GRC Manger/Virtual CISO

e2 Cyber ·www.e2cyber.com.au

Location Melbourne, Victoria, Australia
Work type Remote
Salary AUD 200,000 / year
Type Full time
Level Mid
Source Shazamme
Cyber Leadership
Apply direct
GRC Manager / Virtual CISO
Remote | Australia
Cyber Security Governance, Risk & Compliance | SaaS | Global Growth Organisation
e2 Cyber has been engaged to identify an experienced GRC leader to join a fast-growing global technology organisation operating across Australia, the UK and the US.
This is a unique opportunity to take ownership of a mature and business-critical governance, risk and compliance function, leading certification, audit and assurance activities that directly support customer trust, market growth and regulatory compliance.
The successful candidate will step into a highly visible leadership role, acting as the custodian of the organization's Information Security Management System (ISMS), AI Management System (AIMS), certification roadmap and customer assurance program. ?
The Opportunity
Reporting to the Executive Leadership Team, you will own the end-to-end compliance and assurance program across multiple internationally recognised certification frameworks.
You will work closely with security, engineering, product, legal and executive stakeholders to ensure governance processes remain effective, audit-ready and aligned with business objectives.
This role is ideally suited to someone who has personally owned and operated an ISO 27001 certified management system and enjoys driving outcomes across complex stakeholder environments.
Key Responsibilities
Certification & Assurance
  • Own and manage certification programs including ISO 27001, ISO 42001, DISP, IRAP, Cyber Essentials Plus and related assurance activities.
  • Develop and maintain the annual audit and certification calendar.
  • Lead external certification audits and manage auditor relationships.
  • Coordinate internal audits, corrective actions and continuous improvement initiatives.
  • Drive audit findings through to successful closure.
Governance, Risk & Compliance
  • Own the organisation's ISMS and AIMS governance frameworks.
  • Maintain policies, standards, Statements of Applicability and management system documentation.
  • Ensure alignment between documented controls, operational practices and audit evidence.
  • Manage cyber and AI risk registers, reporting and treatment plans.
  • Monitor and report compliance posture, audit readiness and certification risk to executive stakeholders.
Third-Party Risk & AI Governance
  • Lead vendor and third-party security assessment programs.
  • Maintain third-party risk registers and assurance processes.
  • Manage AI governance activities, including AI risk assessments and AI inventory processes.
  • Partner with key stakeholders to support compliance with emerging AI governance requirements.
Customer Assurance
  • Own customer security questionnaires and RFP security responses.
  • Maintain customer-facing assurance artefacts and trust documentation.
  • Support sales and customer success teams with security and compliance-related enquiries.
  • Provide guidance on framework mapping and customer assurance requirements.
Leadership & Stakeholder Engagement
  • Act as a trusted advisor to executive leadership.
  • Coordinate governance forums, compliance reporting and management reviews.
  • Influence stakeholders across security, engineering, legal, product and business functions.
  • Drive accountability and delivery across teams without direct reporting lines.
About You
To be successful, you will bring:
Essential Experience
  • Demonstrated experience owning and operating an ISO 27001 management system through external certification audits.
  • Experience leading certification, compliance and assurance programs within complex environments.
  • Strong knowledge of governance, risk management and compliance frameworks.
  • Experience managing audit programs, non-conformities and corrective actions.
  • Proven capability in risk register management and remediation tracking.
  • Third-party and vendor risk assessment experience.
  • Exceptional written communication and documentation skills.
  • Australian Citizenship.
Highly Regarded
  • ISO 42001 or AI Governance experience.
  • Exposure to IRAP, DISP, Essential Eight, ISM, Cyber Essentials or similar frameworks.
  • Experience supporting customer security questionnaires and assurance activities within a SaaS environment.
  • Hands-on experience with modern GRC platforms.
  • Certifications such as ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, CISM, CISA, CRISC or CIPP.
Why Apply?
  • Join a globally operating technology organisation experiencing continued growth.
  • Own a mature and highly visible cyber compliance function.
  • Work across security, AI governance, risk and assurance programs.
  • Influence executive decision-making and business strategy.
  • Fully remote working environment.
  • Opportunity to shape and mature governance capabilities at scale.
Important Considerations
This position will commence during an active assurance and certification cycle. As a result, the successful candidate will be expected to assume ownership quickly and play a key role in maintaining audit readiness and certification outcomes from the outset. ?
Apply Now
For a confidential discussion regarding this opportunity, please contact the team at e2 Cyber.
Due to the anticipated volume of applications, only candidates progressing to the next stage of the process will be contacted.


We are an inclusive employer committed to fostering a diverse and accessible workplace. We encourage applications from Aboriginal and Torres Strait Islander peoples, people with disabilities, LGBTQIA+ individuals, people of all ages, and those from culturally and linguistically diverse backgrounds.

#SCR-ben-rogalsky

Frequently asked questions

Who is hiring for the GRC Manger/Virtual CISO role?
e2 Cyber is hiring for the GRC Manger/Virtual CISO position, a Shazamme client. Apply directly on the employer's career site.
Where is the GRC Manger/Virtual CISO job located?
The GRC Manger/Virtual CISO role with e2 Cyber is based in Melbourne, VIC, AU. The role is remote-friendly.
Is the GRC Manger/Virtual CISO role remote?
Yes — the GRC Manger/Virtual CISO position at e2 Cyber is remote. Candidates based in AU are preferred.
What does the GRC Manger/Virtual CISO role pay?
e2 Cyber lists the GRC Manger/Virtual CISO role at up to AUD 200,000 per year.
Is the GRC Manger/Virtual CISO role full-time or contract?
This is a full time position at e2 Cyber.
What experience level is the GRC Manger/Virtual CISO role?
The GRC Manger/Virtual CISO position is aimed at mid-level candidates.
How do I apply for the GRC Manger/Virtual CISO role at e2 Cyber?
Apply directly on e2 Cyber's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS — no third-party form, no resume database.
Apply direct