GRC Consultant - Cyber Lead
Quick Overview
Job Description
XPT Software Australia Pty Ltd Contract
Melbourne, Australia Posted on 06/16/2026
- XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
- XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
- We have 120+technocrats in Australia working at our clientlocations.
- XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
- We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Role Summary
We are seeking anexperienced GRC Consultant - Cyber Lead to drive governance and maturityof non-OS vulnerability management across enterprise application andplatform environments.
This role focuses on cyberrisk oversight, exception management, and vulnerability treatment strategy,ensuring risks are effectively assessed, governed, and aligned with enterprisesecurity standards-while remediation execution remains with delivery teams.
Key Responsibilities
Governance & Risk Oversight
- Define and implement non-OS vulnerability management frameworks,policies, and standards
- Establish governance forums, escalation paths, anddecision-making processes
- Ensure compliance with regulatory, audit, and enterprisesecurity requirements
Exception & Treatment Management
- Manage remediation exceptions and risk acceptance lifecycle
- Validate compensating controls and residual risks
- Drive risk-based treatment plans with application andplatform teams
- Perform risk assessments for vulnerabilities that cannot beremediated
- Enable risk-based decision-making aligned to business riskappetite
- Ensure proper documentation, tracking, and periodic review ofaccepted risks
Tooling & Capability Uplift
- Lead tooling strategy, evaluation, and automation initiatives
- Improve vulnerability management maturity and processes
- Support training and adoption across delivery teams
Security Improvement & SDLC Integration
- Oversee remediation outcomes from pen tests, audits, andassessments
- Promote secure-by-design and DevSecOps practices
- Ensure vulnerabilities are identified and treated beforeproduction release
Stakeholder Management
- Collaborate with Cyber, Application, Infrastructure, andOperations teams
- Provide risk insights to senior leadership and governance forums
- Influence prioritization based on risk severity and businessimpact
Required Skills & Experience
- Strong background in GRC, cyber risk, and vulnerabilitymanagement
- Experience with application/platform vulnerabilities (non-OS)
- Knowledge of frameworks: ISO 27001, NIST, CIS
- Hands-on exposure to tools like Qualys, Tenable, Snyk, orsimilar
- Expertise in risk assessment, exception management, andcompliance
- Strong stakeholder engagement and communication skills
- Familiarity with DevSecOps / SDLC security practices
Qualifications
- Bachelor's degree in IT / Cybersecurity or related field
Skills
Similar jobs
Experience Designer
Water-Corporation · Australia
2 hours agoTechnical Lead
Westpac Group · Sydney, Australia
6 hours agoSolution Designer
XPT Software Australia Pty Ltd · Sydney, Australia
8 hours agoDigital Performance Manager
Greenstone-Financial-Services · Australia
9 hours agoScaled Agile Release Train Lead
XPT Software Australia Pty Ltd · Melbourne, Australia
9 hours agoSenior .NET Team Lead - Hands-On, High-Impact Mentor
Alintech · Sydney, Australia
9 hours ago