
Governance, Risk
4 weeks ago
**The Company**
Imagine a workplace where compassion is at the core of everything this company does, a place that celebrates collaboration, values your contributions, and offers continuous learning opportunities for your growth.
work-life balance for this client is more than a buzzword; it's a priority, and diversity and inclusion are deeply embedded in their culture.
Every day, you'll witness the tangible impact of your efforts, knowing you're part of a calling that's bigger than yourself, surrounded by colleagues who become friends and mentors. If you're seeking a workplace where your heart and skills align with a purpose-driven mission, welcome to an extraordinary place to build your career.
**Your New Role**:
Reporting to the Cyber Security Manager, the Cyber Security GRC Analyst will contribute to and provide support for the management and operations of the cyber security functions. A key element of this role will involve developing and maintaining information security policies and workforce training and awareness for our client.
As the GRC Analyst you will serve as a critical resource for staff and leaders regarding information security policy implementation, interpretation, and compliance.
**Your Responsibilities**:
The Cyber Security GRC Analyst is responsible for reducing information security and cybersecurity risk for our client by helping prioritise and drive remediation efforts throughout the organisation through the following:
- Establishing and maintaining governance and compliance standards.
- Conducting audits and risk assessments to identify vulnerabilities internally and within vendor or third-party supplier products.
- Creating, maintaining, communicating, and enforcing information security policies.
- Advising senior leadership on risk management strategies, including risk mitigation, risk reduction, risk transfer, the risk exception process, and residual risk analysis.
- Participating in the management and operations of the cyber security function.
- Developing and maintaining a risk-aware culture.
Under the guidance and support of the Cyber Security Manager, the GRC Analyst should work independently to execute and manage the cybersecurity and risk function in consistency with local and global regulations and established frameworks. The GRC Analyst holds team and organization-level responsibilities and may be assigned to lead small to medium-scale projects. The analyst works with staff members belonging to primary business functions, technology services teams, and external vendors providing solutions and services to our client, as well as any partners and affiliates.
**Responsibility Domains**:
- Maintain an information security management system based on NIST CSF, ISO/IEC 27001, NIST SP 800-53, and underpinning established and planned controls.
- Conduct cyber security maturity assessments, technical risk assessments, and supplier risk assessments.
- Manage cyber security performance metrics and reporting, author quality documentation, reports, and dashboards.
- Oversee cybersecurity and technology design principles and security architecture blueprints.
- Conduct security assurance and technical reviews of business and technology solutions.
- Define security requirements and test cases for business and technology solutions.
- Manage change management processes, including review and approval for infrastructure and business solutions.
- Provide support for internal audits and external reviews.
- Oversee identity and access management, including solution design and related controls (IGA, PAM, CIAM).
- Develop and implement user provisioning and de-provisioning policies and procedures.
- Lead workforce security awareness activities, including culture, awareness, and training.
- Design and deliver security awareness sessions and training, custom content, and reporting.
- Oversee vulnerability and patch management using tools such as Microsoft Defender Suite and Qualys.
- Manage security operations, including incident detection and response management.
- Ensure data privacy and data security through data loss prevention measures.
**You Will Need**:
Applied knowledge of SABSA security architecture, focusing on business-driven cybersecurity risk management.
Proficiency in cybersecurity standards and frameworks including ISO/IEC 27001:2013, NIST SP 800-53R5, NIST CSF, ISO/IEC 27004, Australian Information Security Manual, and Essential 8, with applied knowledge in implementation, security audits, and assessments.
Experience in developing and implementing cybersecurity policies, with participation as a lead or contributor in at least two life cycle implementations.
- 5-7 years of demonstrated experience in cybersecurity, especially in cloud-dominated computing environments.
- Experience in technology-based security risk assessments.
- Strong familiarity with Microsoft Security Suite (MSCA), Defender Suite, M365 Security Centre, Purview, and Sentinel.
