15 Sep
|
Cyber Forte
|
India
About Cyber Forte
Cyber Forte is an Australian cybersecurity and compliance consultancy helping organisations improve their security posture, achieve and maintain compliance, and prepare for independent certification and assurance.
We work with organisations across a range of industries on frameworks and standards including ISO/IEC 27001, SOC 2, Essential Eight, ISM, PCI DSS and broader cybersecurity governance and risk requirements.
We are looking for an experienced GRC Lead to join our growing delivery team and take responsibility for delivering high-quality governance, risk and compliance engagements for our clients.
About the Role
As a GRC Lead, you will work directly with clients to assess their current security and compliance maturity, identify gaps, develop practical remediation plans and support them through implementation and certification/assessment activities.
You will be involved across the full engagement lifecycle — from initial discovery and gap assessments through to policy and control development, evidence collection, remediation tracking, internal audits and certification readiness.
This is a client-facing, hands-on consulting role. We are looking for someone who can work independently, communicate confidently with stakeholders and translate compliance requirements into practical security outcomes.
Key Responsibilities Governance, Risk & Compliance
- Conduct security and compliance gap assessments against ISO 27001, SOC 2 and other relevant frameworks.
- Develop and maintain Statements of Applicability, control mappings, risk treatment plans and compliance roadmaps.
- Review client policies, procedures, standards and supporting documentation.
- Identify control gaps and provide practical, risk-based recommendations.
- Support clients with remediation planning and tracking.
- Perform information security risk assessments and support clients in developing and maintaining risk registers.
- Assist clients in preparing evidence and maintaining audit readiness.
- Conduct internal audits and control effectiveness assessments.
- Support clients through certification and external audit activities.
- Monitor changes to applicable standards, regulations and security requirements.
ISO 27001
- Conduct ISO/IEC 27001:2022 gap assessments.
- Assist with ISMS implementation and ongoing improvement.
- Develop and review ISO 27001 policies, procedures and supporting documentation.
- Support risk assessment and risk treatment activities.
- Develop and maintain Statements of Applicability.
- Support internal audit and management review activities.
- Prepare clients for Stage 1 and Stage 2 certification audits.
- Support surveillance and recertification activities.
Essential Eight
- Conduct Essential Eight maturity assessments.
- Assess client environments against ML1, ML2 and ML3 requirements.
- Identify technical and governance gaps.
- Develop remediation roadmaps.
- Work with technical teams to validate evidence and control implementation.
- Support clients preparing for Essential Eight assessments and related security requirements.
Client & Project Management
- Lead client workshops and stakeholder meetings.
- Gather and analyse technical and business information.
- Translate technical security issues into clear business and risk language.
- Maintain project actions, risks, issues and deliverables.
- Manage multiple client engagements concurrently.
- Prepare high-quality assessment reports, remediation plans and executive summaries.
- Work closely with Cyber Forte's senior consultants and leadership team.
- Ensure engagements are delivered on time, within scope and to a consistently high standard.
What We're Looking For
We are looking for someone who combines robust GRC knowledge with practical consulting experience.
Essential
- 3+ years' experience in cybersecurity, GRC, information security or compliance consulting.
- Strong working knowledge of ISO/IEC 27001:2022 and cloud security controls.
- Experience conducting ISO 27001 gap assessments, risk assessments and/or internal audits.
- Experience developing information security policies, procedures and control frameworks.
- Strong understanding of information security risk management.
- Experience working directly with clients and senior stakeholders.
- Excellent written and verbal communication skills.
- Strong report writing and documentation skills.
- Ability to manage multiple projects and deadlines.
- Ability to work independently and take ownership of client deliverables.
- Strong attention to detail.
- Early start at 6 AM IST to meet Australia time zone
Desirable
Experience with one or more of:
- ISO 27001
- Essential Eight / Essential Eight Maturity Model
- SOC 2
- PCI DSS
- NIST Cybersecurity Framework
- CIS Controls
- Security governance and assurance
- Cybersecurity maturity assessments
Certifications
One or more of the following would be highly regarded:
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- CISA
- CISM
- CISSP
- CRISC
- IRAP-related experience or qualifications
- Essential Eight assessment experience
Relevant practical experience will be considered alongside formal certifications.
Technical Understanding
You do not need to be a hands-on engineer, but you should be comfortable understanding and discussing common security technologies and environments, including:
- Microsoft 365
- Entra ID / Azure
- Intune
- Endpoint security / EDR
- Identity and access management
- MFA and privileged access
- Network security and firewalls
- Vulnerability management
- Logging and SIEM
- Backup and disaster recovery
- Cloud environments including Azure, AWS and GCP
- Security awareness
- Asset and configuration management
You should be able to understand technical evidence and determine whether it adequately supports the relevant security control or requirement.
What Success Looks Like
You will be expected to:
- Independently manage assigned GRC engagements.
- Conduct client gap assessments with limited supervision.
- Produce high-quality assessment reports and remediation roadmaps.
- Confidently facilitate client workshops.
- Maintain strong client relationships.
- Deliver projects within agreed timelines and scope.
- Contribute to improving Cyber Forte's GRC methodologies, templates and delivery processes.
- Support the broader Cyber Forte team across multiple compliance frameworks.
Why Join Cyber Forte?
- Work directly with a growing Australian cybersecurity consultancy.
- Exposure to a broad range of industries and security frameworks.
- Work closely with senior cybersecurity professionals and leadership.
- Chance to develop expertise across ISO 27001, Essential Eight, SOC 2, ISM, PCI DSS and other frameworks.
- Client-facing role with genuine ownership and responsibility.
- Remote/hybrid working environment.
- Opportunity to grow with the business and take on increasing responsibility.
📌 Cyber GRC Lead (India)
🏢 Cyber Forte
📍 India