Security Analyst Sydney

2 weeks ago


City of Melbourne, Australia Culture Amp Full time

Join us on our mission to make a better world of work. Culture Amp is the world’s leading employee experience platform, revolutionizing how 25 million employees across more than 6,500 companies create a better world of work. Culture Amp empowers companies of all sizes and industries to transform employee engagement, drive performance management, and develop high‑performing teams. Powered by people science and the most comprehensive employee dataset in the world, the most innovative companies including Canva, On, Asana, Dolby, McDonalds and Nasdaq depend on Culture Amp every day. Culture Amp is backed by leading venture capital funds and has offices in the US, UK, Germany and Australia. Culture Amp has been recognized as one of the world’s top private cloud companies by Forbes and as most innovative by Fast Company. How can you help make a better world of work? As a Security Analyst focused on Governance, Risk, and Compliance (GRC), your core mission will be to maintain trust and security throughout our ecosystem. This role is primarily responsible for managing our 3rd Party Vendor Security review process and assisting with timely, high‑quality responses to customer security questionnaires. You will work closely with Sales, Legal, and Procurement teams, ensuring our security documentation is accurate and our third‑party ecosystem is secure. You will also help to foster a strong security culture internally. Skills & Experience: Risk Management (Third‑Party Focus) - Vendor Security Reviews: Complete security third‑party vendor risk reviews for new and existing suppliers, gathering inputs, logging outcomes, and ensuring alignment with the Third‑Party Security Management Standard in partnership with Procurement and Legal. Customer Trust and Security Assurance - Answering Customer Security Questionnaires: Assist where required the timely completion of high‑quality responses to customer and prospect security requests, due diligence questionnaires (DDQs), and information requests. - Maintaining Trust Collateral (SafeBase): Proactively assist and help maintain all security and compliance documentation, artifacts, policies, and certifications within our Security Trust Centre (e.g., SafeBase) to enable a self‑service experience for customers. - Accelerating Deals: Partner with Sales and Legal to triage requests and ensure security communications are consistent and accelerate the sales cycle. - Gathering Reporting Metrics: Collect and track key performance indicators (KPIs) related to customer security review SLAs, document engagement, and overall security assurance efforts for leadership visibility. Security Culture and Awareness - Security Awareness Campaigns: Assist with the design, coordination, and delivery of our hybrid cybersecurity awareness program. - Internal Communication: Draft and schedule compelling security insights for internal newsletters, Slack, and email, translating complex policy and control requirements into clear, action‑oriented guidance for all employees ("Campers"). - Security Champions Initiative: Support the operationalisation of the security champions program across business units to extend program reach and reinforce secure‑by‑default behaviours across the organization. Security Compliance - Program Assistance: Assist the GRC team with the ongoing management and maintenance of our key security compliance programs (e.g., ISO 27001, SOC 2), which includes coordinating evidence collection, documentation updates, and control attestations. You have: - Experience: 1‑3 years of operational experience in a role focused on Security Assurance, Third‑Party Risk (TPR) Management, or GRC. Transferable skills from adjacent domains are highly valued. - Security Compliance Operations: Practical experience assisting with the management of security compliance programs (e.g., SOC 2, ISO 27001, or similar), including coordinating evidence collection from control owners and documenting attestations. - Customer Trust Platform Expertise: Proven ability to manage and update content within a Security Trust Center platform (like SafeBase or similar), including document organization, access controls, and questionnaire response management. - Third‑Party Risk Process: Practical understanding of the vendor security review lifecycle, including the ability to triage, assess, and document risk findings for internal and external suppliers. - Organisational Excellence & SLA Adherence: Excellent organization and prioritization skills with a proven track record of strong follow‑through and working effectively toward defined service level agreements (SLAs) in a fast‑paced environment. - Enablement & Communication Skills: Clear and concise written communication, with the skill to translate complex security concepts (e.g., policy, controls) into practical, action‑oriented guidance suitable for technical and non‑technical internal teams. - GRC Foundations: Familiarity with common security frameworks (e.g., SOC 2, ISO 27001, or similar) is a plus, and a high degree of curiosity, a learning mindset, and a positive, security‑first attitude are essential. Desired (Highly Regarded) Qualifications: - Industry‑recognised qualifications (e.g., Security+, CISA, CRISC, CSA or similar). We believe that our employees are the heartbeat of our success. We're committed to fostering a work environment that truly cares for and develops its people, and creates lasting positive impact. In addition to providing a competitive compensation package, some of the key benefits we offer are: - Employee Share Options Program: We empower you to be an owner in Culture Amp and share in our success. - Programs, coaching, and budgets to help you thrive personally and professionally. - Access to external providers for mental wellbeing and coaching support. - Monthly Camper Life Allowance: An automatic allowance paid out each month with your pay – you can spend it however you like to help improve your experience and life outside work. - Team budgets dedicated to team building activities and connection. - Intentional quarterly wellbeing pauses: A quarterly company‑wide shutdown day in each region to collectively pause, reset and focus on restoration and rest, without having to tap into individual vacation time. - Extended year‑end breaks: An extended refresh period at the end of year. - Excellent parental leave and in‑work support program available from day 1 of joining Culture Amp. - 5 Social Impact Days a year to make a positive impact on the community outside of work. - MacBooks for you to do your best & a work‑from‑home office budget to spend on setting up your home office. - Medical insurance coverage for you and your family (Available for US & UK only). Additionally, we don't just focus on our internal community; we believe in creating a better world of work for all. We're committed to diversity, equity, and inclusion, with Employee Resource Groups and ally communities in place. We have a strong commitment to Anti‑Racism and endeavour to lead by example. Every step we make as a business towards anti‑racism is another step we can take to support our customers in making a better world (of work). You can see our current commitments to Anti‑Racism here. Culture Amp is committed to providing equal employment opportunities to all employees and applicants for employment regardless of race, colour, religion, creed, age, national origin or ancestry, ethnicity, sex, sexual orientation, gender identity or expression, disability, military or veteran status, or any other category protected by federal, state, or local law. #J-18808-Ljbffr



