IT Security GRC Manager
5 days ago
MinterEllison is one of Australia's largest law firms, with nearly 200 years of business history. We're known for our legal and consulting expertise - and for our inclusive and authentic character.
Our purpose is to create sustainable value with our clients, people and communities. That means we have a proud history of providing excellence to clients, nurturing our people and giving back to the communities in which we live and work.
We value excellence, curiosity and collaboration. Clients rely on us for our responsive, commercial approach. Our clients include government departments and agencies, private and publicly listed companies, and small and large businesses in Australia and overseas.
We are currently recruiting for an experienced IT Security GRC Manager to join our internal digital team based in either our Sydney, Melbourne or Brisbane office. In this role, you will be responsible for managing and maintaining the end to end IT security GRC portfolio under our IT security assurance practice. The IT security assurance practice covers: cyber risk management, compliance framework and certification program, client assurance and contract reviews, supply chain security, internal audit, and cyber awareness program.
The ideal candidate will possess in depth experience and knowledge in information systems environment with at least 2 to 3 years hands on, direct experience in managing assurance programs. This is a senior role reporting into the CISO, and will also be 2IC to CISO as required. The desired candidate will be motivated and excited to inspire people at all levels of the business to implement and uphold information security best practices and standards. This role will involve working collaboratively with a cross-section of teams across business operations and will have one direct report.
Agile working arrangements are supported at the firm with a minimum or 3 days in the office required.
In this role you will have the opportunity to:- Uplift and develop a high-performing IT security GRC practice across all IT security assurance areas, fostering a culture of excellence, collaboration, and continuous learning
- Implement a robust IT security compliance framework program integrating multiple compliance certification, frameworks, policies and standards
- Lead and maintain certifications across multiple standards/frameworks and internal audits
- Perform cyber hygiene audits to ensure compliance with external and internal policies, regulations, standards and compliance with client contracts
- Lead client assurance program including responding to client audits/questionnaires, reviewing client cybersecurity contracts, updating MinterEllison Trust Centre and maintaining a high client engagement & experience
- Collaborate with Chief Risk Office to manage and maintain cyber risk lifecycle including cyber risk registers and dashboards
- Lead supply chain cyber risk management program including annual reviews and spot checks
- Maintain cyber security awareness and training programs including role-based training across the Firm
- Provide high quality reporting and updates on cyber security to senior leadership including KPIs/KRIs
- Assist with IT security operations on any cybersecurity incidents during and, if required, after business hours
- Ensure efficient use of managed security services and/or external consultants in the GRC domain.
- People leadership responsibility for one direct report.
- 8 years+ demonstrated, direct, hands on experience in the above mentioned GRC areas, including 2-3 years hands on, direct experience in managing assurance programs
- Strong written and verbal communication skills to engage with all levels of business
- Pragmatic and collaborative with various stakeholders with the ability to bring people on a journey
- Demonstrated experience in writing high quality executive reports/briefings
- Expert knowledge of information security principles, standards and frameworks such as ISO27001. Familiarity with of NIST, SSAE16, APRA CPS234, ASD essential 8, VPDSF
- Knowledge of security policies, standards, and practices.
- Knowledge of the infrastructure, operations, and systems of information technology.
- Agile-mindset, incremental delivery over perfection, willingness to try new approaches to a problem
- Ability to manage projects and tasks independently with little supervision
- Relevant security trainings/certifications not mandatory but will be highly desirable
- Ability to use GenAI models and other pragmatic approaches to improve efficiencies/quality or delivery
- Be up-to-date with information security best practices and industry trends for security solutions and standards
We offer flexible working options to encourage balance, wellbeing and support for sustainable ways of working and a range of social, financial and health benefits, including free gym membership - all with no minimum tenure.
We encourage applications from people of all ages, abilities, cultural backgrounds, genders (including trans or gender diverse), LGBTQ+ people and those with carer responsibilities. We particularly encourage Aboriginal and Torres Strait Islander people to apply.
How to applyWe prefer to connect with people directly, so please submit your CV by clicking on the 'Apply' button. We encourage all applications, including if you do not meet the criteria listed for the role. Your application will also enable us to consider you for other opportunities that may be available at MinterEllison.
