
IT Security Grc Manager
4 days ago
**Location**: Sydney, Brisbane, Melbourne
**Contract Type**: Permanent
MinterEllison is one of Australia’s largest law firms, with nearly 200 years of business history. We're known for our legal and consulting expertise - and for our inclusive and authentic character.
Our purpose is to create sustainable value with our clients, people and communities. That means we have a proud history of providing excellence to clients, nurturing our people and giving back to the communities in which we live and work.
We value excellence, curiosity and collaboration. Clients rely on us for our responsive, commercial approach. Our clients include government departments and agencies, private and publicly listed companies, and small and large businesses in Australia and overseas.
**The Role**
We are currently recruiting for an experienced IT Security GRC Manager to join our internal digital team based in either our Sydney, Melbourne or Brisbane office. In this role, you will be responsible for managing and maintaining the end to end IT security GRC portfolio under our IT security assurance practice. The IT security assurance practice covers: cyber risk management, compliance framework and certification program, client assurance and contract reviews, supply chain security, internal audit, and cyber awareness program.
Agile working arrangements are supported at the firm with a minimum or 3 days in the office required.
In this role you will have the opportunity to:
- Uplift and develop a high-performing IT security GRC practice across all IT security assurance areas, fostering a culture of excellence, collaboration, and continuous learning
- Implement a robust IT security compliance framework program integrating multiple compliance certification, frameworks, policies and standards
- Lead and maintain certifications across multiple standards/frameworks and internal audits
- Perform cyber hygiene audits to ensure compliance with external and internal policies, regulations, standards and compliance with client contracts
- Lead client assurance program including responding to client audits/questionnaires, reviewing client cybersecurity contracts, updating MinterEllison Trust Centre and maintaining a high client engagement & experience
- Collaborate with Chief Risk Office to manage and maintain cyber risk lifecycle including cyber risk registers and dashboards
- Lead supply chain cyber risk management program including annual reviews and spot checks
- Maintain cyber security awareness and training programs including role-based training across the Firm
- Provide high quality reporting and updates on cyber security to senior leadership including KPIs/KRIs
- Assist with IT security operations on any cybersecurity incidents during and, if required, after business hours
- Ensure efficient use of managed security services and/or external consultants in the GRC domain.
- People leadership responsibility for one direct report.
**More About You**
- 8 years+ demonstrated, direct, hands on experience in the above mentioned GRC areas, including 2-3 years hands on, direct experience in managing assurance programs
- Strong written and verbal communication skills to engage with all levels of business
- Pragmatic and collaborative with various stakeholders with the ability to bring people on a journey
- Demonstrated experience in writing high quality executive reports/briefings
- Expert knowledge of information security principles, standards and frameworks such as ISO27001. Familiarity with of NIST, SSAE16, APRA CPS234, ASD essential 8, VPDSF
- Knowledge of security policies, standards, and practices.
- Knowledge of the infrastructure, operations, and systems of information technology.
- Agile-mindset, incremental delivery over perfection, willingness to try new approaches to a problem
- Ability to manage projects and tasks independently with little supervision
- Relevant security trainings/certifications not mandatory but will be highly desirable
- Ability to use GenAI models and other pragmatic approaches to improve efficiencies/quality or delivery
- Be up-to-date with information security best practices and industry trends for security solutions and standards
**Why MinterEllison**
We offer flexible working options to encourage balance, wellbeing and support for sustainable ways of working and a range of social, financial and health benefits, including free gym membership - all with no minimum tenure.
**How to apply
-
Security Manager
2 days ago
Sydney, Australia Bluefin Resources Full timeGreat company culture and team - Newly created role - Large, global company - in house role **With phenomenal growth both globally and in Australia, this well established company is looking to boost their IT security and risk team with a Security Manager, focusing on GRC and Third Party Security and Risk.** Leading the design, development and execution of...
-
SAP GRC Security Consultant
1 week ago
Sydney, New South Wales, Australia Torch Professional Services Pty Ltd Full time $120,000 - $180,000 per yearJoin a high-impact ERP transformation program within a major government agency, modernising legacy SAP ECC6 systems and migrating to S/4HANA in a protected cloud environment. This strategic initiative will enhance security, streamline access governance, and align with evolving compliance standards. About the Role As GRC Security Consultant (SAP Roles &...
-
Security Grc Analyst
1 week ago
Sydney, Australia Lumus Imaging Full time**Date**:23 Apr 2025 **Location**: Sydney, New South Wales, AU, 2000 **Company**:Healius **Job reference**: #15478 **Brand**:Lumus Imaging **Location**: Sydney **Work type**: Full Time (Permanent) **About us** At Lumus Imaging, we are passionate about caring for your health and wellbeing at every stage of life. Lumus Imaging harnesses all of the...
-
Information Security
16 hours ago
Sydney, Australia Decipher Bureau Full timeAre you a Senior GRC consultant looking to move into an internal role? - Global enterprise (1800 people worldwide in 14 countries) - Hybrid work culture & overseas opportunities Are you interested in moving from your consulting role into this internal opportunity within a global enterprise? You would be responsible for ensuring that the company is...
-
Cyber Security
17 hours ago
Sydney, Australia Firesoft People Full time**Cyber Security - Associate Director (GRC)** **Global Professional Services** **$180k - $200k + Super** **Brisbane Based** Our client a renowned organization consistently recognized as one of the best companies to work for. As an Associate Director in Cyber Security Governance, Risk, and Compliance, you will have the opportunity to work on some of the...
-
Security Lead- Grc
2 days ago
Sydney, Australia Bluefin Resources Full time2IC role - solid growth and great career path - excellent company culture A leading financial services organisation is currently seeking an Information Security Lead-GRC and 2IC to join their team on a permanent basis. **Responsibilities**: - Manage, mature and maintain the Third Party Vendor (TPV) security program, including regulatory requirements,...
-
Business Analyst
2 days ago
Sydney, Australia Medibank Private Limited Full timeAt Medibank we’re encouraged to think big. We have a clear purpose to impact better health outcomes for our customers, patients and our community. We celebrate diversity of thought because we want to make better decisions for our customers. As we work towards our goal of better health for better lives, we value the knowledge and contribution of Aboriginal...
-
IT Security Manager
2 weeks ago
Sydney, Australia Frazer Tremble Executive Full timeNV1 clearance required - Permanent position with opportunity for growth - Collaborate with market leaders in this space This NV1 Cyber Security Manager position is with an international leader in their field. Providing their services across Australia, they are now on the lookout for an experienced IT Security Leader to join their team. Working across...
-
Grc Specialist, Aws Security
4 days ago
Sydney, Australia Amazon Web Services Australia Pty Ltd Full time2+ years experience working in areas related to security assurance, such as cybersecurity, auditing, security architecture, regulatory affairs or public sector agencies involved in cybersecurity management. - Experience working with governance, risk and compliance programs that directly involve interaction with regulatory bodies. - Proficient with government...
-
Grc Analyst
2 days ago
Sydney, Australia Latitude Full timeGRC Analyst opportunity focused towards SOX compliance frameworks - Work with a leading company who are expanding their presence Nationally - Flexible hybrid working conditions on offer We have a rewarding new permanent opportunity available for a **Governance, Risk, and Compliance Analyst (GRC & SOX Analyst), **to join a supportive and growing technology...