Skip to main content
AfterDuty

Lead/ Senior Risk Assessor

Interceptica · Melbourne, Victoria

Type
Contract
Posted
7 days ago

Overview

Your experience assessing threats and managing operational risk in policing translates directly to leading cyber security risk assessments.

About this role

We are looking for an experienced Lead/ Senior Risk Assessor to join our team in Melbourne on contract basis for 6 months.

This is a senior role suited to a cyber security risk professional who can operate confidently with senior and executive stakeholders, translate technical security risks into business language, and influence sound risk decisions across the organization.

The Role

You will lead cyber security risk assessments throughout the delivery lifecycle, partnering with technology, security, project, and business teams to identify, evaluate, and address security risks early.

You will also play an important role in maturing the risk assessment function through improved methodologies, processes, documentation, governance, and stakeholder engagement.

Key Responsibilities

  • Lead cyber security risk assessments across projects, programs, and strategic initiatives.
  • Identify, assess, and communicate security risks and appropriate treatment options.
  • Translate complex technical security issues into clear, actionable business risks.
  • Engage with senior leadership and executive stakeholders on risk findings and recommendations.
  • Facilitate risk decisioning and support risk owners in making informed decisions.
  • Partner with Agile and DevOps delivery teams to embed security risk practices into iterative delivery.
  • Maintain risk registers and track treatment plans through resolution or formal acceptance.
  • Develop and improve risk assessment methodologies, templates, standards, and playbooks.
  • Drive improvements in team processes, documentation, and stakeholder engagement.
  • Contribute to broader GRC reporting, governance, metrics, and continuous improvement.
  • Stay current with emerging cyber threats, regulatory requirements, and industry best practice.

What We're Looking For

Essential

  • 8+ years of professional experience, with significant experience in cyber security risk, GRC, information security, or a closely related discipline.
  • Proven experience leading cyber security risk assessments in complex enterprise environments.
  • Strong understanding of frameworks including NIST, ISO 27001/31000, COSO, or equivalent.
  • Demonstrated experience engaging with senior and executive stakeholders.
  • Strong understanding of risk governance, risk treatment, and risk decisioning.
  • Experience working across Agile and DevOps environments.
  • Excellent written and verbal communication skills, with the ability to explain technical risk in business terms.
  • Strong stakeholder management, influencing, analytical, and critical-thinking skills.
  • Ability to operate independently and exercise sound judgement in ambiguous situations.

Highly Desirable

Experience across broader risk disciplines such as

  • Enterprise Risk
  • Operational Risk
  • GRC
  • Compliance
  • Internal Audit
  • Technology Risk

Relevant certifications such as CRISC, CISM, CISSP, ISO 27001 Lead Risk Manager, or equivalent are highly regarded.

Why Join?

This is an opportunity to take a leading role in shaping how cyber security risk is identified, assessed, communicated, governed, and managed across a complex organization — with genuine influence over security and business outcomes.

About risk & resilience roles for ex-police

Risk management, business continuity and emergency-planning roles. Contingency planning, threat assessment and multi-agency coordination experience from policing is directly transferable.

See all risk & resilience jobs in Melbourne

Why this fits a police background — match score 65/100

  • Risk & threat assessment
  • Working to legislation & regulation

More risk & resilience jobs for ex-police