Governance, Risk

2 weeks ago


Sydney, Australia Experis Full time

**The Company**

Imagine a workplace where compassion is at the core of everything this company does, a place that celebrates collaboration, values your contributions, and offers continuous learning opportunities for your growth.

work-life balance for this client is more than a buzzword; it's a priority, and diversity and inclusion are deeply embedded in their culture.

Every day, you'll witness the tangible impact of your efforts, knowing you're part of a calling that's bigger than yourself, surrounded by colleagues who become friends and mentors. If you're seeking a workplace where your heart and skills align with a purpose-driven mission, welcome to an extraordinary place to build your career.

**Your New Role**:
Reporting to the Cyber Security Manager, the Cyber Security GRC Analyst will contribute to and provide support for the management and operations of the cyber security functions. A key element of this role will involve developing and maintaining information security policies and workforce training and awareness for our client.

As the GRC Analyst you will serve as a critical resource for staff and leaders regarding information security policy implementation, interpretation, and compliance.

**Your Responsibilities**:
The Cyber Security GRC Analyst is responsible for reducing information security and cybersecurity risk for our client by helping prioritise and drive remediation efforts throughout the organisation through the following:

- Establishing and maintaining governance and compliance standards.
- Conducting audits and risk assessments to identify vulnerabilities internally and within vendor or third-party supplier products.
- Creating, maintaining, communicating, and enforcing information security policies.
- Advising senior leadership on risk management strategies, including risk mitigation, risk reduction, risk transfer, the risk exception process, and residual risk analysis.
- Participating in the management and operations of the cyber security function.
- Developing and maintaining a risk-aware culture.

Under the guidance and support of the Cyber Security Manager, the GRC Analyst should work independently to execute and manage the cybersecurity and risk function in consistency with local and global regulations and established frameworks. The GRC Analyst holds team and organization-level responsibilities and may be assigned to lead small to medium-scale projects. The analyst works with staff members belonging to primary business functions, technology services teams, and external vendors providing solutions and services to our client, as well as any partners and affiliates.

**Responsibility Domains**:

- Maintain an information security management system based on NIST CSF, ISO/IEC 27001, NIST SP 800-53, and underpinning established and planned controls.
- Conduct cyber security maturity assessments, technical risk assessments, and supplier risk assessments.
- Manage cyber security performance metrics and reporting, author quality documentation, reports, and dashboards.
- Oversee cybersecurity and technology design principles and security architecture blueprints.
- Conduct security assurance and technical reviews of business and technology solutions.
- Define security requirements and test cases for business and technology solutions.
- Manage change management processes, including review and approval for infrastructure and business solutions.
- Provide support for internal audits and external reviews.
- Oversee identity and access management, including solution design and related controls (IGA, PAM, CIAM).
- Develop and implement user provisioning and de-provisioning policies and procedures.
- Lead workforce security awareness activities, including culture, awareness, and training.
- Design and deliver security awareness sessions and training, custom content, and reporting.
- Oversee vulnerability and patch management using tools such as Microsoft Defender Suite and Qualys.
- Manage security operations, including incident detection and response management.
- Ensure data privacy and data security through data loss prevention measures.

**You Will Need**:
Applied knowledge of SABSA security architecture, focusing on business-driven cybersecurity risk management.

Proficiency in cybersecurity standards and frameworks including ISO/IEC 27001:2013, NIST SP 800-53R5, NIST CSF, ISO/IEC 27004, Australian Information Security Manual, and Essential 8, with applied knowledge in implementation, security audits, and assessments.

Experience in developing and implementing cybersecurity policies, with participation as a lead or contributor in at least two life cycle implementations.
- 5-7 years of demonstrated experience in cybersecurity, especially in cloud-dominated computing environments.
- Experience in technology-based security risk assessments.
- Strong familiarity with Microsoft Security Suite (MSCA), Defender Suite, M365 Security Centre, Purview, and Sentinel.
- Expertise in vulnerability man


  • Risk Manager

    4 weeks ago


    Sydney, Australia Compliance and Risk Management Recruitment Full time

    Banking & Finance - Other - Sydney - Permanent / Full Time **21st February, 2024**: **This is an exciting opportunity join a growing listed Financial Institution in Australia. This role plays a pivotal role in supporting the business deliver to its go to market plan, regulatory obligations, and strategic objectives**. **Key Responsibilities** - Delivering...

  • Associate Director

    1 month ago


    Sydney, Australia Compliance and Risk Management Recruitment Full time

    Education & Child Care - University - Other - Sydney - Permanent / Full Time **27th November, 2023**: This is a senior leadership role with the organisation and will be responsible for supporting the risk function. Reporting to the CRO as the 2IC, this role will be responsible for providing strategic and operational advice to the broader leadership and...

  • Corporate Governance

    1 month ago


    Sydney, Australia Compliance and Risk Management Recruitment Full time

    Manufacturing - Management / Supervisor - Sydney - Permanent / Full Time **11th January, 2023**: CRM Recruitment is currently partnering with an organisation who are seeking a Corporate Governance & Compliance Manager, to build and implement the Governance & Compliance Framework for this privately owned consortium. This role is both strategy & execution...


  • Sydney, Australia Sirius People Full time

    **Seeking a Senior Cyber Risk Manager!** **Join a Leading Team in the Banking Industry!** Are you a seasoned professional in the world of cyber risk and security? Do you have a track record of designing controls, setting standards, and providing expert governance advice in the realm of cyber security? If you're ready to make a significant impact and operate...


