to grow in and believe in having fun at work. We offer benefits to help you in your career progression and in addition, we have training and certification opportunities, flexible hours, a great workplace environment, a culture focused on helping you become a balanced consultant while working in a technically strong and diverse team.

We have a fresh and direct approach to working with our clients, breaking away from the status quo - and we are well respected for that.

About Privasec

Privasec is an independent cybersecurity consulting firm and we have been operating for more than 7 years. We have offices located in 6 different cities in Australia, with 3 offices in South East Asia.

We offer Cybersecurity services ranging from Offensive Security to Strategy, Governance, Risk and Compliance services, including ISO27001 implementation and adoption of other International Standards for our clients. We are ISO27001 certified, CREST Accredited and a PCI QSA company. We are a registered Services supplier for both the Singapore Government as well as the Australian Government.