Cyber Compliance Analyst

2 weeks ago


Melbourne, Victoria, Australia McMillan Shakespeare Group Full time

The McMillan Shakespeare Group (MMS) is a trusted provider of salary packaging, novated leasing, disability plan management and support co-ordination, asset management and related financial products and services.

From our origins in 1988 when we created Australia's salary packaging industry to today, MMS has a proud history of innovation and exceptional service.


Through our subsidiaries, we offer a breadth of services and expertise designed to responsibly deliver superior long-term value to our clients and customers, which include Federal and State governments and some of the largest public and private sector, health and charitable organisations.

At the heart of achieving this mission is our team.

Driven by a passion for the work we do, we work together with our customers to make a real difference to people's lives.

MMSG has several compliance obligations imposed by the regulatory and contractual environment in which we operate.

The Cyber Compliance Analyst is tasked with analysing and monitoring strict compliance of internal IT general and cyber controls, providing support in internal and external audits and contributing to improving risk posture of our digital and traditional on-premises services.


A key component of the role is monitoring compliance of IT security controls (ISO27001, ASD (Essential Eight), NIST), conducting risk assessments, managing security education and awareness programs, ensuring staff and 3rd parties are abreast of due diligence and compliance requirements, writing business communications about new security threats and working with IT functional teams and business stakeholders to ensure baseline security requirements are met and assets remain protected within these functional areas.


The Cyber Compliance Analyst is also responsible for developing, maintaining and reporting risk management frameworks that aim to protect the confidentiality, availability and integrity of group assets including data.

The role also requires experience in IT General controls and/or IT Audits, preferably from a Big4 or consulting experience background.


Key Responsibilities:

  • Map existing contracts against security standards identifying potential gaps in compliance and for input into the information security policy and standards
  • Provide support and relevant guidance to external IT auditors and ensure relevant artefacts are timely provided
  • Evaluate cybersecurity standards including NIST, ASD (Essential Eight), ISO27001 and PCI DSS for alignment with internal frameworks
  • Ensure internal security standards, policy, audit, and contracted security requirements are communicated across the business and with 3rd Parties
  • Ensure 3rd parties comply with all relevant due diligence obligations and provide regular attestations
  • Manage the cybersecurity education, training and awareness program and educate employees in security best practices
  • Periodically conduct security reviews and workshops to report business effectiveness in meeting documented standards, controls, and compliance to contractual or policy objectives
  • Oversee the Information, Communication and Technology Risk management framework
  • Conduct regular risk assessments and workshops to ensure risks to the organisation are assessed and understood, and are fed back to stakeholders to ensure the continued effectiveness of the risk management strategy
  • Contribute to improve risk posture, contribute solutions for remediating or mitigating risks and assess residual risks
  • Work with all stakeholders to educate and identify controls and compliance requirements that are applicable
  • Respond to information security incidents, as requested
  • Maintain and develop cyber incident response processes and procedures when new threats to the organisation arise
  • Be an active participant in incident management to support controlled and coordinated responses
  • Contribute to policy development
  • When necessary, prepare Post Incident Reviews
  • Any other security risk and compliance initiatives, as requested.

You will bring:

  • Experience with IT General Controls and/or IT Audits is essential
  • Experience with legal and regulatory obligations such as the Australian Privacy Principles.
  • Experience with ISO27001 a formal certification is a basic requirement

Not essential but advantageous if you have experience in:

  • IT Security and Risk Management such as ISO 31000
  • ASD Essential Eight = preferred but not compulsory
  • NIST = nice to have but not essential
  • PCI DSS = nice to have
  • CRISC Certification nice to have

What we can offer you:

  • Our strong peoplefirst culture
  • Flexible/hybrid working to enhance your work/life balance
  • Novated lease benefits and discounts
  • 12 weeks Paid Parental leave and access to our Parents Portal
  • Exempt Employee Share Plan
  • Paid Income Protection Insurance under MMSG default Super plan
  • Access to a broad range of learning and development programs
  • Career break and volunteering leave
  • Access to Emp


  • Melbourne, Victoria, Australia Cyber Crime Full time

    Lead and manage requirements for cyber security initiatives and improvementsDevelop business cases and cost-benefit analyses for cyber security investmentsMax term contractProgram Visionary: Lead Business Analysis for Cyber SecurityInsignia Financial is transforming its cyber security landscape with a strategic 3-year program, encompassing four strategic...


  • Melbourne, Victoria, Australia Cyber Crime Full time

    Lead and manage requirements for cyber security initiatives and improvements Develop business cases and cost-benefit analyses for cyber security investments Max term contract Program Visionary: Lead Business Analysis for Cyber Security Insignia Financial is transforming its cyber security landscape with a strategic 3-year program, encompassing four strategic...


  • Melbourne, Victoria, Australia Cyber Crime Full time

    Lead and manage requirements for cyber security initiatives and improvementsDevelop business cases and cost-benefit analyses for cyber security investmentsMax term contractProgram Visionary: Lead Business Analysis for Cyber SecurityInsignia Financial is transforming its cyber security landscape with a strategic 3-year program, encompassing four strategic...


  • Melbourne, Victoria, Australia Cyber Crime Full time

    Head of Cyber Security Strategy & Governance Insignia Financial Helping Australians secure their financial wellbeing. View company page Champion transformation, building a future-proof cyber security framework for Insignia Financial Lead an expert team, fostering a culture of security awareness and best practices Position Insignia Financial as a cyber...

  • Cyber Grc Analyst

    2 weeks ago


    Melbourne, Victoria, Australia FourQuarters Full time

    The Company***This large critical infrastructure organisation has a multitude of projects in the pipeline across 3rd party risk and Identity.Due to this, a new role for a Cyber GRC Analyst has been created to perform the work above as well as generalist security governance, risk and compliance functions.The RoleThis job opportunity would suit someone who has...


