StickmanCyber
Website:
stickmancyber.com
Job details:
About the Role:
StickmanCyber is looking for a Senior Cybersecurity GRC Consultant to join our GRC delivery team. You will lead governance, risk, and compliance engagements for a portfolio of clients — running audits, building management systems, and advising clients on ISO 27001, SOC 2, and related frameworks.
This is a senior, client-facing role requiring deep audit experience and the ability to operate with minimal oversight. You will serve as the trusted cybersecurity advisor (vCISO) to C-suite executives, boards, and senior risk leaders across Australia's most critical industries. In this role, you will need to directly influence business outcomes by delivering strategic GRC consulting that transforms client cybersecurity maturity, ensures regulatory compliance, and drives measurable risk reduction.
What You’ll Do:
- Client Advisory & Strategic Consulting
- Act as the primary GRC consultant/ vCISO on client accounts, running audit interviews, writing findings, and presenting results directly to client stakeholders.
- Lead end-to-end GRC engagements: gap assessments, internal audits, ISMS/PIMS implementation, and certification support for clients across ISO 27001, SOC 2, ISO 27701, and ISO 42001.
- Extend GRC coverage into broader compliance frameworks — PCI DSS, GDPR, NIST (CSF/800-53/AI RMF), and CMMC 2.0 — as client needs require.
- Architect enterprise security governance frameworks that align with business objectives, risk appetite, and regulatory requirements.
- Lead cloud security assessments across cloud and hybrid environments, ensuring secure digital transformation initiatives.
- Drive client maturity advancement through strategic road mapping, governance framework design, and risk optimization programs delivering measurable business value.
- Design incident response and business continuity programs that minimize business disruption and protect organisational reputation.
- Business Development & Account Growth
- Support pre-sales activities by developing compelling proposals, conducting client presentations, and demonstrating clear ROI for cybersecurity investments.
- Identify and develop new revenue streams within existing client accounts through needs assessment, gap analysis, and strategic consulting recommendations
- Build and maintain strategic client relationships that result in multi-year consulting contracts and ongoing managed security services engagements.
What We’re Looking For :
- Minimum 12 years of experience in cybersecurity GRC, IT audit, or information security consulting, including senior/lead-level client delivery.
- Strong spoken and written communication. Proven ability to work directly with client stakeholders, including at the executive level.
- A multi-framework consulting environment (i.e., running concurrent ISO, SOC 2, and PCI engagements, not just one framework in-house).
- Hands-on experience running ISO 27001 audits (internal and/or certification) and building ISMS documentation from scratch.
- Working knowledge of SOC 2 (Trust Services Criteria) and at least one of: ISO 27701, ISO 42001, PCI DSS, GDPR, NIST CSF/800-53, or CMMC 2.0.
- Relevant certifications required or strongly preferred: ISO 27001 Lead Auditor/Lead Implementer, CISA, CRISC, or CISSP.
- Based in India, with flexibility to work across time zones to support Australian and other international clients.
Nice to Have :
- Experience in Australian frameworks Essential Eight, APRA CPS 234.
- Prior experience mentoring junior GRC analysts/consultants.
- Exposure to GRC tooling (e.g., Vanta, Drata or similar) and ticketing/PM tools (Jira etc).
What We Offer :
- The opportunity to work across a diverse portfolio of clients and compliance frameworks rather than a single in-house program.
- A senior, high-trust role with direct client ownership.
- Collaborative, experienced GRC team and clear path for growth into practice leadership.
Click on Apply to know more.