Setting the Scene
Our client is part of a global portfolio of specialised software businesses operating across Australia, the UK, Canada and the US. With businesses operating at different levels of security and technical maturity, they are continuing to build a central cyber security capability that provides practical guidance, support and expertise across the portfolio. They are seeking a Senior Security Advisor who can combine strong technical security capability with genuine GRC expertise and, importantly, an advisory mindset. This is a role where influence matters more than authority — you'll help businesses understand risk, develop practical controls and improve their security posture without taking a one-size-fits-all approach.
The Role
Reporting to the CISO, you will work across the portfolio providing security architecture, engineering and GRC guidance while partnering closely with technical and business stakeholders.
Key responsibilities
- Provide security architecture and engineering guidance across cloud, network, identity, endpoint and application environments
- Translate security risks into practical, proportionate controls and technical solutions
- Partner with CTOs, developers and technical leads on security initiatives and secure-by-design decisions
- Operationalise security frameworks, policies and processes across businesses with varying levels of maturity
- Support GRC activities aligned to NIST, ISO 27001, SOC 2 and relevant international requirements
- Conduct vendor and third-party security risk assessments
- Improve security reporting, processes and compliance automation
- Support newly acquired businesses in developing and integrating appropriate security practices
- Provide detailed security insights and reporting to support senior leadership and board-level reporting
- Build strong relationships across the portfolio and influence security outcomes without relying on formal authority
What you'll bring - 3–6 years' experience across Cyber Security, ideally with a strong security engineering or architecture foundation
- Strong understanding of GRC and the practical application of security frameworks
- Hands-on exposure across cloud, identity, network, endpoint and/or application security
- Experience with frameworks such as NIST, ISO 27001 and SOC 2
- Strong advisory, consulting and stakeholder engagement skills
- Ability to communicate effectively with technical teams, business leaders and senior stakeholders
- Strong critical thinking and problem-solving skills
- Ability to assess risk proportionately and tailor security controls to the needs and maturity of the business
- A collaborative mindset with the confidence to challenge and push back when required
- Experience across multiple businesses, consulting, software or acquisition environments is highly desirable
Certifications such as CISSP, CISM or ISO 27001 Lead Auditor are advantageous but not essential. The right mindset and capability are more important than having every certification or framework on your CV.
What's in it for you?
- $130,000–$160,000 + 12% super + 5% annual bonus (from base salary)
- Genuine opportunity to shape cyber security across a diverse global software portfolio
- Clear pathway towards security leadership as the function grows
- Strong investment in training, upskilling and professional development
- Opportunities to attend industry conferences
- Exposure to international security, GRC and regulatory environments
- Australia wide hybrid working, with a minimum of 3 days per week in the office
- Opportunity to work across Melbourne and Sydney offices where required
- Supportive environment that values critical thinking, initiative and continuous improvement
How to apply Applications are treated with absolute confidentiality. Click
APPLY or contact
Clodagh at clodagh@decipherbureau.com for an informal conversation about your next career move. Equal opportunity and diversity are a priority. We encourage applicants from all backgrounds to apply.