About the team
Our Risk Consulting practice is one of Grant Thornton's leading advisory businesses, bringing together experts across Technology Risk, Financial Crime, Internal Audit and Risk Advisory to help organisations manage uncertainty and seize opportunity. We work closely with clients to solve complex business challenges, strengthen governance and controls, and navigate an evolving regulatory and risk environment.
Within this practice, our Technology Risk Consulting team helps organisations build confidence in their technology, cyber and data environments. From technology assurance and cyber risk to governance, compliance and major project assurance, we deliver practical, forward-looking advice that enables clients to innovate securely, manage risk effectively and achieve their strategic objectives.
About this role
Lead meaningful Technology Risk engagements across Controls Assurance (SOC, ASAE), IT General Controls (ITGCs), cyber security, privacy, and data governance.
As a Manager in our Melbourne team, you’ll work closely with clients to understand their technology risk environment, provide practical recommendations and deliver high-quality assurance and advisory outcomes.
You’ll also play an important role fostering the development of Associates and Senior Associates, shaping client relationships, and contributing to the continued growth of our national Technology Risk practice.
Key responsibilities
- Lead Technology Risk engagements across Controls Assurance reporting, IT Audit, Cyber Rsk, Privacy, and Data Governance
- Apply frameworks such as SOC, COBIT, PCI-DSS, ISO 27001, NIST, GS 007 and Essential 8 to assess client environments
- Build trusted client relationships through clear communication, strong planning and practical risk advice
- Translate complex technology risks into pragmatic recommendations for executive and technical stakeholders
- Manage engagement scope, budget, delivery quality, risks and stakeholder expectations
- Coach Associates and Senior Associates through review, feedback and ‘on-the-job’ development opportunities
- Contribute to the continued growth of Grant Thornton’s Technology Risk practice in Melbourne
Skills and experience
You’ll thrive in this role if you’re a detail-oriented person who enjoys solving problems, building relationships on a strong foundation of trust, and helping clients to make confident decisions about technology risk. We value curiosity, care, accountability and the ability to communicate clearly with both technical and non-technical audiences.
Required
- IT risk and security management experience within a public practice or corporate environment
- ‘Hands-on’ experience with auditing standards and industry frameworks, such as SOC-2, GS 007, ASAE 3150 and 3402, COBIT, PCI-DSS, ISO 27001, Essential 8 and / or NIST
- Demonstrable understanding of Hyperscale IT systems and their deployment across organisations, with the ability to tailor your communication style to the needs of different audiences
- Excellent interpersonal skills, with a passion for exceptional client service and delivery
- People leadership experience with a strong sense of ownership and accountability, while providing coaching and mentoring opportunities to less experienced team members
Desirable
- CISA, CRISC, CISM, ISO Lead Auditor, or other relevant qualification(s) (or currently pursuing)
If you’re interested in this role but don’t feel that you match every single one of our requirements, we would still love to hear from you and explore the unique skillset and attributes that you can bring to the team.
Reach your remarkable
At Grant Thornton, we do things differently because we understand that when you strive for better and care about what you do, remarkable things are possible. We’re a dynamic and authentic mix of backgrounds, perspectives and ways of thinking. We’re driven by our shared purpose – we ignite the potential within our people and clients to create enduring success and positively shape the communities around us.
With us, you’ll be exposed to challenging and rewarding opportunities – building your confidence and capabilities at every step. You’ll be supported, motivated and inspired by a team of passionate and caring collaborators and leaders. You’ll be empowered to build a career path that’s tailored to you and encouraged to make a meaningful difference. And we’ll make sure the excellence you deliver and the impact you make is always seen, felt and celebrated.
Key Responsibilities
- Advise clients on cybersecurity governance, regulatory compliance, risk management, and overall posture improvement.
- Identify program and technical control gaps, and translate those into actionable, prioritized remediation plans.
- Map cybersecurity controls to applicable frameworks and regulations (e.g., NIST CSF, HIPAA, CMMC, ISO 27001, PCI DSS), tailored to the client’s business model, industry, and regulatory profile.
- Evaluate technical environments (e.g., network infrastructure, cloud, endpoint, access controls) to determine practical solutions that meet security and compliance goals.
- The individual must have tool proficiency with security solutions such as SentinelOne, Huntress, Perception Point, and Splunk—or demonstrate the ability to quickly become proficient in their use.
- Draft, implement, and review cybersecurity policies and standards appropriate to the organization’s maturity and compliance needs.
- Guide clients through external assessments and audits (SOC 2, ISO, CMMC), including readiness planning, evidence gathering, and post-audit remediation.
- Collaborate with internal engineering and technical services teams to ensure alignment between strategic guidance and technical execution.
- Provide support across administrative and operational functions as needed to maintain continuity and redundancy in leadership roles.
- Stay up to date on the threat landscape, emerging compliance requirements, and best practices in cybersecurity governance.
Qualifications
- 10+ years of cybersecurity experience with a strong emphasis on governance, risk, and compliance.
- Demonstrated experience advising clients or stakeholders in regulated industries, such as healthcare, financial services, or critical infrastructure.
- Technical knowledge sufficient to understand enterprise architecture, identify vulnerabilities, and map solutions to framework controls.
- Proven ability to write and implement information security policies and provide audit readiness support.
- Experience supporting or leading audit prep and response for SOC 2, ISO 27001, HIPAA, CMMC, or other major frameworks.
- Ability to provide clarity and direction across multiple functions in a lean organization.
- Exceptional communication and documentation skills—able to bridge gaps between technical teams, leadership, and external counsel.
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field. Master’s degree or relevant certifications preferred.
Preferred Certifications
- CISSP, CISA, CISM, CRISC, or equivalent
- CMMC RP/RPA or CCP
Experience interfacing with or supporting outside counsel is a plus.
Location: Remote
Apply Now
Incase you would like to apply to this job directly from the source, please click here