  • Sydney, Australia City of Canada Bay Full time

    **Permanent Full Time - 35 hours per week**: - **$93,392 - $107,401 per annum plus super**: - **9-day fortnight** The City of Canada Bay is a thriving, colourful community, surrounded by the beautiful bays of Sydney Harbour. The area is also known for its parklands, cycle paths and walkways. City of Canada Bay Council’s values underpin how we operate:...

  • Manager, Risk

    4 weeks ago


    Sydney, Australia NSW Government -Department of Customer Service Full time

    **Manager, Risk & Governance, Temporary, locations are flexible across NSW with hybrid working** An exciting opportunity has arisen for a Manager, Risk & Governance to join our Program Delivery team within Revenue NSW to manage and mitigate risks at a tactical and strategic level. Be part of an innovative program that transforms our approach to compliance,...

  • Manager Governance

    4 weeks ago


    Sydney, Australia NSW Government -Department of Customer Service Full time

    **Risk & Compliance Manager** - Full - time, ongoing role based in Sydney CBD (Haymarket) with flexible work options - Clerk Grade 11/12 base salary, $134,411 - $155,445 plus employer’s contribution to superannuation and annual leave loading **Let’s talk about the Opportunity!** This is an exciting opportunity for a risk and compliance professional to...


  • Sydney, Australia BOQ Full time

    About the Role Here at BOQ Group we have been busy working behind the scenes building out our Purpose, our Values, and our Strategic Pillars to help us achieve an exciting future-state through the transformation of digital banking.  We are strengthening, simplifying, optimising, and digitising, whilst ensuring our foundations are in place. With...


  • Sydney Central Business District, Australia HCF Full time

    Reporting to the Chief Information Officer, the Head of IT Risk, Audit and Governance will be responsible for overseeing and managing all aspects of technology-related risks and governance to ensure the effective and secure operation of HCFs information technology systems. The role will play a key role in identifying and mitigating IT-related risks,...


  • Sydney, Australia Davidson Group Services Full time

    **Impressive Company Performance** This organisation is one of the world’s leading professional services and consulting firms. With an exceptional reputation for client service, customer delivery and commercial advisory, this firm has an unparalleled track-record of success in all its core markets. **The Role - Delivering the Vision** This hybrid role...


  • Sydney, Australia QBE Full time

    Primary Details Time Type: Full time Worker Type: Employee- Location: Sydney- Type: Permanent, full time The opportunity- Senior tactical and strategic leadership role managing QBE’s first line risk community and customer remediation function- Join a major Australian and international insurer during an exciting phase of our development- Be a central...


  • Sydney, Australia QBE Insurance Full time

    **Primary Details** Time Type: Full time Worker Type: Employee - **Location: Sydney**: - **Type: Permanent, full time** **The opportunity** - Senior tactical and strategic leadership role managing QBE's first line risk community and customer remediation function - Join a major Australian and international insurer during an exciting phase of our...


  • Sydney, Australia Terra Firma Full time

    Terra Firma is a leading Australian owned IT Business & Project Services Consulting company, providing professional consulting services to enterprise clients in Energy, Telecommunications, Government, Not for Profit and Financial Services industries. Our core values are Pride and Passion, Collegiality and Adding Value. This is truly embedded into our...

  • 1st Line Risk

    7 days ago


    Sydney, Australia Insignia Financial Full time

    1st Line Risk & Governance Manager - Permanent full-time, location agnostic - Join a diverse and high performing team and add value across P&C. - A truly flexible work culture. **The Role** This role is responsible for the delivery of 1st line Risk (1LOA) support for People & Culture, with a specific focus on Payroll governance as well as Regulatory and...


  • Sydney, Australia Domain Group Full time

    **Cyber Governance, Risk and Compliance Lead - Sydney Office - Permanent Full Time** A great opportunity for a **Cyber Security Governance, Risk and Compliance** **(GRC) Lead**, in partnership with the Cyber Security GRC Manager, the Lead will be responsible for the delivery of the Cyber Security Governance, Risk and Compliance initiatives. You will work...


  • Sydney, Australia Talent International Full time

    **Job Details**: **Location** Sydney **Salary** Negotiable **Job Type** Full Time **Ref** BBBH100908_1681877672 **Contact** Donal McCann **Posted** about 4 hours ago - Based in Armidale - Working from Anywhere - Lead the Information Security Strategy **The role** This Higher Education client is seeking an experienced Manager - Security...


  • Sydney, Australia Domain Group Full time

    **Cyber Governance, Risk and Compliance Manager - Sydney Office - Permanent Full Time** We have a high impact; newly created opportunity for an experienced Cybersecurity Governance, Risk and Compliance (GRC) Manager, to join our Domain team. Reporting into the Chief Information Security Officer (CISO); you will be responsible for the implementation and...


  • Sydney, Australia The Decipher Bureau Full time

    This ASX listed organisation have seen considerable growth and investment in their cyber and risk team over the years, with lots of new initiatives in the GRC space that need to be delivered specifically defining group wide cyber principles.You will be across a number of accountabilities including leading security risk assessments and analysis, defining...

  • IT Governance Manager

    1 month ago


    Sydney, Australia Michael Page Full time

    About Our Client Our client is a company responsible for regulating financial institutions. Job Description Establish Cloud Governance Frameworks and required controls and strategies (especially within the Microsoft Azure environment) Provide governance, risk, and compliance insights to drive improvement across IT. Plan the implementation of...

  • IT Governance Manager

    4 weeks ago


    Sydney, Australia Michael Page Full time

    Being part of a challenging and rewarding environmentWorking closely with senior management across the organizationAbout Our ClientOur client is a company responsible for regulating financial institutions.Job DescriptionEstablish Cloud Governance Frameworks and required controls and strategies (especially within the Microsoft Azure environment) Provide...