IT Security Grc Manager

7 hours ago


Sydney, Australia MinterEllison Full time

**Location**: Sydney, Brisbane, Melbourne

**Contract Type**: Permanent

MinterEllison is one of Australia’s largest law firms, with nearly 200 years of business history. We're known for our legal and consulting expertise - and for our inclusive and authentic character.

Our purpose is to create sustainable value with our clients, people and communities. That means we have a proud history of providing excellence to clients, nurturing our people and giving back to the communities in which we live and work.

We value excellence, curiosity and collaboration. Clients rely on us for our responsive, commercial approach. Our clients include government departments and agencies, private and publicly listed companies, and small and large businesses in Australia and overseas.

**The Role**

We are currently recruiting for an experienced IT Security GRC Manager to join our internal digital team based in either our Sydney, Melbourne or Brisbane office. In this role, you will be responsible for managing and maintaining the end to end IT security GRC portfolio under our IT security assurance practice. The IT security assurance practice covers: cyber risk management, compliance framework and certification program, client assurance and contract reviews, supply chain security, internal audit, and cyber awareness program.

Agile working arrangements are supported at the firm with a minimum or 3 days in the office required.

In this role you will have the opportunity to:

- Uplift and develop a high-performing IT security GRC practice across all IT security assurance areas, fostering a culture of excellence, collaboration, and continuous learning
- Implement a robust IT security compliance framework program integrating multiple compliance certification, frameworks, policies and standards
- Lead and maintain certifications across multiple standards/frameworks and internal audits
- Perform cyber hygiene audits to ensure compliance with external and internal policies, regulations, standards and compliance with client contracts
- Lead client assurance program including responding to client audits/questionnaires, reviewing client cybersecurity contracts, updating MinterEllison Trust Centre and maintaining a high client engagement & experience
- Collaborate with Chief Risk Office to manage and maintain cyber risk lifecycle including cyber risk registers and dashboards
- Lead supply chain cyber risk management program including annual reviews and spot checks
- Maintain cyber security awareness and training programs including role-based training across the Firm
- Provide high quality reporting and updates on cyber security to senior leadership including KPIs/KRIs
- Assist with IT security operations on any cybersecurity incidents during and, if required, after business hours
- Ensure efficient use of managed security services and/or external consultants in the GRC domain.
- People leadership responsibility for one direct report.

**More About You**
- 8 years+ demonstrated, direct, hands on experience in the above mentioned GRC areas, including 2-3 years hands on, direct experience in managing assurance programs
- Strong written and verbal communication skills to engage with all levels of business
- Pragmatic and collaborative with various stakeholders with the ability to bring people on a journey
- Demonstrated experience in writing high quality executive reports/briefings
- Expert knowledge of information security principles, standards and frameworks such as ISO27001. Familiarity with of NIST, SSAE16, APRA CPS234, ASD essential 8, VPDSF
- Knowledge of security policies, standards, and practices.
- Knowledge of the infrastructure, operations, and systems of information technology.
- Agile-mindset, incremental delivery over perfection, willingness to try new approaches to a problem
- Ability to manage projects and tasks independently with little supervision
- Relevant security trainings/certifications not mandatory but will be highly desirable
- Ability to use GenAI models and other pragmatic approaches to improve efficiencies/quality or delivery
- Be up-to-date with information security best practices and industry trends for security solutions and standards

**Why MinterEllison**

We offer flexible working options to encourage balance, wellbeing and support for sustainable ways of working and a range of social, financial and health benefits, including free gym membership - all with no minimum tenure.

**How to apply



  • Sydney, Australia Credible Full time

    **This new opportunity is for a GRC Security Consultant with MyCISO**: MyCISO is a Sydney HQ’d SaaS security start-up, transforming cyber security program management for all. MyCISO is the platform that enables security leaders leverage to assess, improve and manage both their organisation and their supply chain’s security maturity, aligned to a variety...


  • Council of the City of Sydney, Australia ClearCompany Full time

    Hudson are proud to partner with a unique organisation that serves the community in numerous ways to find a cyber security GRC specialist to drive the maturity of their cyber security GRC practices. You will work in a welcoming, tight knit team that supports each other day in day out. A great opportunity for someone who wants to work independently and take...


  • Sydney, New South Wales, Australia Torch Professional Services Pty Ltd Full time $120,000 - $180,000 per year

    Join a high-impact ERP transformation program within a major government agency, modernising legacy SAP ECC6 systems and migrating to S/4HANA in a protected cloud environment. This strategic initiative will enhance security, streamline access governance, and align with evolving compliance standards. About the Role As GRC Security Consultant (SAP Roles &...

  • sap grc

    2 weeks ago


    Sydney, New South Wales, Australia INNOVATE IT AUSTRALIA Full time $80,000 - $120,000 per year

    Key Responsibilities:Configure and support SAP GRC (Access Control, Risk & Compliance) and SAP IDM.Manage user provisioning, role design, and SoD (Segregation of Duties) analysis.Integrate GRC and IDM with SAP and non-SAP systems.Support audit, compliance, and access governance activities.Troubleshoot and maintain related workflows and documentation.Skills...


  • Sydney, Victoria, , Australia XPT Software Australia Pty Full time $100,000 - $150,000 per year

    At least 1 full life cycle implementation of GRC Access Control 12.0 (ARA,BRM,EAM) or technical migration from ECC 6.0 to S4H 2023 (RISE with SAP)Should be able to implement GRC tool independentlyKnowledge on SAP S4 HANA/ Fiori based security role and authorizationShould have implementation knowledge of BW,PO,CRM securityMust have knowledge to handle changes...

  • Security Lead

    1 week ago


    Sydney, Australia Technology People Australia Full time

    Our clients seek an experienced Security Manager/Lead to maintain and enhance the existing Security Posture across the Business. You will be required to ensure the security of all Information Systems and Data. You will manage all PCI-DSS Obligations to make sure all compliance is in line with required regulations. You will develop and maintain all...


  • Sydney, Australia Peoplebank Full time

    Location: - Sydney- Job Type: - Permanent- Posted: - about 6 hours ago- Contact: - Masood Khan- Discipline: - Security / Cyber Security - Reference: - 254710Are you an experienced Information Security Specialist with a passion for GRC? Do you have skills across internet presence, compliance, and third-party vendor management? If so, we have an exciting...


  • Sydney, Australia NSW Police Force Full time

    **Computer System Officer Level 5**: - **Ongoing Full-Time**: - **Sydney Olympic Park** **About us** The NSW Police Force (NSWPF) is one of the largest police forces in the western world, with more than 20,000 employees, including more than 4,000 administrative employees who support the sworn officers that provide a range of law and order services 24...

  • Cybersecurity GRC

    1 week ago


    Sydney, New South Wales, Australia Master2Manage® Pty Limited, Australia Full time $80,000 - $120,000 per year

    Multiple roles in Cybersecurity GRCWe are partnering with one of the government client, and require multiple roles as below:1. Cyber GRC AnalystSecure Australia's Digital FutureJoin a high-profile government program and make an impact on national cyber resilience.About the RoleWe are seeking aCyber GRC Analystto support a major Australian Government...


  • Sydney, New South Wales, Australia Hastha Solutions Full time $80,000 - $120,000 per year

    Urgent requirement of SAP GRC and IDM Consultant - Contract - Sydney RequirementsMust have strong knowledge of SAP GRC Access Control 10.1 or 12.0 and Process Control Expertise in SAP IDM 8.0, including its architecture, design, and implementation Hands-on experience with SAP BTP Identity and Access Management components: IAG, IAS, and IPS ...