- Owns and maintains ISO/IEC 27001:2022 and ISO/IEC 42001:2023, incl. SoA/Annex mapping, policy suite, audits and auditor/
- Develops, implements and measures cyber security policies/procedures/standards to meet regulatory requirements and best
- Manages cyber risk program: assessments, treatment/mitigation planning, residual risk reporting, and risk/obligations r
Role Type
Description
About Revio Cyber Security
Revio Cyber Security is an Australian Managed Security Service Provider (MSSP) headquartered in Sydney, delivering security operations, governance, risk and compliance (GRC), and cyber advisory services to organisations in regulated industries, including financial services, superannuation, technology and professional services. We operate a lean, high-trust team in which specialists own their programs end-to-end, from policy and certification through to client-facing advisory work.
Position Purpose
The Cyber Governance Risk and Compliance Specialist leads the governance, risk and compliance function for cyber security across Revio and its clients. The role owns Revio’s certified Information Security and AI Management Systems, the enterprise cyber risk and obligations program, and the internal and client audit and assurance program conducted against Australian and international standards. It is also a client-facing advisory role: the specialist delivers assessments, due diligence and board-level reporting to organisations in regulated industries, where the standard of evidence expected is that of an external auditor.
Key Responsibilities
Reporting to the Chief Executive Officer, the Cyber Governance Risk and Compliance Specialist will be responsible for:
- Own and maintain Revio’s certified ISO/IEC 27001:2022 Information Security Management System and ISO/IEC 42001:2023 AI Management System, including the Statement of Applicability, Annex A and Annex B control mapping, the governing documentation and policy suite, management review and security committee cycles, the internal audit program, external auditor and certification body management through certification and surveillance audits, and the closure of non-conformities and corrective actions.
- Develop, implement and measure the effectiveness of cyber security policies, procedures and standards to meet regulatory requirements and industry best practice, covering access control, acceptable use, change control, and blast-radius assessment, patch and auto-update policy, supply chain security, cryptographic key lifecycle and incident management, and drive continual improvement of the management systems.
- Manage the enterprise cyber risk program, including risk assessments, treatment and mitigation planning, and residual risk reporting to management and the Board, and maintain the cyber risk register, obligations register and risk appetite statement.
- Conduct internal and client security audits and assurance assessments against frameworks including NIST CSF 2.0, ISO/IEC 27001, the ACSC Essential Eight and its transition to the Essentials Series, CIS Controls v8, APRA CPS 230 and CPS 234, and Security of Critical Infrastructure Act obligations, including the Critical Infrastructure Risk Management Program, and support SOC 2 Type 1 and Type 2 readiness and attestation.
- Deliver client-facing governance, risk and compliance advisory, including cyber due diligence for investors and acquirers, maturity and gap assessments with costed remediation roadmaps, control design reviews, security questionnaire and tender responses, and written reporting to client executives, audit and risk committees and boards.
- Design and operate the third-party and vendor risk management program, including vendor criticality tiering, supplier security due diligence using CAIQ and equivalent questionnaires, third-party risk rating tooling, contractual security requirements, the exception workflow and vendor onboarding and periodic review.
- Own the security awareness and simulation program for Revio and client populations, including role-based training and its completion and certification records, phishing simulation campaigns, and tabletop and crisis simulation exercises for staff, senior management and boards, including sector-specific scenarios for superannuation and financial services clients.
- Define data and system classification requirements to prioritise security controls, implement data protection measures such as Data Loss Prevention across cloud and endpoint environments, and conduct compliance assessments to confirm that regulatory and legal cyber security obligations are met, including obligations arising from the Privacy Act and its reform program.
- Support security operations and incident response for internal and client incidents, including investigation, containment, remediation, assessment of notifiable data breach and regulatory notification obligations, and lessons-learned reporting that feeds corrective action back into the management systems
Skills, Knowledge and Experience
- Essential: A bachelor’s degree or higher in cyber security, information technology, information systems or a related discipline; equivalent qualifications and relevant experience will be considered.
- Demonstrated experience in cyber security governance, risk and compliance, including developing security policy, maintaining risk and obligations registers, and conducting internal audits and compliance assessments.
- Direct experience supporting an ISO/IEC 27001 certification or surveillance audit, including preparation of the Statement of Applicability, control evidence and auditor packs, and management of non-conformities to closure.
- Strong working knowledge of ISO/IEC 27001 and ISO/IEC 42001, NIST CSF 2.0, SOC 2, APRA CPS 234 and CPS 230, the ACSC Essential Eight, CIS Controls v8 and the SOCI Act and CIRMP obligations.
- Experience in third-party and vendor risk management and security due diligence, including CAIQ-based assessment and vendor criticality tiering.
- Familiarity with GRC and security tooling, such as GRC platforms, Microsoft Purview and Defender, SIEM platforms, third-party risk rating tools, and Jira and Confluence.
- Excellent written communication, stakeholder engagement, analytical and problem-solving skills, with the ability to write for an executive or Board audience and to hold a position under audit and client scrutiny.
- Desirable: Relevant professional certification, such as Certified Information Security Manager (CISM) or an ISO/IEC 27001 Lead Implementer or Lead Auditor credential (held or in progress); exposure to ISO/IEC 42001 or AI governance; and experience delivering GRC services in a consultancy or MSSP environment across concurrent client engagements, and board-level reporting to organisations in regulated industries, where the expected standard of evidence
Australia
New Zealand
United Kingdom
Canada
Singapore
Malaysia