- Expertise in vulnerability man
-
Risk Lead
1 week ago
Sydney, New South Wales, Australia Compliance & Risk Management Recruitment Full timeImmediate opportunity for an experienced Risk and Insurance Lead to join a large Council.Great role to develop your career.Excellent career opportunity Lead from the front We are working with one of Sydney's largest Councils who is looking for a risk professional to join the team as a Risk and Insurance Lead.This opportunity will have you develop the risk...
-
Governance and Risk Lead
1 week ago
Sydney, Australia City of Canada Bay Council Full time**Permanent Full Time - 35 hours per week**: - **$93,392 - $107,401 per annum plus super**: - **9-day fortnight** The City of Canada Bay is a thriving, colourful community, surrounded by the beautiful bays of Sydney Harbour. The area is also known for its parklands, cycle paths and walkways. City of Canada Bay Council’s values underpin how we operate:...
-
Principal Governance
3 weeks ago
Sydney, Australia NSW Government -Independent Commission Against Corruption Full time**_NSW Independent Commission Against Corruption_** **_ Principal Governance & Risk (ICAC 23/016)_** **Let’s talk about the opportunity** The **_Principal Governance & Risk_** leads the development and ongoing operation of governance, compliance and risk frameworks, policies and strategies at the Commission. This position provides a challenging and...
-
Risk Governance Specialist
3 days ago
Sydney, New South Wales, Australia ANZ Full timeRisk Management FrameworkThe Risk Governance Specialist will be responsible for ensuring that the Markets business has processes in place to identify and manage compliance and regulatory risk. This includes monitoring risk profiles, operational risk and compliance events/reportable events, audit findings, customer complaints, control testing and QA results...
-
Risk, Governance and Compliance Officer
4 weeks ago
Sydney, Australia Universities Admissions Centre (UAC) Full timePosted: 23/08/2024 Closing Date: 20/09/2024 **Job Type**: Full Time - FTA Location: Sydney, NSW Job Category: Finance & Accounts Are you passionate about governance, compliance, and risk management? Join our dynamic Finance & Corporate Governance Department at UAC, Australia’s leader in servicing prospective students and the higher education sector....
-
Governance Officer
3 weeks ago
Sydney, Australia Ashdown Consulting Full time$77 p/h + super - 6 month contract - Sydney CBD location **Governance Officer - Risk and Resilience | 4 month contract** *** **| $85.08 p/h** **Incl. super** - $77 p/h + super - 6 month contract - Sydney CBD location **About the Company** This NSW government agency is a major service provider who strives to deliver a more consistent and innovative...
-
Senior Risk Management Professional
4 days ago
Sydney, New South Wales, Australia Compliance & Risk Management Recruitment Full timeThe Compliance and Risk Management Recruitment team is seeking an experienced Risk Lead to join a large Council in Sydney's Inner West.About the RoleThis is an immediate opportunity for a skilled professional to develop their career and take ownership of risk management strategies. The successful candidate will have the drive to execute their strategy and...
-
IT Governance Risk Management Professional
6 days ago
Sydney, New South Wales, Australia Australian Prudential Regulation Authority Full timeAbout the RoleThe Australian Prudential Regulation Authority (APRA) is seeking a highly skilled Senior IT Governance Risk Analyst to join its team.This key role plays a critical part in ensuring the effective implementation, monitoring, and continuous improvement of IT governance processes, risk management, and controls across the organisation.Key...
-
Head of Risk Reporting
3 weeks ago
Sydney, Australia Insignia Financial Full timeHead of Risk Reporting & Governance - Champion the continuous improvement of Risk Management reporting and governance - Bring your detailed knowledge of risk and compliance frameworks to this key role! - Full-time, permanent opportunity (Hybrid working - mix of work from home & the office) **The Role** As Head of Risk Reporting Governance, you will be...
-
Governance and Risk Manager
3 days ago
Sydney, New South Wales, Australia Transgrid Full timeAbout the RoleWe are seeking an experienced Transaction Governance Manager to join our team. As a key member of our commercial transactions team, you will play a critical role in structuring, negotiating, and securing internal approvals for complex commercial transactions.This is a unique opportunity for a commercially astute and dynamic professional to...