  • Melbourne, Victoria, Australia Ignite Specialist Recruitment Services Full time

    Contract TypeContractReferenceBH-369650IndustryITSalaryNegotiable The Security Expert will provide services as a senior information and cyber security analyst, to oversee the technical implementation and delivery of a suite of priority cyber security services to the department and its partners, including the Australian Signals Directorate (ASDs) recommended...


  • Melbourne, Victoria, Australia Compare Club Full time

    St Kilda Rd office with flexible working environment Vibrant & inclusive culture Small, dynamic team, where a proactive, problemsolving approach is requiredCompare Club is one of Australia's leading personal finance marketplaces. We have over 280 employees across Melbourne, Sydney, Brisbane. Our experts make it easy to find better value health insurance,...


  • Melbourne City Centre, Victoria, Australia Parliament of Victoria Full time

    About the roleWe have an exciting opportunity for a Cyber Security professional. Reporting to the Cyber Security Coordinator you will work closely with the IT Team on Cyber Security activities within the Parliament of Victoria. You will play a vital role in keeping Parliament's proprietary and sensitive information secure.As Cyber Security Analyst you will...


  • Melbourne City Centre, Victoria, Australia Parliament of Victoria Full time

    Parliament of Victoria - Department of Parliamentary ServicesWe have an exciting opportunity for a Cyber Security professional. Reporting to the Cyber Security Coordinator you will work closely with the IT Team on Cyber Security activities within the Parliament of Victoria. You will play a vital role in keeping Parliament's proprietary and sensitive...


  • Melbourne, Victoria, Australia Public Sector People Full time

    As soon as possible start Hybrid working Inner Melbourne location- $700 daily rate + superPublic Sector People (PSP) are currently looking to speak to aCyber Security Analyst would be interested in a 6-month contract within Local Government.- _As soon as possible start date _- _6-month contract with potential extension_- _Inner Melbourne location_- _Hybrid...


  • Melbourne, Victoria, Australia ENGIE Full time

    Cyber Security Analyst - Industrial Control SystemsOur Cyber Security team is growing We are seeking a Cyber Security Analyst with specific experience with Industrial Control Systems operating systems, particularly power stations, to join our Cyber Security team to analyse and monitor ENGIE's cyber security measures and be responsible for the remediation,...

  • Grc Cyber Analyst

    2 weeks ago


    Melbourne, Victoria, Australia Arup Full time

    Joining ArupArup's purpose, shared values and collaborative approach has set us apart for over 75 years, guiding how we shape a better world.As a governance, risk and compliance (GRC) cyber analyst for our growing global cyber securityteam you will help protect Arup's digital infrastructure and data from cyber-attack. You will help toassess Arup's...


  • Melbourne, Victoria, Australia IOOF Holdings Limited Full time

    Exciting Opportunity to Join a Best-in-Class Cyber TeamDevelop broad experience in cyber security operationsWork alongside an inspiring, supportive, and collaborative Cyber teamBuild Your Expertise: Become a Cyber Security ProfessionalAre you looking to kickstart your career in the dynamic world of cyber security? Insignia Financial is in the process of...


  • Melbourne, Victoria, Australia Randstad Australia Full time

    Responsibilities:Conduct PCI DSS and NIST assessments to evaluate the current security landscape.Perform vulnerability assessments and implement patching procedures.Review and analyze network configurations and security measures.Investigate the organization's cyber footprint to identify potential risks and areas for improvement.Provide detailed reports on...


  • Melbourne, Victoria, Australia Randstad Australia Full time

    Responsibilities:Conduct PCI DSS and NIST assessments to evaluate the current security landscape.Perform vulnerability assessments and implement patching procedures.Review and analyze network configurations and security measures.Investigate the organization's cyber footprint to identify potential risks and areas for improvement.Provide detailed reports on...


  • Melbourne, Victoria, Australia ENGIE Group Full time

    Select how often (in days) to receive an alert: Cyber Security Analyst - Industrial Control Systems Requisition ID: 18596 Location: Southbank, AU, 3006 Our Cyber Security team is growing We are seeking a Cyber Security Analyst with specific experience with Industrial Control Systems operating systems, particularly power stations, to join our Cyber...


  • Melbourne, Victoria, Australia Insignia Financial Full time

    Exciting Opportunity to Join a Best-in-Class Cyber TeamDevelop broad experience in cyber security operationsWork alongside an inspiring, supportive, and collaborative Cyber teamBuild Your Expertise: Become a Cyber Security ProfessionalLooking to kickstart your career in cyber security? Insignia Financial is assembling an exceptional cyber security team and...


  • Melbourne, Victoria, Australia Caleb and Brown Pty Ltd Full time

    Caleb & Brown is the world's leading cryptocurrency brokerage, providing a professional service by which our clients can safely buy, sell and swap cryptocurrencies through their very own personal broker. Founded by a small team of crypto experts in 2016, we have grown to a team of 55 staff with offices in Australia and Europe, serving 20,000 clients across...


  • Melbourne, Victoria, Australia Randstad Australia Full time

    Responsibilities:Collaborate with the Cyber Security Analyst to support PCI DSS and NIST assessment activities.Gather and document business requirements related to security assessments and compliance.Analyze and interpret data to identify security gaps and recommend solutions.Facilitate communication between technical and non-technical stakeholders to ensure...


  • Melbourne, Victoria, Australia Randstad Australia Full time

    Responsibilities:Collaborate with the Cyber Security Analyst to support PCI DSS and NIST assessment activities.Gather and document business requirements related to security assessments and compliance.Analyze and interpret data to identify security gaps and recommend solutions.Facilitate communication between technical and non-technical stakeholders to ensure...