Core Duties:
The Cyber Security Consulting Team Lead manages the Consulting Team to deliver end-to-end cyber
security consulting services, undertaking duties that include, but are not limited to:
- Conducting comprehensive cyber security risk assessments and audits of client technical environments (cloud and on-premise) and policies and procedures, utilising practical implementation knowledge to provide insightful and actionable findings
- Evaluating client security controls against recognised standards (e.g., PCI DSS, IRAP, ISM, ISO 27001, SOC2, NIST, Essential Eight) and legislative requirements, identifying vulnerabilities, risks, and compliance gaps
- Providing expert advice and direct assistance in the design, implementation, configuration, and remediation of security controls, technologies, policies and procedures based on assessment outcomes and client objectives
- Developing and customising client-specific cyber security documentation, including policies, procedures, and governance frameworks aligned with best practices
- Advising and actively supporting clients throughout the process of preparing for and achieving cyber security certifications (e.g., PCI DSS, IRAP, ISM, ISO 27001, SOC2), including readiness assessments and evidence preparation
- Serving as a subject matter expert and trusted advisor, providing tailored strategic guidance and maintaining strong client relationships to understand business context and security requirements
- Preparing detailed reports documenting assessment findings, implementation activities, compliance status, and strategic recommendations
- Working with the development team to implement automated or technological solutions which streamline client processes, especially with regard to intensive tasks such as audit evidence gathering and log monitoring activities
- Meeting implemented KPIs related to performance of the Consulting team
- People management responsibilities related to the Consulting team including, but not limited to, regular performance reviews, client escalations, oversight of day to day tasks and priorities, internal reporting, etc.
Qualifications & Experience
- Tertiary qualification in Information Technology, Cyber Security, Computer Science, or a related field, or equivalent demonstrated industry experience
- A minimum of 2 years demonstrated professional experience in cyber security consulting, encompassing both security assessment/audit and technical implementation activities
- Proficient knowledge and practical application experience with recognised cyber security frameworks and standards (e.g., PCI DSS, IRAP, ISM, ISO 27001, SOC2, NIST Cyber Security Framework, Essential Eight)
- Experience in implementing security controls, technologies, and governance frameworks within diverse IT environments
- Strong analytical skills with the ability to assess complex systems and identify security risks and control weaknesses
- Excellent written and verbal communication skills, with the ability to convey technical information clearly to varied audiences, including senior management
- Experience in managing small teams of up to 5 resources
- Proven ability to manage client engagements and deliverables effectively
- Relevant industry certifications are highly regarded (e.g., CISSP, CISM, CISA, ISO 27001 Lead Auditor / Lead Implementer)
Job Types: Full-time, Permanent
Pay: $100,000.00 – $120,000.00 per year
Work Location: In person
Report job