Grc Analyst

2 weeks ago


Sydney, Australia Latitude Full time

GRC Analyst opportunity focused towards SOX compliance frameworks
- Work with a leading company who are expanding their presence Nationally
- Flexible hybrid working conditions on offer

We have a rewarding new permanent opportunity available for a **Governance, Risk, and Compliance Analyst (GRC & SOX Analyst), **to join a supportive and growing technology team based in Sydney, New South Wales.

This is a mid-senior level position, and the GRC Analyst will have hybrid working conditions on offer, ideally with work onsite for 3 days a week, collaborating with an internal team of passionate technology enthusiasts, and this new hire will be reporting directly the Technology Operations Manager.

**In this role, you’ll be responsible for day-to-day responsibilities, including**:

- Overseeing and managing the risks associated with third-party vendors and suppliers.
- Updating and maintaining policy documentation across all Business Units.
- Participate in and support the implementation of **SOX compliance and frameworks.**:

- Support the Corporate IT Operations function to manage risk and compliance processes, establish and enhance compliance frameworks and support policy frameworks to adhere to regulatory requirements.
- Leading the third-party vendor management program to identify and manage risks posed by third parties that the company works with.
- Maintaining and updating risk registers.
- Developing Enterprise risk dashboards and working on threat and risk assessments.
- Reporting key risks to Executive management.
- Promoting risk ownership across the organisation and business units.
- Collaborating with cross-functional teams to facilitate enterprise risk management, identify and analyse risks, develop risk mitigation strategies.
- Work with the internal GRC tools & platforms to continuously improve processes and implement and manage governance frameworks.
- Conducting information security audits, assessments, and reviews to ensure compliance with internal policies, standards, and external industry regulations.
- Developing and managing the cyber security awareness training program and identifying areas for improvement.
- Ensuring 100% compliance with safety regulations and promptly reporting potential breaches for corrective action.

**Skills & experience required to enhance your success in this role, includes**:

- Hands-on experience in the field of Governance, Risk and Compliance, across Information and Cyber Security disciplines.
- Commercial experience working in Governance, Risk, and Compliance, with a primary focus on governance & compliance.
- Possess experience and exposure to **SOX compliance and frameworks.**:

- Possesses a genuine interest and passion for Cyber and Information Security.
- Self-motivated and capable of taking ownership of this function, as this will be a lean technology team that you’ll be joining which requires a good sense of ownership and autonomy.
- Ability to provide guidance and add value to the other the company’s business units by presenting scenarios and influencing team members.
- Familiarity with key risk frameworks such as NIST, ACSC, ISO27001, PCI, ASD Essential Eight, SOCI etc.
- Understanding of the role of key audit reports, such as PCI and ISO27001.
- Previous experience working as a GRC Analyst or GRC Business Analyst with a compliance focus.
- Sound knowledge of information security tools and technologies, such as firewalls, antivirus, encryption, SIEM, vulnerability scanners, etc.

Please kindly note, that to be considered for this role, you must be located in Australia and possess full work rights.


  • Risk Systems Analyst

    4 weeks ago


    Sydney, Australia ING Full time

    ING, Australia’s most recommended bank is on the hunt for an experienced **Manager, Risk Improvement **for our **Risk Excellence Program** of work in our **RX Systems/Non-Financial Risk team**. This key appointment is an instrumental and specialist role responsible for the development, business support, data quality and change management of ING...

  • Governance, Risk

    7 days ago


    Sydney, Australia Leidos Full time

    Company Description **Job Description**: Leidos Australia have a great opportunity that enables you to build on your Cyber Security experience and utilise your passion in a Governance, Risk and Compliance role. In this permanent full time opportunity supporting a major Federal Government Program, you will be pivotal in ensuring the ongoing ICT security...


  • Sydney, Australia The Decipher Bureau Full time

    This ASX listed organisation have seen considerable growth and investment in their cyber and risk team over the years, with lots of new initiatives in the GRC space that need to be delivered specifically defining group wide cyber principles.You will be across a number of accountabilities including leading security risk assessments and analysis, defining...

  • Technical BA

    15 hours ago


    Sydney, Australia Talenza Full time

    Talenza have been engaged to source a Technical Business Analyst for an ongoing risk program Who You Are You are a strong Data Migration Business Analyst with: 8+ years as a Tech/Data BA Financial Services experience (must) Data Migration experience (must), and ideally on a GRC program Strong vendor engagement experience Risk systems...


  • Sydney, Australia Diligent Corporation Full time

    **About Us** Diligent is the global leader in modern governance, providing SaaS solutions across governance, risk, compliance, audit and ESG. Empowering more than 1 million users and 700,000 board members and leaders with a holistic view of their organization's GRC practices so they can make better decisions, faster. No matter the challenge. At Diligent,...


  • Sydney, Australia Westpac Full time

    Westpac Group has a rich heritage and offers employees a multitude of opportunities. We aim to attract the best people inside and outside of the business - building an organisation where the best talent thrives. The Westpac Group has a complex Information Technology environment that needs to deliver to the rapidly changing needs of our customers and...