Back to jobs

Senior Security Consultant

CypherLeapPhilippinesPosted 3w ago
Cybersecurity Analyst
Apply on LinkedIn

Job Description

Senior Cybersecurity Consultant – GRC & Advisory Services


Location

Philippines or India (Remote)


Employment Type

Full-Time Employee or Independent Contractor


About CypherLeap

CypherLeap is a cybersecurity consulting and managed security services company helping organisations across Australia strengthen their security posture through governance, risk and compliance programs, security assessments, managed security services, penetration testing, threat intelligence, external attack surface management, and strategic cybersecurity advisory services. 

 

We work with organisations ranging from startups to enterprises and regulated industries, delivering practical cybersecurity outcomes that balance compliance requirements with real-world security risks.


The Opportunity

This is a senior consulting role with a strong focus on Governance, Risk and Compliance (GRC). 

 

The successful candidate will lead customer engagements across ISO/IEC 27001, the NIST Cybersecurity Framework, PCI DSS, the Essential Eight, SOC 2, and related cybersecurity initiatives. While the role is primarily focused on GRC consulting, we are seeking someone with a strong technical cybersecurity background who can provide practical guidance on security controls, architectures, threat intelligence, attack surface management, security operations concepts, and remediation activities as needed. 

 

This role is ideal for someone who began their career in a technical cybersecurity discipline before transitioning into consulting and GRC.


Key Responsibilities

• Lead cybersecurity maturity assessments, gap assessments and compliance reviews. 

• Conduct ISO/IEC 27001 readiness assessments, internal audits and certification preparation activities. 

• Deliver Essential Eight assessments and remediation roadmaps. 

• Support customers with NIST CSF, PCI DSS, SOC 2 and CIS Controls initiatives. 

• Facilitate cybersecurity risk assessments and workshops. 

• Develop policies, standards, procedures and governance documentation. 

• Support customers during certification audits and compliance assessments. 

• Prepare executive reports, risk summaries and remediation plans. 

• Review customer security architectures and validate security controls. 

• Support security strategy and roadmap development. 

• Lead customer workshops and stakeholder interviews. 

• Mentor junior consultants and support pre-sales activities. 

• Contribute to service development and internal capability uplift. 


Required Experience

• Minimum 7 years of cybersecurity experience. 

• Minimum 4 years of GRC, compliance or cybersecurity consulting experience. 

• Strong practical experience delivering ISO/IEC 27001 programs end-to-end. 

• Previous hands-on experience as a SOC Analyst, Security Engineer, Cybersecurity Engineer, Incident Response Analyst, Vulnerability Management Specialist or Technical Security Consultant. 

• Demonstrated experience independently leading customer engagements. 

• Strong understanding of cybersecurity controls and security architecture principles. 

• Excellent verbal and written English communication skills. 

• Experience presenting to executive and technical stakeholders.


Mandatory Technical Background

Candidates must have at least 3 years of hands-on experience in a SOC, Security Engineering, Incident Response, Vulnerability Management, Threat Detection, or Cybersecurity Engineering role before transitioning to GRC or consulting. 

 

Candidates with exclusively audit, compliance or governance backgrounds and no prior technical cybersecurity experience will not be considered.


Framework Experience

Strong experience with several of the following: 

• ISO/IEC 27001:2022 

• NIST Cybersecurity Framework (CSF) 

• PCI DSS 

• ACSC Essential Eight 

• CIS Controls 

• SOC 2 

• APRA CPS 234 

• ASD ISM 

• Cybersecurity Risk Management Frameworks 

 

Experience with PCI DSS and NIST Cybersecurity Framework is highly desirable.


Preferred Certifications

• ISO/IEC 27001 Lead Auditor 

• ISO/IEC 27001 Lead Implementer 

• CISSP 

• CISM 

• CRISC 

• PCI Professional (PCIP) 

• PCI Internal Security Assessor (ISA) 

• GIAC Certifications 

• Security+


Working Arrangements

• Ability to work substantially within Australian Eastern Time (AEST/AEDT) business hours. 

• Experience supporting customers in Australia, New Zealand, the United Kingdom or North America is highly desirable. 

• Ability to travel occasionally if required.


Startup Environment

CypherLeap is a growing cybersecurity consultancy. The successful candidate must be comfortable operating in a fast-moving environment where processes continue to evolve. 

 

We value consultants who are proactive, adaptable, commercially aware, and willing to contribute beyond their narrowly defined job descriptions. 

 

The successful candidate will be comfortable contributing across multiple service areas, helping build processes, mentoring junior team members and supporting the growth of new service offerings.


What Success Looks Like

Within your first 12 months, you will: 

 

• Independently lead customer GRC engagements. 

• Become a trusted cybersecurity advisor to CypherLeap customers. 

• Deliver high-quality assessments, reports and remediation roadmaps. 

• Contribute to the growth of CypherLeap's consulting practice. 

• Assist in developing repeatable methodologies and service offerings. 

• Support customers through certification, compliance and security improvement programs.


Ideal Candidate Profile

The ideal candidate started their career as a technical cybersecurity professional and later moved into GRC and consulting. 

 

They combine strong technical foundations with excellent consulting, communication and stakeholder management skills and can confidently engage with auditors, executives, IT managers and security engineers. 

 

  • They enjoy solving problems, taking ownership, working independently and helping shape the future of a growing cybersecurity business.