Pioneers in Cybersecurity as a Service and AI driven Cybersecurity Platform
At StickmanCyber, our mission is more than a commitment – it's a guiding light: "We do everything in our power to protect our customers from cyber threats"
Established in 2006, we've carved a niche in the cybersecurity landscape, demonstrating a remarkable business growth. Our success story is built on a foundation of trust and commitment that the staff at StickmanCyber have created with our clientele, which includes several prestigious public listed companies.
Senior Cybersecurity GRC Consultant - vCISO
India | Remote
StickmanCyber is looking for a Senior Cybersecurity GRC Consultant to join our GRC delivery team. You will lead governance, risk, and compliance engagements for a portfolio of clients — running audits, building management systems, and advising clients on ISO 27001, SOC 2, and related frameworks.
This is a senior, client-facing role requiring deep audit experience and the ability to operate with minimal oversight. You will serve as the trusted cybersecurity advisor (vCISO) to C-suite executives, boards, and senior risk leaders across Australia's most critical industries. In this role, you will need to directly influence business outcomes by delivering strategic GRC consulting that transforms client cybersecurity maturity, ensures regulatory compliance, and drives measurable risk reduction.
What You'll Do
Client Advisory and Strategic Consulting
- Serve as the primary liaison between clients and internal teams.
- Act as the primary GRC consultant/ vCISO on client accounts, running audit interviews, writing findings, and presenting results directly to client stakeholders.
- Lead end-to-end GRC engagements: gap assessments, internal audits, ISMS/PIMS implementation, and certification support for clients across ISO 27001, SOC 2, ISO 27701, and ISO 42001.
- Extend GRC coverage into broader compliance frameworks — PCI DSS, GDPR, NIST (CSF/800-53/AI RMF), and CMMC 2.0 — as client needs require.
- Architect enterprise security governance frameworks that align with business objectives, risk appetite, and regulatory requirements.
- Lead cloud security assessments across cloud and hybrid environments, ensuring secure digital transformation initiatives.
- Drive client maturity advancement through strategic road mapping, governance framework design, and risk optimization programs delivering measurable business value.
- Design incident response and business continuity programs that minimize business disruption and protect organisational reputation.
Business Development & Account Growth
- Support pre-sales activities by developing compelling proposals, conducting client presentations, and demonstrating clear ROI for cybersecurity investments.
- Identify and develop new revenue streams within existing client accounts through needs assessment, gap analysis, and strategic consulting recommendations
- Build and maintain strategic client relationships that result in multi-year consulting contracts and ongoing managed security services engagements.
Account Management
- Lead regular service review meetings to discuss performance, receive feedback, and identify growth or improvement opportunities.
- Flag upsell and cross-sell signals to the Account Manager during QBRs and governance meetings.
- Define a structured offboarding workflow to ensure clean exits, final billing accuracy, and relationship preservation for future re-engagement.
- Maintain a live stakeholder map per client (decision-makers, sponsors) to reduce relationship risk during client-side personnel changes.
What We're Looking For
- Minimum 12 years of experience in cybersecurity GRC, IT audit, or information security consulting, including senior/lead-level client delivery.
- Strong spoken and written communication. Proven ability to work directly with client stakeholders, including at the executive level.
- A multi-framework consulting environment (i.e., running concurrent ISO, SOC 2, and PCI engagements, not just one framework in-house).
- Hands-on experience running ISO 27001 audits (internal and/or certification) and building ISMS documentation from scratch.
- Working knowledge of SOC 2 (Trust Services Criteria) and at least one of: ISO 27701, ISO 42001, PCI DSS, GDPR, NIST CSF/800-53, or CMMC 2.0.
- Relevant certifications required or strongly preferred: ISO 27001 Lead Auditor/Lead Implementer, CISA, CRISC, or CISSP.
- Based in India, with flexibility to work across time zones to support Australian and other international clients.
Nice to Have
- Experience in Australian frameworks Essential Eight, APRA CPS 234.
- Prior experience mentoring junior GRC analysts/consultants.
- Exposure to GRC tooling (e.g., Vanta, Drata or similar) and ticketing/PM tools (Jira etc).
