Governance, Risk, Compliance

2 days ago


Sydney, Australia SAS Full time

:
At SAS, where you start doesn’t have to be where you end; and there is ample opportunity for internal career mobility. Whether you’re looking to grow a new skill or experience a new role, there’s no time like the present to take the next step; and we’re here to support you in your journey.

We’re looking for a Governance, Risk, Compliance - Audit Security Advisor to join our team in Australia, specifically focused on Compliance in Government. The role will assess information security and cybersecurity risk, facilitate compliance with regulatory requirements and information security policies, execute assurance testing to required performance standards, and develop and report information security metrics. They are responsible for lowering information security and cybersecurity risk to SAS, partnering with other teams across the enterprise.

**Your responsibilities may include**:

- Review SAS Cloud or on-premises security contract terms, respond to RFP and security questionnaires, and support information security-related discussions with customer security teams and auditors during negotiations and post-sale operational activities.
- Facilitate and ensure continuous monitoring activities are operating effectively, identifying control gaps and deficiencies and reporting to management, as applicable.
- Assist in the development System Security Plans, Plans of Actions and Milestones, Continuous Monitoring Plans, and Incident Response Plans in collaboration with other teams.
- Conduct scheduled and ad hoc reviews of applicable SAS Cloud solution environments, including the support and management of external assessor activities related to certifications and customer contractual requirements.
- Research and contribute to information security polices and standards, with the objective of continually maturing operations, while meeting regulatory and compliance obligations.
- Participate in security investigations and compliance reviews, as required by contract or regulation.
- Identify and recommend cost effective improvements to security practices while maintaining compliance to required standards and regulations.
- Use the GRC tool to create and manage continuous monitoring indicators, build reporting dashboards, document electronic work papers, and manage audit documentation.
- Identify risk issues and work in collaboration with other teams across the enterprise to remediate.

**Other knowledge, skills, and abilities**
- Maintain an ability to be flexible with others, to display tact and diplomacy, and to maintain a high degree of confidentiality and integrity.
- Strong time management skills (schedules, prioritization).
- Excellent communication, analysis, and process flow skills.
- Ability to be flexible, display tact and diplomacy, and maintain confidentiality and integrity.
- Must have the ability to work with little supervision, escalating issues, as appropriate.
- Perform other duties, as assigned.
- Travel as business requirements dictate at management discretion.

**Qualifications**
- Bachelor's degree in Business, IT, Computer Science, Project Management or related field
- 5-8+ years of functional experience in project management, management consulting, IT, audit/compliance or related field.
- Experience in a regulated (pharmaceutical, banking, insurance, government) industry (may be concurrent with the above functional experience).
- Understanding of regulatory standards (ex: IRAP, PMDA, PCI, NIST 800-53).
- Knowledge and experience with best practices/standards (ex: COBIT, GAMP5, ISO 27000 or 42000).
- Must be an Australian citizen
- Successful applicants will be required to complete a background check (including criminal history check) prior to commencement of employment.

**Nice to Haves**
- Use and/or implementation of a GRC tool (ex: ServiceNow, Archer, Teammate, Thompson Reuters)
- Management consulting experience
- Experience with ServiceNow issue management ticketing system
- Auditor or security certification (ex: CISA, IIA, CISSP) and/or training
- SAS software implementation experience or IT hosting experience

**Diverse and Inclusive**

At SAS, it’s not about fitting into our culture - it’s about adding to it. We believe our people make the difference. Our diverse workforce brings together unique talents and inspires teams to create amazing software that reflects the diversity of our users and customers. Our commitment to diversity is a priority to our leadership, all the way up to the top; and it’s essential to who we are. To put it plainly: you are welcome here.#SAS

LI-IL1



  • Sydney, Australia Cicero Corporation Pty Ltd Full time

    Newly created role Instrumental to the business and a fantastic team under you. Outstanding benefits and fabulous down to earth culture In this newly created role you will be responsible for championing governance, compliance and risk mitigation across the entire business. Leveraging the existing Compliance Playbook, the role will strengthen current sales...


  • Sydney, New South Wales, Australia Eunexus Pty Ltd Full time

    About EunexusEunexus is a high-security cloud services provider delivering private, secured, and fully managed hosting environments for clients with advanced compliance needs. Our proprietary Eunexus Cloud platform is designed for organisations that require dedicated, compliant, and scalable infrastructure supported by Australian-based teams.The RoleWe are...


  • Sydney, New South Wales, Australia Kwela Solutions Pty Ltd Full time $90,000 - $120,000 per year

    About UsKwela Solutions, a leading Governance Risk & Compliance software company is seeking a Consultant with experience in Risk & Compliance and a keenness to implement software. The consultant will join an experienced team that supports our clients with the implementation and training of our web-based software, Folio, which enables organisations to align...


  • Sydney, New South Wales, Australia nbn® Australia Full time $120,000 - $180,000 per year

    Build your career and Australia's future.Not many people can say they are working on building Australia's future. With us you'll be doing just that, leaving a legacy for all Australians. Plus, there's equal employment, great training, and true flexible working arrangements.We have an exciting opportunity at nbn for aHSE Governance, Risk and Compliance...


  • Sydney Olympic Park, Australia Flourish Australia Full time

    Flourish Australia has an exciting opportunity for a **Manager, Governance, Risk and Compliance** to join our Support Hub team in **Sydney Olympic Park**!** **About the position**: - **Ongoing full-time **(76 hours per fortnight) - **Working Monday to Friday**: - Located in** Sydney Olympic Park**: - **Flexible working from home arrangements** are...


  • Sydney, Australia MinterEllison Full time

    **Location**: Sydney **Contract Type**: Permanent MinterEllison is one of Australia’s largest law firms, with nearly 200 years of business history. We're known for our legal and consulting expertise - and for our inclusive and authentic character. Our purpose is to create sustainable value with our clients, people and communities. That means we have a...


  • Sydney, Australia Domain Group Full time

    **Cyber Governance, Risk and Compliance Manager - Sydney Office - Permanent Full Time** We have a high impact; newly created opportunity for an experienced Cybersecurity Governance, Risk and Compliance (GRC) Manager, to join our Domain team. Reporting into the Chief Information Security Officer (CISO); you will be responsible for the implementation and...

  • Governance, Risk

    1 week ago


    Sydney, Australia Leidos Full time

    Company Description **Job Description**: Leidos Australia have a great opportunity that enables you to build on your Cyber Security experience and utilise your passion in a Governance, Risk and Compliance role. In this permanent full time opportunity supporting a major Federal Government Program, you will be pivotal in ensuring the ongoing ICT security...


  • Sydney, New South Wales, Australia Fujitsu Full time $120,000 - $150,000 per year

    About the job Expression of Interest_ Governance, Risk and Compliance (GRC)We Are FujitsuWe use technology to make happier lives. We are a global leader in technology and business solutions that transform organizations and the world around us. We have a long heritage of bringing innovation and expertise, continuously working to contribute to the growth of...


  • Sydney, New South Wales, Australia Platinum Pacific Partners Full time $104,000 - $130,878 per year

    Our client is a high-growth investment management and technology business that's redefining how people engage with financial products and services. With a focus on simplifying wealth management, they deliver managed funds, model portfolios and tailored solutions to the advised retail market. Combining institutional-grade investment strategies with...