Governance & Risk Compliance Analyst

1 week ago


Melbourne, Victoria, Australia McMillan Shakespeare Full time

The McMillan Shakespeare Group (MMS) is a trusted provider of salary packaging, novated leasing, disability plan management and support co-ordination, asset management and related financial products and services.

From our origins in 1988 when we created Australia's salary packaging industry to today, MMS has a proud history of innovation and exceptional service.


Through our subsidiaries, we offer a breadth of services and expertise designed to responsibly deliver superior long-term value to our clients and customers, which include Federal and State governments and some of the largest public and private sector, health and charitable organisations.

At the heart of achieving this mission is our team.

Driven by a passion for the work we do, we work together with our customers to make a real difference to people's lives.

MMSG has several compliance obligations imposed by the regulatory and contractual environment in which we operate.

The Governance Risk and Compliance Analyst role is tasked with coordinating and performing MMS security assessment and control testing reporting, analysing and monitoring strict compliance of internal IT controls, regulatory and information security policies and procedures.

This role works with internal and external audit firms to provide supportive documentation as applicable.

The role can be done from Adelaide, Brisbane, Melbourne or Sydney.


A key component of the role is monitoring compliance of IT security controls (ISO27001, ASD (Essential Eight), NIST), conducting risk assessments, supporting security education and awareness programs, ensuring staff and 3rd parties are abreast of due diligence and compliance requirements, writing business communications about new security threats and working with IT functional teams and business stakeholders to ensure baseline security requirements are met and assets remain protected within these functional areas.


The Governance Risk and Compliance Analyst is also responsible in ensuring the security of all protected information collected, used, maintained, or released by MMS.


The Role:

  • Implement security controls, maintaining and reporting risk assessment frameworks, ensuring documented and ongoing compliance that aligns and advances MMS business objectives
  • Evaluate risks and develop security procedures, and controls to manage risks, improving MMS's security positioning through process improvement, policy, automation, and the continuous evolution of capabilities
  • Conduct regular risk assessments and workshops to ensure risks to MMS are assessed and understood, and are fed back to stakeholders to ensure the continued effectiveness of the risk management strategy
  • Provide support and relevant guidance to external auditors and ensure relevant artefacts are timely provided
  • Evaluate cybersecurity standards including NIST, ASD (Essential Eight), ISO27001 and PCI DSS for alignment with internal frameworks
  • Implement processes, such as GRC (governance, risk and compliance), to automate and continuously monitor information security controls, exceptions, risks, testing
  • Ensure internal security standards, policy, audit, and contracted security requirements are communicated across the business and with 3rd Parties
  • Develop reporting metrics, dashboards, and evidence artefacts
  • Define and document business process responsibilities and ownership of the controls
  • Schedule regular assessments and testing of effectiveness and efficiency of controls and creates GRC reports
  • Document and report control failures and gaps to stakeholders, providing remediation guidance and prepare management reports to track remediation activities
  • Assists other Cyber Security team members in the management and oversight of security program functions
  • Contribute to improve risk posture, contribute solutions for remediating or mitigating risks and assess residual risks
  • Train, guide, and act as a resource on security assessment functions to other departments
  • Any other security risk and compliance initiatives, as requested.

You will bring:

  • Experience in IT Security and Risk Management such as ISO 31000.
  • Experience with legal and regulatory obligations such as the Australian Privacy Principles.
  • Experience with ISO27001, ASD Essential Eight, NIST PCI DSS
  • Tertiary qualification in a Computing/IT discipline is preferable.
  • CRISC Certification

What we can offer you:

  • Our strong peoplefirst culture
  • Flexible/hybrid working to enhance your work/life balance
  • Novated lease benefits and discounts 12 weeks Paid Parental leave and access to our Parents Portal
  • Exempt Employee Share Plan
  • Paid Income Protection Insurance under MMSG default Super plan
  • Access to a broad range of learning and development programs
  • Career break and volunteering leave
  • Access to Employee Assistance Program and annual Flu vaccination
  • Lifestyle Rewards program
As an employer who embraces Diversity, Equity & Inclusion, we hold a collective commitment to foster an en

  • Melbourne, Victoria, Australia Culture Amp Full time

    Join us on our mission to make a better world of work.Culture Amp revolutionizes how over 25 million employees across 6,000 companies create a better world of work. As the global platform leader for employee experience, Culture Amp empowers companies of all sizes and industries to transform employee engagement, develop high performing teams, and retain...

  • Risk Partner

    1 week ago


    Melbourne, Victoria, Australia Amp Full time

    Risk Consulting (Insurance & Superannuation) If you are based in Australia or New Zealand, it's highly likely that you are familiar with AMP. However, in a time when society is evolving, AMP is also undergoing significant changes. We are now operating as a more agile business with innovative leadership and fresh perspectives. These are truly exciting times...


  • Melbourne, Victoria, Australia Nixil Full time

    You will work with a range of stakeholders across the business providing information security compliance and risk management support and guidance.Additionally, you will manage cyber security policies and standards, ensure they are periodically updated and aligned them with the overall Banking Information Security Policy framework.Reporting to the Manager,...


  • Melbourne, Victoria, Australia Compliance & Risk Management Recruitment Full time

    Compliance & Risk Management Recruitment Policy, Planning & Regulation (Government & Defence) Our client is a busy and unique industry led Not for Profit training organisation. Over their multiple campuses, they provide an array of services and training courses. With a team of close to 180 people and rapidly growing they have a great job opportunity for...


  • Melbourne, Victoria, Australia Compliance and Risk Management Recruitment Full time

    Banking & Finance Other Melbourne Permanent / Full Time10th May, 2023:We are working with a growing boutique financial services business who are currently seeking a Risk & Compliance Officer for a newly created role.Key Responsibilities: Incident, breach and complaint assessments Testing and maintaining compliance Compliance checklists Review documents,...