  • Council of the City of Sydney, Australia Quay Appointments Full time

    A leading recruitment firm is seeking a Senior Security Operations Analyst for a 6-month contract in Sydney CBD or Parramatta. This role involves investigating cybersecurity incidents, supporting security analysis, and enhancing security monitoring capabilities. Applicants should have over 6 years of cybersecurity experience and knowledge of compliance...


  • Council of the City of Sydney, Australia NSW Government Full time

    Job Description - Security Operations Analyst (0000B23S) Security Operations Analyst - 0000B23S - Ongoing Full time Opportunity - Be part of a team driving innovation in secure system design - Protect critical systems and infrastructure from cyberattacks, solving real-world problems About the Role The Security Operations Analyst is responsible for...


  • Council of the City of Sydney, Australia NSW Government Full time

    Job Description - Data Security Analyst (0000B4PL) Overview Join us to make a difference for all students in NSW! Data Security Analyst - 0000B4PL About the role Are you ready to protect our information and drive security forward? At NESA, join our newly established Cybersecurity, Information Assurance, and Data Protection team and play a key role in...


  • Council of the City of Sydney, Australia NSW Government Full time

    Job Description - Cyber Security Analyst (0000B23Y) Cyber Security Analyst - 0000B23Y - Ongoing Full Time Opportunity - Work with leading cyber security tools, including IAM, PAM, and SIEM platforms - Work with a passionate, innovative team to protect critical systems from evolving cyber threats About the Role The Cyber Security Analyst is responsible...

  • IT Security Analyst

    1 week ago


    Melbourne, Australia Dynatrace Full time

    Great opportunity for an IT Security Analyst to be a part of our Employee Digital Entablement team based in Sydney or Melbourne. This role will be responsible for Threat response, Vulnerability management, executing strategies and ensuring organizational and client IT security expectations are being satisfied. There will be an expectation of collaborating...


  • City of Melbourne, Australia Chubb Fire & Security Ltd. Full time

    # At Chubb we are driven by a powerful purpose - to protect your worldDevice Support Analyst page is loaded## Device Support Analystlocations: 314 Boundary Road Dingley, Melbourne VIC 3172, Australia Chubbtime type: Full timeposted on: Posted Todayjob requisition id: JR40003731**Device Support Analyst****About the Role**We are seeking a proactive and...

  • Security Analyst

    1 week ago


    Melbourne, Australia Culture Amp Full time

    **Join us on our mission to make a better world of work.** Culture Amp revolutionizes how over 25 million employees across 6,000 companies create a better world of work. As the global platform leader for employee experience, Culture Amp empowers companies of all sizes and industries to transform employee engagement, develop high performing teams, and retain...

  • Security Analyst

    2 weeks ago


    Melbourne, Australia Varonis Full time

    Incident Response Security Analyst Description The Varonis Security Analyst will maximize the customer’s value from Varonis through direct customer engagement. The analyst will provide customer-facing services, including incident response, investigations, alert reviews, and security posture reviews. They will have intimate knowledge of Varonis’...

  • IT Security Analyst

    1 week ago


    Melbourne City Centre, Australia HAYS Full time

    Excellent opportunity to join #Top public sector client for a short contract **Your new company** Victorian government department is looking for a Security IT Analyst to be part of their Security team for a short-term contract (3weeks) **Your new role** You will be responsible for a broad range of tasks and duties including: - Knowledge in identifying...


  • City of Melbourne, Australia Varonis Full time

    Senior Security Analyst (MDDR) - Japanese Speaker Senior Security Analyst - Japanese Speaker The Company: Varonis (Nasdaq: VRNS) is a leader in data security, fighting a different battle than conventional cybersecurity companies. Our cloud-native Data Security Platform continuously discovers and classifies critical data, removes exposures, and detects...