What We Offer
- The opportunity to work across a diverse portfolio of clients and compliance frameworks rather than a single in-house program.
- A senior, high-trust role with direct client ownership.
- Collaborative, experienced GRC team and clear path for growth into practice leadership.
Responsibilities:
-
Serve as the primary liaison between clients and internal teams.
- Build and maintain trusted, long-term relationships with key client stakeholders.
- Develop a thorough understanding of each client's organisation, business processes, priorities, culture, and pain points.
-
Run kick-off meetings, monthly governance meetings, and quarterly business reviews (QBRs) with clients. Conduct quarterly internal review meetings with the Account Manager to maintain transparency on account health.
-
For all clients on their reporting format, content, and frequency (executive summaries, board-level reports, detailed governance packs, meeting minutes).
- Produce and present reports using StickmanCyber-approved templates.
- Ensure supporting teams understand their responsibilities for contributing to client and internal reports. Prioritise quality over quantity.
-
Oversee end-to-end delivery across all assigned client engagements.
- Maintain a detailed project plans tracking progress, risks, milestones, scope, schedule, and costs.
- Ensure all projects are delivered on time, within scope, and within budget.
- Track and formally manage any changes to project scope, schedule, or costs via the CR process in collaboration with the team.
- Monitor and manage service delivery metrics including response times, issue resolution rates, and client satisfaction scores.
- Flag delivery risks proactively before they become client-facing issues.
-
Act as the escalation owner for all client issues. Triage, manage, and resolve escalations within defined SLAs. Report and escalate to the managers as needed, with clear context, impact assessment, and recommended resolution.
-
Work closely with internal competency teams (Technical, Compliance, SOC, etc.) to ensure positive delivery outcomes. Coordinate with the Head of Delivery on resource availability and allocation across projects. Assist teams in prioritising tasks where required to maintain delivery momentum.
-
Drive NPS scoring and structured client feedback collection at defined intervals. Work with the client's success function to gather testimonials and case study opportunities. Use feedback to identify service improvement areas and share insights with the manager.
-
Lead regular service review meetings to discuss performance, receive feedback, and identify growth or improvement opportunities.
- Flag upsell and cross-sell signals to the Account Manager during QBRs and governance meetings.
- Define a structured offboarding workflow to ensure clean exits, final billing accuracy, and relationship preservation for future re-engagement.
- Maintain a live stakeholder map per client (decision-makers, sponsors) to reduce relationship risk during client-side personnel changes.
- Bachelor’s degree in business management/IT, Computer Science, or a related field.
- 4-7 years of experience in client delivery management.
- IT project management experience.
- Solid understanding of business cases and risk management.
- Strong communication and leadership skills.
- Client-facing, client relationship & delivery focused.
- Strong problem-solving and decision-making skills.
- Ability to work independently and as part of a team.
Join StickmanCyber
We have:
No Investors, No Debt, No Greed
No Inflated Valuations, No Unrealistic Targets
Just Pure, Uncomplicated Commitment
We are accountable only to our staff and clients. This unique focus sets us apart.
We're not just running a business; we're nurturing a philosophy. Every day, we're committed to ensuring the security of our customers and the welfare of our staff. Growth is not our primary goal; our aim is to maintain fairness in pricing, pay our staff well, and reinvest profits for our staff training, new technology, innovations that is targeted for our customers' success.
We pride ourselves on being the trailblazers in the Cybersecurity as a Service (CSaaS) domain, a testament to our innovative spirit and commitment to excellence. Our business model not only generates robust recurring revenue but also ensures profitability, showcasing our operational strength and market resilience.
Our most ambitious project yet is the development of an industry-first AI-based Cybersecurity platform. This cutting-edge technology is a game-changer, poised to revolutionize how we safeguard businesses from cyber threats. By joining our team, you'll be at the forefront of this exciting venture, leveraging AI to enhance our capabilities and deliver unparalleled protection to our clients.
We're looking for passionate individuals who are eager to contribute to a larger global cybersecurity product/platform company. If you're driven by innovation, excellence, and a desire to make a significant impact in the cybersecurity world, StickmanCyber is your destination.
