Cyber Grc Specialist

Boeing Boeing · Aerospace · Brisbane, Australia, Australia

This role is for a Cyber Governance, Risk, and Compliance (GRC) Specialist at Boeing Australia. The primary responsibilities include developing and maintaining security policies, leading risk assessments, managing compliance programs, overseeing audits, managing third-party risk, coordinating security control implementation, developing security metrics and reporting, driving security awareness programs, and advising on secure design and compliance requirements. The role requires experience in information security GRC, familiarity with security baselines and frameworks like ISM, NIST, and ISO 27001, and a NV1 clearance.

What you'd actually do

  1. Develop, maintain, and communicate enterprise information security policies, standards, procedures, and guidelines
  2. Lead and execute risk assessments (e.g., asset, vendor, application) and coordinate remediation tracking and reporting
  3. Maintain the compliance program for applicable regulations and frameworks
  4. Manage internal and external audits and assessments, including preparation of evidence, remediation plans, and auditor engagement
  5. Operate or oversee third-party risk management: vendor due diligence, contract security clauses, and ongoing monitoring

Skills

Required

  • 3+ years experience in information security governance, risk management, or compliance
  • demonstrable experience mapping to ISM or similar national-level security guidance
  • Familiarity with secure configuration baselines, vulnerability management, identity and access controls, and cryptography best practices
  • Strong written and verbal communication skills
  • Able to produce policies, control mappings, and concise executive reporting
  • Remediate critical and high-risk ISM findings
  • An understanding of security monitoring, incident response, and threat intelligence processes
  • Familiarity with security technologies and tools such as SIEM, IDS/IPS, and endpoint protection systems
  • Experience with incident handling and response methodologies, including evidence collection and analysis
  • Knowledge of security frameworks and standards such as Australian Government ISM, NIST, ISO 27001, or CIS Controls
  • Strong analytical and problem-solving skills
  • Excellent communication and collaboration skills to work effectively with cross-functional teams
  • A NV1 clearance with the ability and willingness to obtain a NV2
  • Australian Citizens to meet defence security requirements with the ability to obtain Australia Negative Vetting Level 1 clearance

Nice to have

  • Bachelor’s degree in computer science, Information Security, or a related field (or equivalent experience)

What the JD emphasized

  • mapping to ISM or similar national-level security guidance
  • Remediate critical and high-risk ISM findings
  • Australian Government ISM