Haystack
← Back to Jobs
Full time
Other

GRC Consultant - Cyber Lead

XPT Software Australia Pty LtdMelbourne, Victoria🇦🇺AustraliaPosted 10 Aug 2026

Quick Overview

Work Type
On Site
Schedule
Full Time
Level
Mid Senior

Job Description

XPT Software Australia Pty Ltd Contract

Melbourne, Australia Posted on 06/16/2026

  • XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
  • XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
  • We have 120+technocrats in Australia working at our clientlocations.
  • XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
  • We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Job Description

Role Summary

We are seeking anexperienced GRC Consultant - Cyber Lead to drive governance and maturityof non-OS vulnerability management across enterprise application andplatform environments.

This role focuses on cyberrisk oversight, exception management, and vulnerability treatment strategy,ensuring risks are effectively assessed, governed, and aligned with enterprisesecurity standards-while remediation execution remains with delivery teams.

Key Responsibilities

Governance & Risk Oversight

  • Define and implement non-OS vulnerability management frameworks,policies, and standards
  • Establish governance forums, escalation paths, anddecision-making processes
  • Ensure compliance with regulatory, audit, and enterprisesecurity requirements

Exception & Treatment Management

  • Manage remediation exceptions and risk acceptance lifecycle
  • Validate compensating controls and residual risks
  • Drive risk-based treatment plans with application andplatform teams
  • Perform risk assessments for vulnerabilities that cannot beremediated
  • Enable risk-based decision-making aligned to business riskappetite
  • Ensure proper documentation, tracking, and periodic review ofaccepted risks

Tooling & Capability Uplift

  • Lead tooling strategy, evaluation, and automation initiatives
  • Improve vulnerability management maturity and processes
  • Support training and adoption across delivery teams

Security Improvement & SDLC Integration

  • Oversee remediation outcomes from pen tests, audits, andassessments
  • Promote secure-by-design and DevSecOps practices
  • Ensure vulnerabilities are identified and treated beforeproduction release

Stakeholder Management

  • Collaborate with Cyber, Application, Infrastructure, andOperations teams
  • Provide risk insights to senior leadership and governance forums
  • Influence prioritization based on risk severity and businessimpact

Required Skills & Experience

  • Strong background in GRC, cyber risk, and vulnerabilitymanagement
  • Experience with application/platform vulnerabilities (non-OS)
  • Knowledge of frameworks: ISO 27001, NIST, CIS
  • Hands-on exposure to tools like Qualys, Tenable, Snyk, orsimilar
  • Expertise in risk assessment, exception management, andcompliance
  • Strong stakeholder engagement and communication skills
  • Familiarity with DevSecOps / SDLC security practices

Qualifications

  • Bachelor's degree in IT / Cybersecurity or related field

Skills

Compliance
Risk Assessment
Stakeholder Management

Similar jobs