- Location
- Sydney - Barangaroo, Australia · Perth - 225 St. Georges Terrac
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Management
- Experience
- 2+ years
- Source
- Workday
Description
Company:
MarshDescription:
We are seeking a talented individual to join our Cyber Risk Consulting team at Marsh. This role will be based in Sydney OR Perth. This is a hybrid role that has a requirement of working at least three days a week in the office.
As a Consultant, you will support clients to improve cyber resilience by assessing cyber risk, strengthening governance and controls, supporting incident readiness, and advising on practical risk management improvements. You will work closely with senior consultants and client stakeholders across a range of industries, translating technical cyber issues into clear business advice and helping deliver high-quality consulting outputs.
We will count on you to:
- Support delivery of cyber risk consulting engagements, including cyber risk assessments, maturity reviews, control reviews, incident response readiness, and tabletop exercises.
- Assess cyber security risks, vulnerabilities, impacts, and control gaps across people, process, technology, and third-party environments.
- Assist in preparing incident response plans, playbooks, and board- or executive-level workshop materials.
- Contribute to client advisory work on cyber governance, policies, security frameworks, and resilience uplift roadmaps.
- Review and analyse security controls against relevant frameworks and standards such as ISO 27001, NIST, CPS 234, and ASD Essential Eight.
- Support the evaluation of security technologies, vendors, and implementation approaches that improve client security posture.
- Help quantify cyber risk and communicate findings in a way that supports decision-making and investment prioritisation.
- Build strong client and internal relationships, support business development activities, and contribute to proposals, thought leadership, and marketing initiatives.
- Work collaboratively with senior team members and provide guidance to junior colleagues where appropriate.
What you need to have:
- 2–4 years of experience in cyber security, cyber risk, technology risk, or a related consulting role.
- Experience in risk assessments, security reviews, incident response planning, and/or cyber resilience work.
- Sound understanding of key cyber security concepts, frameworks, and control domains, including governance, vulnerability management, identity and access management, cloud security, and third-party risk.
- Strong written and verbal communication skills, including the ability to explain technical matters to non-technical audiences.
- Strong analytical, problem-solving, and stakeholder management skills.
What makes you stand out:
- Knowledge of and experience working with frameworks and standards such as ISO 27001, NIST, CPS 234, and ASD Essential Eight.
- Professional certifications such as CISM, CISSP, CRISC, CISA, or equivalent.
- Ability to manage competing priorities, work well in a team, and operate effectively in a client-facing environment.
- Commercial awareness and an interest in developing advisory and consulting skills.
Why join our team:
- We help you be your best through professional development opportunities, interesting work and supportive leaders.
- We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients and
communities. - Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.