Principal Consultant
- Hiring from
- Australia
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
Principal Security Consultant (GRC)
Sydney | Hybrid
Lead the conversations that shape how organisations manage cyber risk.
From helping executives navigate a simulated cyber incident to shaping an organisation’s security strategy, this role puts you at the centre of important client decisions.
Infotrust’s Governance, Risk & Compliance practice is growing, and we’re looking for an experienced consultant to join our Sydney team. You’ll work closely with our Head of GRC, lead complex engagements and bring practical insight to clients’ security challenges.
The Role
Executive incident response tabletop exercises will be a key part of your remit. You’ll design and facilitate sessions that test how leadership teams respond under pressure, challenge assumptions and help them make better decisions when an incident occurs.
Help clients understand their cyber risks, develop their GRC strategy and turn it into a practical program of work. You’ll have ownership of engagements, supported by experienced colleagues across Infotrust’s broader security practices.
Work will include:
- Scoping and leading complex cyber security and GRC engagements
- Developing security strategies and roadmaps aligned with business priorities
- Facilitating executive tabletop exercises that strengthen incident preparedness
- Advising C-suite and senior stakeholders on cyber risk, governance and resilience
Skills & Experience
Suited to an experienced security practitioner who can connect technical knowledge with business context. Comfortable leading a room, asking thoughtful questions and explaining complex issues clearly to senior audiences.
We’re looking for:
- Substantial cyber security experience, including senior consulting or advisory work
- A strong practitioner foundation and experience helping clients put security recommendations into practice
- A track record of facilitating incident response tabletop exercises for executive teams
- Experience developing GRC strategies and leading complex programs of work
- Strong knowledge of security frameworks such as ISO 27001, with familiarity across the ISM and Essential Eight
- An active interest in the Australian cyber security landscape and what emerging changes mean for clients
CISSP or CISM would be well regarded, along with IRAP assessment experience.
Why Infotrust
Infotrust brings together cyber security, technology and advisory services. Our GRC consultants work alongside offensive and defensive security specialists, an 24/7 SOC, and a dedicated Digital Forensics and Incident Response team.
That breadth gives you access to specialist expertise and practical perspectives to inform your advice. We also offer hybrid working, professional development and paid parental leave.
If you’re ready to take greater ownership of client strategy and bring your expertise to executive conversations, apply or contact Kristen Brinker for a confidential conversation.