  • Risk Partner

    1 week ago


    Melbourne, Victoria, Australia AMP Full time

    Risk Consulting (Insurance & Superannuation)If you are based in Australia or New Zealand, chances are you are familiar with AMP. However, as society evolves, so do we. We are now a more agile organization with new leadership and innovative thinking.These are thrilling times for us. There is a great opportunity for visionary individuals to assist us in...

  • Risk Officer

    1 week ago


    Melbourne, Victoria, Australia Compliance and Risk Management Recruitment Full time

    Banking & Finance Analyst Melbourne Permanent / Full Time17th February, 2023:We are working with a growing boutique financial services business who are currently seeking a Risk Officer for a newly created role in their Melbourne head office.Key Responsibilities: Incident, breach and complaint assessments Testing and maintaining compliance Compliance...

  • IT Governance, Risk

    1 week ago


    Melbourne, Victoria, Australia Crown Melbourne Full time

    Job Number: MEL14964)IT Governance, Risk & Compliance AnalystFull Time Crown MelbourneDue to the expansion of the IT Risk & Compliance team we have an opportunity for an IT Governance, Risk and Compliance (GRC) Analyst to join Crown Melbourne. Reporting to the Group Assistant Manager, IT Compliance, you will assist with the management and implementation of...


  • Melbourne, Victoria, Australia AMP Full time

    Adviser Education AnalystIf you live in Australia or New Zealand, you've likely heard of AMP. But at a time when society is changing, we are too. We're now a nimbler business with new leadership and thinking.For us, these are exciting times. There's a real potential for big thinkers to help us redefine what financial services could be. And turn our legacy...


  • Melbourne, Victoria, Australia Australia Post Full time

    Press space or enter keys to toggle section visibility Name Payroll Governance and Compliance Analyst Site / Location Ref # Entity Australia Post Opening Date 27-May-2024 Suburb Melbourne Work Type Permanent Full Time Description & RequirementsPress space or enter keys to toggle section visibility Payroll Governance and Compliance Analyst Help us...


  • Melbourne, Victoria, Australia Anton Murray Consulting Full time

    Melbourne- Asset Management- Contract or TemporaryOur client is a leading global financial services organisation seeking an experienced Risk & Compliance Analyst to join them on an initial 9-month contract.Key Responsibilities Provide Subject Matter Expert advice and effective second line review and challenge across the Australian business on the Risk...


  • Melbourne, Victoria, Australia Australia Post Full time

    Payroll Governance and Compliance AnalystHelp us deliver like never before Australia Post is delivering like never before. From the vehicles that we drive, to the small businesses that make our communities thrive. We're delivering for the environment, for our communities, for our customers and for our people. We're moving forward and we want you to come...


  • Melbourne, Victoria, Australia Bendigo & Adelaide Bank Full time

    Your new role with Bendigo Bank is just a few clicks away.As the Risk and Compliance Analyst, you will be reporting to the Head of Risk and Compliance Services with key responsibilities relating to analysing risk and compliance data for deep dives and thematic reviews related to risk, controls, events, business continuity management and compliance...


  • Melbourne, Victoria, Australia Bendigo and Adelaide Bank Full time

    Risk & Compliance Analyst (Junior)Position Description: Position Description - Risk and Compliance Analyst Your new role with Bendigo Bank is just a few clicks away.As the Risk and Compliance Analyst, you will be reporting to the Head of Risk and Compliance Services with key responsibilities relating to analysing risk and compliance data for deep dives and...

  • Global Esop

    1 week ago


    Melbourne, Victoria, Australia Culture Amp Full time

    Join us on our mission to make a better world of work.Culture Amp revolutionizes how over 25 million employees across 6,000 companies create a better world of work. As the global platform leader for employee experience, Culture Amp empowers companies of all sizes and industries to transform employee engagement, develop high performing teams, and retain...


  • Melbourne, Victoria, Australia Compliance and Risk Management Recruitment Full time

    Admin / Secretarial / Office Support Other Melbourne Permanent / Full Time16th February, 2023:We are working with a boutique, culture focussed Australian asset management business. They are a commercial business with exciting initiatives and set up for success. They are looking for a compliance professional to work alongside a team of highly skilled asset...


  • Melbourne, Victoria, Australia Compliance and Risk Management Recruitment Full time

    Education & Child Care Secondary Other Melbourne Permanent / Full Time20th March, 2023:Our client is a leading co-educational catholic school located in the South East of Melbourne. With a culture of continuous improvement coupled with respect, collaboration, and generosity they boast a long -term staff tenure on large & impressive grounds designed to...


  • Melbourne, Victoria, Australia Kaizen Recruitment Full time

    Growing Australian fund manager Collaborative & closeknit team | Eastern suburbs location Outstanding career development opportunityOur client is a growing Australian fund manager who is in search of a Risk and Compliance Manager to drive risk culture, manage internal processes and procedures, provide advice to the leadership team and Board, and upskill and...


  • Melbourne, Victoria, Australia Johnson Recruitment Full time

    Highly regarded not for profit Melbourne city fringe/hybrid Broad executive leadership role Circa $150K + super, and attractive NFP salary packaging Highly regarded not for profit Melbourne city fringe/hybrid Broad executive leadership role Circa $150K + super, and attractive NFP salary packagingThe Organisation: Based in Inner East/City fringe and close to...


  • Melbourne, Victoria, Australia Culture Amp Full time

    The Opportunity at Culture AmpThis is a truly unique opportunity to lead corporate communications for Culture Amp, within the Brand and Communications team.We are the storytellers, curators and custodians of translating strategy, company values and our view on the world of work.The Director, Corporate Communications will step into a new role at Culture Amp,...