Cybersecurity Consultant

  • Remote - Australia

Remote

Cybersecurity

Mid-level

Job description

You need to be an Australian Citizen with baseline clearance or NV1 for this role to be eligible.

Our Why

Datacom works with organisations and communities across Australia and New Zealand to make a difference in people’s lives and help organisations use the power of tech to innovate and grow.

About the Role (your why)

The Cybersecurity Consultant role, with a focus on Governance, Risk and Compliance (GRC), is responsible for helping Datacom’s customers strengthen their security posture by aligning security measures with business goals.

You will work closely with Datacom’s customers to ensure compliance with key Australian cybersecurity standards and regulations, primarily with the Australian Signals Directorate (ASD) Information Security Manual (ISM) and Essential Eight (E8), the Commonwealth Protective Security Policy Framework (PSPF) and may include other supporting international and national security standards and industry frameworks.

This role is ideal for security professionals with 3–5 years of experience who can conduct GRC assessments, making a direct impact on Datacom’s customers’ cyber resilience and compliance to protect against cyber threats..

What you’ll do

  • Security Consulting: Act as a trusted advisor to Datacom’s customers and internal stakeholders, understanding their cybersecurity needs and providing expert guidance and security solutions.
  • Stakeholder Collaboration: Collaborate with cross functional teams to ensure a shared understanding of security risks and propose fit for purpose mitigations. This may include working closely with project managers, technical support teams, architects, third party vendors, developers, security teams and business units to integrate security requirements into projects or business as usual (BAU) tasks.
  • Project Delivery: Support the planning and delivery of security projects or Datacom’s engagements, ensuring outcomes are achieved on time and meet quality standards. Maintain documentation of activities and track progress against project goals.
  • Continuous Improvement: Stay up to date with the latest cyber threats, vulnerabilities, and best practices. Proactively recommend improvements to security policies, processes and tools to enhance overall security posture.
  • Communication and Reporting: Prepare clear reports and presentations on security findings and recommendations. Communicate technical information to both technical and non-technical audiences (e.g. executives or customers) in an understandable manner, to facilitate informed decision-making.
  • Risk Assessments: Conduct comprehensive cybersecurity risk assessments and business impact analyses to identify vulnerabilities and evaluate potential threats. Develop risk artefacts such as plans, reports or registers and create roadmaps for safeguarding critical assets based on assessment findings.
  • Compliance and Audit: Undertake compliance assessments against relevant standards, frameworks and regulations (e.g. ISM, PSPF or ISO 2700127002). Ensure the organisation
  • meets requirements of frameworks and industry-specific regulations. Prepare for and support internal (Datacom) and external (IRAP or ANAO) audits, addressing any compliance gaps identified.
  • Policy Development: Develop and update security policies, plans, standards, and procedures aligned with best practices and regulatory requirements. This includes authoring cybersecurity policy documents and process improvement artefacts to strengthen governance. Ensure that policies reflect frameworks and are communicated effectively across the organisation.
  • Security Strategy and Advisory: Contribute to the creation of tailored cybersecurity strategies and governance frameworks that align with Datacom or the customers’ unique business objectives and risk appetite. Provide advice to senior management on implementing security controls and risk treatments in a pragmatic, business-aligned manner.

