Haystack
← Back to Jobs
Full time
Technology
NG

Senior Security Consultant

NCC GroupSydney, New South Wales🇦🇺AustraliaPosted 19 Jul 2026

Why This Role Stands Out

Elevate your career by becoming a trusted advisor to organizations, helping them navigate complex cyber threats and strengthen their security postures with high-impact consulting. This hybrid role offers significant growth potential for seasoned security professionals who excel at strategic advisory and stakeholder engagement, allowing you to make a tangible difference within a reputable global firm.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Sydney, New South Wales, Australia
PCI DSSSOC 2GDPRStakeholder Management

Job Description

Senior Security Consultant

Department: Cyber Services and Capabilities

Employment Type: Full Time

Location: AUS Sydney Clarence Street

Description

Position Title: Senior Consultant

Location: Sydney

Role Purpose: Do you enjoy helping organisations understand, secure, and strengthen their cyber security postures against modern security threats? At NCC Group, you'll help clients manage their cyber security risks across all environments and multiple business sectors.

Our Senior Cyber Security Consultants play a key client facing role, providing expert cybersecurity advisory services to multiple clients across industries. This position focuses on delivering high impact security assessments, strategic recommendations, and implementation support while balancing technical depth with strong stakeholder engagement. The consultant acts as a trusted advisor, helping clients manage cyber risk, meet regulatory requirements, and align security initiatives with business objectives.

You'll work at the intersection of cyber security, risk management, and operational resilience, supporting organisations as they respond to increasing regulatory scrutiny, geopolitical risk, and complex third party ecosystems. This is a high impact consulting work that blends strategic advisory, governance, and practical security improvement across supply chains.

Key Responsibilities
  • Lead and deliver cybersecurity consulting engagements for multiple clients.
  • Conduct enterprise risk assessments, security maturity assessments, and gap analysis.
  • Design and recommend security architectures, operating models, and control frameworks.
  • Advise clients on regulatory and compliance requirements (e.g., ISO 27001, NIST, SOC 2, PCI DSS, GDPR).
  • Develop cybersecurity strategies, roadmaps, policies, and governance frameworks.
  • Prepare and present executive level reports, risk dashboards, and recommendations.
  • Manage client relationships and act as a trusted security advisor.
  • Contribute to proposals, statements of work, and business development activities.
  • Liaise with the Resource Management and Pre Sales team during the sales cycle to assist in quantifying, pricing, and assessing resources required for the project delivery.
  • Assist with sales proposals, bids and tenders for delivery of consulting and implementation services.
Skills, Knowledge & Expertise
  • Strong experience in cyber security risk management, maturity assessments, supply chain security, third party risk, or operational risk consulting, ideally in complex enterprise environments.
  • Bachelor's degree in computer science, Information Security, or related discipline.
  • 5+ years of experience in cybersecurity, with significant consulting or advisory experience.
  • Strong knowledge of cybersecurity frameworks, risk management, and governance models.
  • Experience working across multiple client environments and industries.
  • Ability to balance hands on technical work with strategic advisory responsibilities.
  • Excellent written and verbal communication skills for technical and non technical audiences.
  • Practical understanding of controls and risk management frameworks, supplier assurance, and ecosystem level security threats.
  • Experience conducting risk assessments, workshops, or assurance activities with third parties.
  • Strong written and verbal communication skills, able to produce concise reports, and deliver clear recommendations.
Nice to haves (not show stoppers)
  • Experience with regulatory and compliance drivers (e.g., DORA, NIS2, SOCI, critical infrastructure regulations).
  • Understanding of software supply chain security (e.g., SBOMs, secure development, open source risk).
  • Exposure to geopolitical risk, sanctions, or operational resilience.
Certifications
  • CISA, CISSP, CISM, CRISC.
  • ISO 27001 / 27036 Lead Implementer or Auditor.
  • Supply chain or risk related certifications.
Consulting Specific Competencies
  • Client relationship and stakeholder management.
  • Engagement delivery and time management across multiple projects.
  • Executive level presentation and storytelling.
  • Commercial awareness and contribution to sales efforts.
  • Leadership, coaching, and team collaboration.
Ways of working
  • Focusing on Clients and Customers.
  • Working as One NCC.
  • Always Learning.
  • Being Inclusive and Respectful.
  • Delivering Brilliantly.
Job Benefits
  • Superannuation.
  • Leaves Benefits include but not limited to:
  • Annual leave - 20 days.
  • Sick Leave & caregivers Leave - 10 days.
  • Marriage/Civil Partnership Leave (1 day).
  • Moving Home Leave (1 day).
  • Employee Assistance Program with access to confidential counselling support 24 hours a day, 7 days a week. This is a free service for up to 6 occasions per calendar year for you and your close family.

Similar jobs