Work with cutting-edge AI technology that helps make the world a safer and more secure place. DroneShield (ASX:DRO) develops market-leading counter-drone solutions used by military organisations, government agencies, airports, critical infrastructure operators, and law enforcement operating in some of the most challenging and high-stakes environments in the world. Employees work at the forefront of innovation, solving complex technical problems and delivering mission-critical capabilities where performance, reliability, and speed matter.
As an ASX200-listed company and the world's only publicly listed pure-play counter-drone business, DroneShield is experiencing rapid growth. Revenue increased from A$57 million in 2024 to more than A$217 million in 2025, supported by record profitability, a global sales pipeline exceeding A$2.5 billion, and annual R&D investment of over A$50 million.
Since 2017, DroneShield has grown from 11 employees to more than 550 globally, with operations across Australia, the United States, Europe, and the Middle East, supporting customers in over 70 countries.
The role is based at DroneShield's Sydney headquarters, which houses corporate, commercial, engineering, and operational teams supporting the company's global growth and customer base.
About the role
DroneShield is looking for a Cyber Security GRC Engineer to support the operation and continual improvement of DroneShield’s governance, risk and compliance programme. Reporting to the Cyber Security GRC Specialist, this role contributes to maintaining an audit-ready security posture, consistent and scalable governance across DroneShield’s global operations and risk-informed business decision-making.
You will support ISO 27001 and core governance, risk and compliance processes, including surveillance and recertification audits, continual improvement of the ISMS, risk management, control assurance and the development of scalable, low-friction compliance processes. You will also contribute to customer and regulatory assurance activities and support alignment with frameworks such as ISM, PSPF, DISP, CMMC and NIST where required.
As part of the broader remit, you will help operate DroneShield’s third party and supply chain security programme, including vendor due diligence, security assessments, remediation tracking, ongoing monitoring and reporting.
This is an engineering role within a GRC function. A significant part of the role involves operating ISMS and supply-chain processes, including audits, evidence management, risk registers, vendor assessments and remediation tracking. The other major component is engineering better ways to perform that work. You will use scripting, APIs, integrations and workflow automation to improve evidence collection, assessments, reminders and reporting, replacing manual spreadsheet-based processes where practical. If your GRC experience has been limited to manual compliance activities and you have not used technology to improve a process, this role is unlikely to be the right fit.
Responsibilities, Duties and Expectations
- Support the operation and continual improvement of the ISO 27001 ISMS, including surveillance and recertification audits, evidence collection and corrective-action tracking.
- Assist with internal audits, control validation and broader GRC assurance activities across corporate, infrastructure, cloud and product environments.
- Maintain accurate GRC records, including risks, controls, evidence, non-conformities, exceptions and remediation actions.
- Support cyber risk assessments and the maintenance of the cyber risk register.
- Support the mapping and alignment of controls to relevant frameworks, including the ISM, PSPF, DISP, CMMC, NIST CSF and NIST SP 800-171.
- Contribute to customer, tender and regulatory assurance responses using accurate, reusable and scalable evidence.
- Support policy and standard lifecycle activities, including scheduled reviews, stakeholder consultation and publication.
- Operate third party and supply chain security processes, including vendor intake, risk classification, due diligence, security assessment, remediation tracking, ongoing monitoring and offboarding.
- Review vendor questionnaires, certifications, audit reports and other security assurance evidence.
- Maintain vendor risk records and track material findings and remediation actions, escalating risks and exceptions to the GRC Specialist as required.
- Work with Procurement, Legal, IT, Security, Engineering and business owners to incorporate proportionate security checks into vendor onboarding, renewal and offboarding.
- Design and build automation for evidence collection, assessment workflows, reminders, reporting and other compliance activities.
- Build and maintain integrated dashboards and metrics covering control effectiveness, audit readiness, risk and remediation progress, avoiding duplicate or standalone reporting processes.
Qualifications, Experience and Skills
- BS degree in Computer Science, Information Technology, or a similar technical field, or equivalent practical experience.
- Demonstrated practical experience in cyber security GRC, technology risk, third party risk, security assurance, audit or a related field.
- Candidates would typically bring 3-5 years of relevant experience in related roles, which may include:
- GRC Consultant
- Security Engineer
- Security Analyst
- Compliance and Risk Officer
Essential knowledge and experience:
- Practical experience supporting an ISO 27001 ISMS, audit lifecycle or comparable security assurance programme.
- Experience conducting or supporting risk assessments, control assessments, compliance reviews or third-party security assessments.
- Practical scripting or integration experience (Python, PowerShell, REST APIs, Jira or Power Automate workflows or similar) that you have used to automate a compliance, reporting or assessment task. Be ready to talk through something you built.
- Ability to review security and compliance evidence, identify gaps and communicate findings clearly.
- Strong organisational skills, with the ability to manage multiple assessments, actions and stakeholders.
- Clear written and verbal communication skills.
Desirable
- Exposure to ISM, PSPF, DISP, CMMC, NIST 800-53, NIST CSF or NIST SP 800-171.
- Familiarity with GRC platforms, workflow tools, evidence repositories or AI-assisted assessment technologies.
- Experience introducing automation using AI or low-code technologies.
- Comfortable working on the command line in a Linux environment.
- Project management techniques and processes.
- Relevant ISO 27001, audit, risk or cyber security training or certification.
Note for recruitment agencies: We do not accept unsolicited candidates from external recruiters unless specifically instructed.
Data Privacy
DroneShield Group Pty Ltd collects and processes personal information for recruitment and hiring purposes. Where applicable, personal information is processed on the basis of DroneShield's legitimate interests in assessing and selecting candidates for employment. For further information regarding how we collect, use, disclose, store and retain personal information, including your privacy rights, please refer to our Privacy Policy: https://www.droneshield.com/privacy-policy

