GRC Assessor

e2 Cyber ·www.e2cyber.com.au

Location Canberra, Australian Capital Territory, Australia
Work type Hybrid
Salary AUD 140 - 160 / hour
Type Full time
Level Mid
Source Shazamme
GRC
Apply direct
A major Federal Government department is seeking experienced Cyber Security GRC Assessors to join its Cyber Assurance function. This role supports cybersecurity risk assessments and security assurance activities across a diverse ICT environment, directly contributing to the Authority to Operate (ATO) processes for critical government systems.

The Opportunity: You’ll assess ICT systems, platforms and services across on-premises, hybrid cloud, cloud, SaaS and AI-enabled environments, ensuring alignment with Australian Government security frameworks including the PSPF, ISM and Essential Eight.

Working closely with technical teams and senior stakeholders, you’ll review security documentation and architecture, identify risks and control gaps, and deliver clear, practical assessment reports and remediation advice.

Key Requirements
  • 5+ years’ experience in cyber security risk assessments, security assurance or ICT governance

  • Strong working knowledge of PSPF, ISM and Essential Eight

  • Demonstrated experience supporting ATO or equivalent security authorisation processes

  • Experience assessing systems across on-prem, hybrid and cloud (Azure/AWS)

  • Ability to assess AI-enabled systems or apply assurance skills to AI governance and data risks

  • Strength in reviewing security documentation, architecture, risk artefacts and control evidence

  • Proven ability to translate findings into clear, concise risk advice and recommended treatments

  • Strong communication skills, stakeholder engagement capability and the ability to work independently

Highly Desirable
  • Certifications such as CISSP, CISM, CRISC, CISA, Azure Security, AWS Security

  • IRAP assessor experience or experience supporting IRAP assessments

  • Background in Australian Government cyber security, ICT assurance, risk management or security authorisation environments




We are an inclusive employer committed to fostering a diverse and accessible workplace. We encourage applications from Aboriginal and Torres Strait Islander peoples, people with disabilities, LGBTQIA+ individuals, people of all ages, and those from culturally and linguistically diverse backgrounds.

Frequently asked questions

Who is hiring for the GRC Assessor role?
e2 Cyber is hiring for the GRC Assessor position, a Shazamme client. Apply directly on the employer's career site.
Where is the GRC Assessor job located?
The GRC Assessor role with e2 Cyber is based in Canberra, ACT, AU. The role is hybrid-friendly.
Is the GRC Assessor role remote?
Yes — the GRC Assessor position at e2 Cyber is hybrid. Candidates based in AU are preferred.
What does the GRC Assessor role pay?
e2 Cyber lists the GRC Assessor role at AUD 140–160 per hour.
Is the GRC Assessor role full-time or contract?
This is a full time position at e2 Cyber.
What experience level is the GRC Assessor role?
The GRC Assessor position is aimed at mid-level candidates.
How do I apply for the GRC Assessor role at e2 Cyber?
Apply directly on e2 Cyber's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS — no third-party form, no resume database.
Apply direct