-
Specialist, Risk
4 weeks ago
Sydney, Australia IAG New Zealand Full timeCreate an impact as a Specialist, Risk & Governance joining the largest insurance group in Australia and New Zealand. **YOUR ROLE** Our **Line 1 Risk & Governance team** has an opportunity for an experienced operational risk management Specialist, where you will be an integral member of a small team that makes a significant impact. Our team supports all...
-
Manager, Operational Risk and Governance
3 weeks ago
Sydney, Australia QBE Insurance Full timeQBE Insurance Sydney, AustraliaPosted 13 minutes ago Hybrid Permanent Competitive **Primary Details** Time Type: Full time - Worker Type: Employee - **Location: Sydney**: - **Type: Permanent, full time** **The opportunity** An exciting opportunity for a Manager, Operational Risk & Governance, Investments & Treasury to join QBE's global Investments &...
-
Risk Governance Specialist
3 days ago
Sydney, New South Wales, Australia HSBC Full timeAt HSBC, we are committed to creating a better world for our customers, people, investors, communities, and the planet we share.We bring together unique expertise, capabilities, breadth, and perspectives to provide opportunities through global connectivity. As an HSBC employee in Australia, you'll have access to tailored professional development...
-
Cloud & Risk Governance Manager
3 weeks ago
Sydney, Australia ING Full timeWhen you come to work at ING, you’re joining a modern and progressive team where individuality isn’t just accepted, it’s encouraged. You’ll be surrounded by people who are friendly, inclusive and respectful, who want you to reach your potential. It’s one of the many reasons we’re proud to be an Employer of Choice for Gender Equality. As our...
-
Cloud & Risk Governance Manager
3 weeks ago
Sydney, Australia ING Full timeWhen you come to work at ING, you’re joining a modern and progressive team where individuality isn’t just accepted, it’s encouraged. You’ll be surrounded by people who are friendly, inclusive and respectful, who want you to reach your potential. It’s one of the many reasons we’re proud to be an Employer of Choice for Gender Equality. As our...
-
Governance, Policy and Risk Specialist
4 weeks ago
Sydney, Australia Lifestyle Solutions Full time**About the job** The Governance Risk & Policy Specialist will provide specialist strategic and operational governance, policy, compliance and enterprise risk management advice and services, to support the achievement of business strategies and corporate governance requirements, with a particular focus on supporting the Board of Directors and the Executive...
-
Head of Data Risk Governance
3 weeks ago
Sydney, Australia NAB - National Australia Bank Full time**Work type**: Permanent Full time **Region**: NSW- Sydney CBD, NSW- Sydney inner, VIC- Melbourne CBD, VIC- Melbourne inner - **Convert a Risk and Governance role into a Business Value add proposition to significantly benefit our customers.**: - **This diverse and highly visible senior leadership role reaches across the entire NAB Group working closely with...
-
Manager - Product Risk Governance
4 weeks ago
Sydney, Australia HSBC Full timeSome career choices have more impact than others. We’re looking for progressive minds who are driven and forward-thinking, who are open to different ideas and cultures, who can connect with customers and colleagues and who’ll work with courageous integrity every day. As an HSBC employee in Australia, you’ll have access to tailored professional...
-
Digital Risk Governance Expert
33 minutes ago
Sydney, New South Wales, Australia ALOIS Solutions Full timeCompany OverviewAt ALOIS Solutions, we are committed to enhancing and upholding our security and risk environment. We seek a highly skilled Digital Risk Governance Expert to join our team.About the Role:Providing support through advice, guidance, and assurance activities.Supporting Infrastructure Tribe in identifying and managing non-financial risk...
-
Risk Governance Expert
3 days ago
Sydney, New South Wales, Australia Australia and New Zealand Banking Group Limited Full timeAbout the RoleThe Risk Governance Expert will be responsible for evaluating and managing compliance risk across the organization. You'll work closely with the operational risk team on the integration of the I.A.M framework and assist with regulatory submissions, responses and presentations.This role involves developing and maintaining collaborative...