If you are currently a MinterEllison employee, please apply through the internal careers page.
If you would like further information, require any adjustments throughout the recruitment process or for a confidential discussion, please contact Miriam.Harner@minterellison.com.
#J-18808-Ljbffr-
IT Security GRC Manager
5 days ago
Sydney, New South Wales, Australia Minter Ellison Full timeMinterEllison is one of Australia's largest law firms, with nearly 200 years of business history. We're known for our legal and consulting expertise - and for our inclusive and authentic character.Our purpose is to create sustainable value with our clients, people and communities. That means we have a proud history of providing excellence to clients,...
-
GRC Portfolio Manager
5 days ago
Sydney, New South Wales, Australia xceltium Full timeIT Security GRC Portfolio ManagerXceltium is seeking an experienced IT Security GRC Portfolio Manager to join our team. As a seasoned professional, you'll be responsible for managing and maintaining the end-to-end IT security GRC portfolio within the IT security assurance practice.This role involves developing and leading a high-performing IT security GRC...
-
IT Security GRC Manager
5 days ago
Sydney, New South Wales, Australia xceltium Full timeLacking a great mentor and leader who will develop you and give you a progression path to elevate your career?I get it. I've been there. You know what you want but you're not getting it where you are.You want an environment where you can grow, progress and build your skills.You want ownership and empowerment where you can make your mark and drive tangible...
-
IT Security GRC Manager
2 days ago
Sydney, New South Wales, Australia xceltium Full timeLacking a great mentor and leader who will develop you and give you a progression path to elevate your career?I get it. I've been there. You know what you want but you're not getting it where you are.You want an environment where you can grow, progress and build your skills.You want ownership and empowerment where you can make your mark and drive tangible...
-
ServiceNow GRC Consultant
1 week ago
Sydney, New South Wales, Australia Jenkin Beattie Full time2 days ago Be among the first 25 applicantsDirect message the job poster from Jenkin BeattieSenior Consultant | ServiceNow | Microsoft Dynamics 365Junior GRC ServiceNow Consultant – Melbourne/Sydney/BrisbaneStart Date: End of April/MayAbout the Role:We're on the lookout for a Junior GRC ServiceNow Consultant to join a leading consultancy and be involved in...
-
GRC Consultant
7 days ago
Sydney, New South Wales, Australia Minter Ellison Full timeJob DescriptionWe are seeking a seasoned professional to join our dynamic Governance, Risk and Compliance (GRC) team.The ideal candidate will have experience in GRC solutions, risk management frameworks, and governance practices. They will work closely with senior leaders to deliver high-profile GRC engagements with leading Australian organisations.In this...
-
Risk Management and IT Security Lead
5 hours ago
Sydney, New South Wales, Australia Minter Ellison Full timeJob DescriptionWe are currently recruiting for an experienced IT Security GRC Manager to join our internal digital team based in either our Sydney, Melbourne, or Brisbane office.In this role, you will be responsible for managing and maintaining the end-to-end IT security GRC portfolio under our IT security assurance practice. The practice covers cyber risk...
-
Senior Principal- GRC
5 days ago
Sydney, New South Wales, Australia Infosys Singapore & Australia Full timeLocation: Sydney/Melbourne, Please do not apply if you reside outside of Australia.Infosys Consulting works with clients to develop and implement innovative strategies and drive process improvements that create business value, including technology-enabled business transformation. We look for opportunities to improve financial, risk and operational...
-
Information Security Leader
5 days ago
Sydney, New South Wales, Australia Minter Ellison Full timeMinter Ellison has a proud history of providing exceptional service to clients, nurturing our employees, and giving back to the communities we serve. We value excellence, curiosity, and collaboration.We are currently recruiting for an experienced IT Security GRC Manager to join our internal digital team based in Sydney, Melbourne, or Brisbane offices. In...
-
GRC Portfolio Manager
5 days ago
Sydney, New South Wales, Australia Minter Ellison Full timeMinter Ellison, one of Australia's largest law firms, offers flexible working options to encourage balance, wellbeing, and support for sustainable ways of working. We provide a range of social, financial, and health benefits, including free gym membership.We encourage applications from people of all ages, abilities, cultural backgrounds, genders (including...