What you’ll bring

  • 3–5 years of hands-on experience in cybersecurity or information security roles, preferably including some time in a consulting or advisory capacity with large organisations is highly desirable.
  • Working in roles with direct exposure to GRC within the Australian Government will be a distinct advantage, but not mandatory.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field or equivalent work experience in a relevant discipline can be advantageous but not mandatory.
  • Professional security certifications are highly valued. Certifications such as CAP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer or similar security certifications demonstrate relevant expertise. Certifications like CISSP (or Associate of CISSP), CEH, OSCP, or relevant SANS GIAC certifications (e.g. GSEC, GCIH, GPEN) are a plus. Certification in cloud security (e.g. AWS Security Specialty, CCSP) or other specialised areas is also highly regarded.
  • Knowledge of Australian cybersecurity and privacy regulations (e.g. familiarity with the Australian Privacy Act and Notifiable Data Breaches scheme) is useful.
  • Australian citizenship and the ability to obtain a minimum Australian Government security clearance of Baseline Vetting (or higher) is needed to work on government customer projects.
  • Practical knowledge of cybersecurity frameworks and standards. For example, familiarity with Australian government standards like the ISM, E8 and PSPF. Experience applying risk management frameworks and ensuring compliance with regulations is highly regarded.
  • Demonstrated ability to conduct security risk assessments and compliance reviews. Comfortable mapping security controls to framework requirements, identifying gaps, and recommending remediation actions. Experience developing and maintaining risk assessment material, security policies, and/or audit documentation essential.
  • Strong analytical and problem-solving capabilities with keen attention to detail. Proactive in troubleshooting security issues and adept at finding creative, practical solutions. Ability to handle multiple priorities and work under pressure during security incidents or project deadlines.
  • Excellent written and verbal communication skills are essential. Able to translate technical security findings into clear, non-technical language for business leaders or customers. Strong interpersonal skills to work effectively with various Datacom or customers stakeholders, build consensus on security measures, and mentor junior team members.
  • While not mandatory, any awareness of the following international and industry standards or frameworks will be useful, while experience will be highly regarded:
  • o ISO/IEC 27001 - Information Security Management System (ISMS), ISO/IEC 27002 Information Security Controls, ISO/IEC 31000 Risk Management - Principles and Guidelines, and ISO/IEC 27005 Information Security Risk Management.
  • o National Institute of Standards and Technology (NIST) - various risk, privacy, control, configuration and audit frameworks.
  • o ITIL practices for IT service management (ITSM), including security operations and incident management.
  • o Australian Prudential Regulation Authority (APRA CPS 234) - Information Security Standard.
  • o Australian Privacy Act 1988 and Notifiable Data Breaches (NDB) Scheme.
  • o PCI DSS (Payment Card Industry Data Security Standard).
  • o Open Web Application Security Project (OWASP).
  • o MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge).
  • o Common Vulnerability Scoring System (CVSS).
  • o Zero Trust Architecture (ZTA).
  • o Centre for Internet (CIS) Security Critical Security Controls.
  • o Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM).

Why join us here at Datacom?

Datacom is one of Australia and New Zealand’s largest suppliers of Information Technology professional services. We have managed to maintain a dynamic, agile, small business feel that is often diluted in larger organisations of our size. It’s our people that give Datacom its unique culture and energy that you can feel from the moment you meet with us.

We care about our people and provide a range of perks such as social events, chill-out spaces, remote working, flexi-hours and professional development courses to name a few. You’ll have the opportunity to learn, develop your career, connect and bring your true self to work. You will be recognised and valued for your contributions and be able to do your work in a collegial, flat-structured environment.

We operate at the forefront of technology to help Australia and New Zealand’s largest enterprise organisations explore possibilities and solve their greatest challenges, so you will never run out of interesting new challenges and opportunities.

We want Datacom to be an inclusive and welcoming workplace for everyone and take pride in the steps we have taken and continue to take to make our environment fun and friendly, and our people feel supported.

Share this job:
Please let Datacom know you found this job on Remote First Jobs 🙏

Benefits of using Remote First Jobs

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

Advanced Filters

Filter by category, benefits, seniority, and more.

Priority Job Alerts

Get timely alerts for new job openings every day.

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

Search remote, work from home, 100% online jobs

We help you connect with top remote-first companies.

Search jobs

Hiring remote talent? Post a job

Frequently Asked Questions

What makes Remote First Jobs different from other job boards?

Unlike other job boards that only show jobs from companies that pay to post, we actively scan over 20,000 companies to find remote positions. This means you get access to thousands more jobs, including ones from companies that don't typically post on traditional job boards. Our platform is dedicated to fully remote positions, focusing on companies that have adopted remote work as their standard practice.

How often are new jobs added?

New jobs are constantly being added as our system checks company websites every day. We process thousands of jobs daily to ensure you have access to the most up-to-date remote job listings. Our algorithms scan over 20,000 different sources daily, adding jobs to the board the moment they appear.

Can I trust the job listings on Remote First Jobs?

Yes! We verify all job listings and companies to ensure they're legitimate. Our system automatically filters out spam, junk, and fake jobs to ensure you only see real remote opportunities.

Can I suggest companies to be added to your search?

Yes! We're always looking to expand our listings and appreciate suggestions from our community. If you know of companies offering remote positions that should be included in our search, please let us know. We actively work to increase our coverage of remote job opportunities.

How do I apply for jobs?

When you find a job you're interested in, simply click the 'Apply Now' button on the job listing. This will take you directly to the company's application page. We kindly ask you to mention that you found the position through Remote First Jobs when applying, as it helps us grow and improve our service 🙏

Apply