Senior Governance, Risk and Compliance Consultant
AU152333 SYDNEY (AU152333), Australia
Full Time Senior-level / Expert Clearance required AUD 88K - 164K * est.
Kyndryl
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day.Who We Are
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities.
The Role
As a Senior Governance, Risk and Compliance Consultant , your primary responsibility will be providing advisory services to Australian clients, guiding them in managing their cybersecurity risks and ensuring compliance with Australian regulations such as the APRA CPS230/234, SOCI, ESCO, Australian Privacy Principles (APPs), the Australian Cyber Security Centre (ACSC) guidelines, and NIST and ISO 27001 frameworks. You will conduct risk assessments, evaluate existing security programs, and help design and implement effective security governance, risk management, and compliance frameworks. In this role, you will also assist clients in meeting the compliance requirements of the Notifiable Data Breaches (NDB) scheme and help develop and refine their incident response plans. You will work alongside executive teams to develop security strategies, ensure alignment with business goals, and ensure the confidentiality, integrity, and availability of business-critical data.
Collaboration will be your forte, as you work closely with clients to understand their unique security requirements and assess their current security posture. Armed with this knowledge, you'll provide expert guidance and recommendations on the best security practices, risk management strategies, and robust security policies that will fortify their defenses.
You won't stop at providing advice; you'll roll up your sleeves and get hands-on. Designing and implementing security controls, policies, and procedures will be your playground. You'll work alongside cross-functional teams to deploy state-of-the-art technologies, including firewalls, intrusion detection/prevention systems, access controls, and encryption technologies, ensuring a comprehensive security framework.
The thrill of uncovering vulnerabilities and risks is what motivates you. Armed with your extensive knowledge, you'll conduct thorough security assessments, leaving no stone unturned in identifying potential security breaches. Your findings will serve as the foundation for meticulous security audits and reviews, ensuring adherence to policies and procedures. Your reports and findings will be the catalyst for management decisions and actions.
In the fast-paced world of cybersecurity, staying ahead of the game is crucial. That's why you'll continuously immerse yourself in the latest security threats, technologies, and best practices. Your recommendations will drive enhancements to the organization's security posture, ensuring it remains at the cutting edge of defense.
Your influence won't be limited to systems alone. You'll lend your expertise to the design and review of IT infrastructure, systems, and applications, ensuring they are secure by design from inception.
Not only will you make an impact within our organization, but you'll also collaborate with customers and vendors on security assessments, audits, and due diligence activities. Your knowledge and experience will be instrumental in shaping secure collaborations and partnerships.
Our consultants are restless for innovation. They are at the edge of technology, changing the way our customers implement business solutions – so, if you’re a problem-solver, an innovative thinker, and a self-starter with a passion high impact assignments which align technology to business outcomes, then we want to hear from you! Apply today to join our team that has a host of exciting projects and customers waiting for you to work with them to solve complex transformation puzzles through technology.
Your Future at Kyndryl
As a Security Consultant at Kyndryl you will join the Kyndryl Consultant Profession, working with other Kyndryl Consultants, Architects, Project Managers, and cross-functional Technical Subject Matter Experts – presenting unlimited opportunities with unmatched support through our investment in your learning, training, and career growth
Who You Are
You’re good at what you do and possess the required experience to prove it. However, equally as important – you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused – someone who prioritizes customer success in their work. And finally, you’re open and borderless – naturally inclusive in how you work with others.
Required Skills:
· Expertise in Australian regulatory frameworks such as APRA CPS230/234, SOCI, ESCO, VPDSS, IS18, Australian Privacy Principles (APPs) and the Australian Cyber Security Centre (ACSC) guidelines.
· In-depth understanding of Australian laws such as the Privacy Act 1988, Notifiable Data Breaches (NDB), and Critical Infrastructure Bill.
· Ability to apply industry frameworks like NIST Cybersecurity Framework (CSF), ISO 27001 and CIS Controls within the Australian context.
· Experience with government and industry certifications, such as IRAP (Information Security Registered Assessors Program).
· Expertise in conducting risk assessments and audits in accordance with local regulatory requirements and frameworks.
· Excellent written and verbal communication skills for creating documentation, presenting findings, and advising clients at the C-suite level.
· Strong stakeholder management capabilities, especially when liaising with senior management and government entities in the Australian market.
Required Experience
· At least 7-10 years of experience in GRC, with a strong emphasis on CISO consulting services in the Australian market.
· Proven experience in advising Australian enterprises, government agencies, or large-scale private sector organisations on regulatory compliance and risk management.
· Familiarity with Australia’s Critical Infrastructure Risk Management practices, Cyber Security Strategy 2020-2030, and other national frameworks.
· A strong track record of managing complex, enterprise-level cybersecurity and compliance projects within Australia.
· Experience in leading GRC-related initiatives and working in a consultancy environment, specifically in Australia.
· Certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Auditor are highly desirable.
Australian Citizen with the ability to obtain AGSVA security clearance.
Being You
Diversity is a whole lot more than what we look like or where we come from, it’s how we think and who we are. We welcome people of all cultures, backgrounds, and experiences. But we’re not doing it single-handily: Our Kyndryl Inclusion Networks are only one of many ways we create a workplace where all Kyndryls can find and provide support and advice. This dedication to welcoming everyone into our company means that Kyndryl gives you – and everyone next to you – the ability to bring your whole self to work, individually and collectively, and support the activation of our equitable culture. That’s the Kyndryl Way.
What You Can Expect
With state-of-the-art resources and Fortune 100 clients, every day is an opportunity to innovate, build new capabilities, new relationships, new processes, and new value. Kyndryl cares about your well-being and prides itself on offering benefits that give you choice, reflect the diversity of our employees and support you and your family through the moments that matter – wherever you are in your life journey. Our employee learning programs give you access to the best learning in the industry to receive certifications, including Microsoft, Google, Amazon, Skillsoft, and many more. Through our company-wide volunteering and giving platform, you can donate, start fundraisers, volunteer, and search over 2 million non-profit organizations. At Kyndryl, we invest heavily in you, we want you to succeed so that together, we will all succeed.
Get Referred!
If you know someone that works at Kyndryl, when asked ‘How Did You Hear About Us’ during the application process, select ‘Employee Referral’ and enter your contact's Kyndryl email address.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits C CISA CISM CISO CISSP Clearance Compliance Encryption Firewalls Governance Incident response Intrusion detection ISO 27001 IT infrastructure NIST Privacy Risk assessment Risk management Security assessment Security Clearance Security strategy Strategy Vulnerabilities
Perks/benefits: Career development Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.