-
IT Security Governance Lead
5 hours ago
Sydney, New South Wales, Australia xceltium Full timeJob DescriptionXceltium OverviewXceltium is a highly profitable global professional services business with a strong track record of investment in technology and people. Our team views technology as a key strategic enabler, driving growth and innovation.We're looking for an experienced IT Security GRC Manager to join our team and lead the development and...
-
Senior Consultant
5 days ago
Sydney, New South Wales, Australia Minter Ellison Full timeAbout the RoleWe are seeking an experienced Manager to join our dynamic and fast-growing Governance, Risk and Compliance (GRC) team. As a Senior Consultant - GRC Solutions, you will have the opportunity to work on high-profile client projects, delivering exceptional outcomes while managing and developing a team of Consultants.Manage responsibility in the...
-
Information Security Manager
1 day ago
Sydney, New South Wales, Australia xceltium Full timeThe role of the Information Security Manager - Compliance and Risk at xceltium is to oversee the management and maintenance of the end-to-end IT security GRC portfolio within the IT security assurance practice.This practice covers cyber risk management, compliance framework and certification program, client assurance and contract reviews, supply chain...
-
Sydney, New South Wales, Australia NTT America Solutions, Inc. Full timeWe are looking for a highly experienced GRC Consultant: Cybersecurity Risk Reduction to join our team at NTT America Solutions, Inc. As a key member of our advisory services team, you will be responsible for delivering security consultations to clients, leading risk assessments and gap analyses, and developing security policies and procedures.The successful...
-
Grc Senior Consultant/ Security Advisor
2 weeks ago
Sydney, New South Wales, Australia Wipro Shelde Full timeGet AI-powered advice on this job and more exclusive features.Direct message the job poster from Wipro Shelde Talent Acquisition Partner/ Recruitment Specialist ABOUT US Wipro Shelde Australia is a sovereign cybersecurity offering for the Australian market based on the philosophy of defending organisations against modern-day threats while enabling business...
-
IT Security Professional
2 days ago
Sydney, New South Wales, Australia NTT America Solutions, Inc. Full timeYour Day at NTT DATA: As a Senior Security Consultant (GRC), you will be responsible for leading maturity and risk assessments, developing security policies, ensuring alignment with industry standards and regulations, and providing guidance and support to junior members of the security consultancy team. You will work closely with clients to understand their...
-
Information Security Manager
5 hours ago
Sydney, New South Wales, Australia Minter Ellison Full timeAbout YouWe're looking for a highly skilled individual with at least 8 years of demonstrated, direct experience in the GRC areas, including 2-3 years of hands-on experience in managing assurance programs.You'll need strong written and verbal communication skills to engage with all levels of business, as well as pragmatic and collaborative abilities to bring...
-
SAP GRC Access Controls Expert
3 days ago
Sydney, New South Wales, Australia Paxus - Technology + Digital Talent Full timeAbout the Role:This is an exciting opportunity for a seasoned SAP Security expert to join our team as a Business Security Solutions Specialist.Key Responsibilities:Design, build, and test innovative business solutions using SAP systems integration.Leverage your leadership skills to drive successful project delivery and client satisfaction.Pursue unique...
-
Security Program Manager
7 days ago
Sydney, New South Wales, Australia Pyramid Global Technologies Full timeJob Description of Security Program Manager in Sydney:14 to 20 years (Minimum 8 to 10 years experience in Cyber Security domain)Lead and manage Cybersecurity Landscape for client and ensure all deliverables with respect to contract by providing thought leadership & supporting cybersecurity strategy.Managing various Security tracks within the account (such as...
-
Information Security Governance Expert
5 days ago
Sydney, New South Wales, Australia xceltium Full timeXceltium: Where Careers ThriveWe're seeking an experienced professional to join our team as a Cybersecurity Assurance Leader. In this role, you'll have the opportunity to develop and lead a high-performing IT security GRC practice, fostering a culture of excellence, collaboration, and continuous learning.Your responsibilities will include managing and...