Senior Cyber GRC Specialist

3 weeks ago


Sydney, New South Wales, Australia Ampol Full time
Overview

Senior Cyber GRC Specialist role at Ampol. Ampol is Australia's only owned fuel brand, with a focus on delivering value through technology and data-driven transformation.

About the role

The Cyber, Risk & Governance teams protect Ampol Group's reputation and social license to operate by enhancing cyber resilience. The Senior GRC Analyst will support cyber security governance, risk and compliance across Ampol, including IT suppliers, outsourced providers, and internal IT environments. Responsibilities include assessing, aligning, and testing security controls to meet regulatory obligations and industry best practices.

You'll take us further by
  • Translating strategy into action: execute policy updates, risk assessments, and compliance checks.
  • Managing workflows: own GRC tasks such as control testing, risk reviews, third-party assessments, and audit preparation.
  • Conducting assessments: lead or assist with cyber risk assessments, control gap analyses, and audits.
  • Maintaining registers and dashboards: keep risk registers, control libraries, and compliance tracking tools up to date.
  • Preparing reports and presentations: draft reports for management and governance forums to show risk and compliance status.
  • Tracking KPIs and KRIs: monitor indicators and escalate deviations with context and recommended actions.
  • Cross-functional liaison: build relationships with stakeholders across Ampol including technology managers within the Technology, Digital & Data function.
  • Identifying improvement opportunities and implementing enhancements with minimal supervision.
  • Team support: assist Cyber GRC team members to foster a culture of excellence.
We'd love it if you have
  • Strong knowledge of industry environments, architecture, technologies, and IT services with cyber risk management expertise.
  • Excellent stakeholder management and ability to reach consensus among diverse views.
  • Strong planning and organisational skills with the ability to balance priorities.
  • Demonstrated expertise in regulations (e.g., Privacy Act 1988, Critical Infrastructure Act 2018), standards (e.g., PCI DSS), and frameworks (e.g., NIST CSF, ISO 27001).
  • General IT experience including knowledge of development, operations, and change management.
  • Experience with project management methodologies to help teams meet deadlines.
  • Analytical, problem-solving, and decision-making abilities to address technology challenges.
We'll take you further by
  • Competitive total remuneration including base salary, performance incentive, employee share offers, and a 25% discount on fuel for two privately used cars.
  • Flexible/hybrid work options.
  • Internal recognition platform and career development opportunities.
  • Family-friendly benefits including BabyCare Package and novated lease options.
  • Employee Share Scheme and access to discounts through Ampol Benefits & Recognition platform.
  • Paid volunteering day per year with Ampol Foundation partners.

We're an equal opportunity workplace. We celebrate diversity and inclusion and welcome applications from people of all ages, cultural backgrounds, and diverse sexualities and genders. Aboriginal and Torres Strait Islander peoples are encouraged to apply.

Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Information Technology
  • Industries: Oil and Gas

Referrals increase your chances of interviewing at Ampol. For job alerts and more, visit Ampol's career site.


#J-18808-Ljbffr

  • Sydney, New South Wales, Australia Ampol Full time

    OverviewSenior Cyber GRC Specialist role at Ampol. Ampol is Australia's only owned fuel brand, with a focus on delivering value through technology and data-driven transformation.About the roleThe Cyber, Risk & Governance teams protect Ampol Group's reputation and social license to operate by enhancing cyber resilience. The Senior GRC Analyst will support...


  • Sydney, New South Wales, Australia Naviro Full time

    OverviewItalian Speaking Cyber Security GRC Specialist – Naviro, Sydney, New South Wales, Australia.EngagementContract, up to 3 months.Base pay rangeA$120.00/hr - A$150.00/hrClient needThey have a contract requirement (up to 3 months) looking for an Italian speaking Cyber Security GRC Specialist. Client's need for Italy's Cloud Strategy Attestation: CSPs...


  • Sydney, New South Wales, Australia Naviro Full time

    OverviewItalian Speaking Cyber Security GRC Specialist – Naviro, Sydney, New South Wales, Australia.EngagementContract, up to 3 months.Base pay rangeA$120.00/hr - A$150.00/hrClient needThey have a contract requirement (up to 3 months) looking for an Italian speaking Cyber Security GRC Specialist. Client's need for Italy's Cloud Strategy Attestation: CSPs...


  • Sydney, New South Wales, Australia Naviro Full time

    OverviewItalian Speaking Cyber Security GRC Specialist – Naviro, Sydney, New South Wales, Australia.EngagementContract, up to 3 months.Base pay rangeA$120.00/hr - A$150.00/hrClient needThey have a contract requirement (up to 3 months) looking for an Italian speaking Cyber Security GRC Specialist. Client's need for Italy's Cloud Strategy Attestation: CSPs...

  • Senior GRC Analyst

    1 week ago


    Sydney, New South Wales, Australia Oscar Zhao Full time

    Join a global insurance broker Your new company A global general insurance broker is seeking a permanent Senior GRC Analyst to join their Cybersecurity Team in Sydney. This role will involve owning the IT risk management process and cyber security governance processes. Your new role Reporting to the CISO, your new role will be varied and...

  • Senior GRC Analyst

    2 weeks ago


    Sydney, New South Wales, Australia Hays Full time $140,000 - $150,000 per year

    Competitive SalaryPermanent full-time opportunityOpportunity to UpskillYour new companyA global general insurance broker is seeking a permanent Senior GRC Analyst to join their Cybersecurity Team in Sydney. This role will involve owning the IT risk management process and cyber security governance processes.Your new roleReporting to the CISO, your new role...

  • Cyber Governance Lead

    2 weeks ago


    Sydney, New South Wales, Australia beBeeCyber Full time $120,000 - $140,000

    Senior Cyber Governance SpecialistThis role involves operating at the intersection of cyber strategy, governance, risk, and technical execution. The selected candidate will work with a fast-growing organisation to find solutions that ensure optimal performance.Key Responsibilities:Conduct assessments using NIST CSF, ISO 27001, and other frameworks to...


  • Sydney, New South Wales, Australia Quay Appointments Full time

    **$1000+super per day**:- **6 months**:- **WFH/ Chatswood Hybrid**Join a High Profile State Government program and **collaborative and supportive team****About Our Client**Our client is looking for motivated The Cyber Security Specialist Practitioner is responsible for the coordination and delivery of a range of specialised cyber security services resulting...


  • Sydney, New South Wales, Australia beBeeCyberSecurity Full time $120,000 - $150,000

    Cyber Security GRC Specialist Job OverviewA Cyber Security GRC Specialist with Italian language proficiency is required to support a client's Italy Cloud Strategy Attestation.Key Responsibilities:Compliance ManagementDocumentation and CertificationRisk Management and Business ContinuityRequirements:Technical Skills: network security, cloud security, risk...


  • Sydney, New South Wales, Australia Laing O'Rourke group Full time

    About Laing O'RourkeLaing O'Rourke is a $6 billion international operation with 70 years of involvement in Australian construction and infrastructure, including nearly two decades under the Laing O'Rourke banner. The business delivers projects as diverse as the environments in which they are built, from high security military bases and major rail transport...