Security Compliance Analyst

3 days ago


Melbourne, Australia KPMG Full time

**Job no**: 519867

**Work type**: Permanent Full Time

**Location**: Melbourne

**Division**: Business Services

**Role and Responsibilities**:
**The Security Compliance Analyst works for the Manager of Security Compliance, a team within the Governance, Compliance and Risk function of the Information Security Office (ISO). This role requires the ability to communicate to, and assist in presenting to IT leadership, Privacy and Office of General Counsel with regards to information security compliance and ongoing improvement of KPMG’s information security posture. The role must provide a balanced blend of business enablement while minimising information security risk, providing pragmatic advice to uphold policies and assisting project and stakeholder teams to work through compliance challenges.**:
**The core functions of this role include**:

- **Assess all aspects of information security compliance for KPMG Australia;**
- **Assist in providing information security reporting to local IT leadership, regional and global leadership;**
- **Coordinate with other aspects of the business including Legal, Privacy, P&I (HR), CISO, ITS and internal stakeholders within the business;**
- **Assist the Security Compliance team in facilitating the annual external ISO27001/27017 audit, the internal Information Protection Controls Audit (IPCA) and any other reviews such as APRA CPS234 or NIST CSF;**
- **Perform regular compliance reviews to ensure adherence to KPMG Policies, Procedures and Standards;**
- **Perform regular reviews of KPMG Policies, Procedures and Standards to ensure they remain up to date and aligned to global documents;**
- **Assist in developing and deploying the annual mandatory Security Awareness for Everyone (S.A.F.E.) training and quarterly Phishing Awareness training; track mandatory training completion by KPMG users;**
- **Assist in working with ASPAC, regional or Global teams to implement broader information security initiatives;**
- **Answer Client Queries about KPMG’s information security posture in a timely manner;**
- **Liaise with OGC and the business to review client contracts’ security clauses to ensure KPMG can agree to the security clauses posed by clients, or amend as necessary;**
- **Proactively provide assistance in other Security Compliance team work as needed.**

**Qualifications and Education Requirements**:
This role requires:

- Minimum of a bachelor’s degree in an information or business-related discipline.
- Minimum 1.5-2 years of experience in IT roles, preferably with involvement in a combination of compliance, auditing and service desk work.
- Preferred, but not required to have accreditation in two of the following, ISO27001 Lead Auditor or Lead Implementor/CISM/Microsoft SC 900 - Security, Compliance and Identity Management; GCIH and/or CISSP (or relevant certifications)
- A valid Australian Driver’s License (any State or territory)
- Criminal Records Check and possible a National NV-1 security clearance

**Preferred Knowledge / Skill / Ability**:
**Key Responsibility Areas **_(Please list in order of importance)_**

**_Key Position Accountabilities_**
Name the key areas for which the position is accountable

**_ % of Total Role_**

**_ Major Standards_**

What are the key activities or tasks to be carried out?
- **_Outputs:_**:

- What are the expected end results?

**_Measures:_**
How are these results measured?
- **Security Compliance Management**

70%
- Ensure all appropriate information security controls are implemented within KPMG, including conducting annual reviews and tracking findings.
- Ensure Information security controls are embedded into KPMG’s processes.
- Promote information security awareness and facilitate end-user training.
- Assess security clauses within proposed client contracts to ensure alignment with KPMG’s information security posture, security policies and risk appetite.
- Respond to Client Queries relating to KPMG’s information security posture in a timely manner, to enable the business to work with KPMG clients.
- Establish a local process to review and ensure local/regional compliance with Global compliance requirements, systems and processes.
- Assist in the assurance of effective Information Security Policies & Standards and testing compliance against the Policies & Standards.
- Coordinate with the internal teams and stakeholders to timely conclude the security reviews. Liaising with the stakeholders to close/remediate open findings.
- Assist in follow-up process for annual firm-wide training to confirm compliance and completion of the security training. Assist in publishing monthly firm-wide security awareness articles.
- Assist in maintaining effective working relationships within the business by responding promptly to the active client queries/security assessments and contracts.
- Assist in project reviews and assessments to ensure information security best practices.
- Monitoring and compliance reporting.
- Maintaining and ens



  • Melbourne, Victoria, Australia Uniting (Victoria and Tasmania) Limited Full time $89,900 - $96,300 per year

    Permanent full time opportunityBased in Melbourne's CBD with hybrid work arrangementsBe part of a purpose-driven organisation making meaningful social impactYour new roleAs Security Compliance Analyst, you will support the development and maintenance of Uniting's security standards and ensure ongoing compliance with key frameworks.Working closely with the...


  • Melbourne, Victoria, Australia Uniting Vic Full time $89,000 - $96,000 per year

    Permanent full time opportunityBased in Melbourne's CBD with hybrid work arrangementsBe part of a purpose-driven organisation making meaningful social impactYour new roleAs Security Compliance Analyst, you will support the development and maintenance of Uniting's security standards and ensure ongoing compliance with key frameworks.Working closely with the...

  • Security Analyst

    5 days ago


    Melbourne, Australia affix Full time

    GRC Security Analyst We are seeking a highly skilled and motivated GRC Security Analyst to join our team. As a GRC Security Analyst, you will be responsible for ensuring the security and compliance of our systems, identifying and mitigating threats and vulnerabilities, and contributing to the overall security posture of the organization. This is an exciting...


  • Melbourne, Australia Staffx Pty Ltd Full time

    **About the Company** This IT Services and IT Consulting company is an Australian company that has core competencies in banking and financial services. They work with leading and local companies across the APAC region. Their highly skilled, talented IT specialists are experts in their fields, and employees are placed in key value-adding roles with our...


  • Melbourne, Australia McMillan Shakespeare Group Full time

    Cyber Compliance Analyst The McMillan Shakespeare Group (MMS) is a trusted provider of salary packaging, novated leasing, disability plan management and support co-ordination, asset management and related financial products and services. From our origins in 1988 when we created Australia's salary packaging industry to today, MMS has a proud history of...


  • Melbourne, Australia Australian Bureau of Meteorology Full time

    Executive Level 1, Ongoing/Non-ongoing - $115,443 - $125,832 + 15.4% super - Melbourne The Security Risk Analyst is a trusted advisor and analyst, reporting to the Security Risk Manager. The position plays an important role in safeguarding the Bureau's customers, systems, personnel and facilities, ensuring compliance with Australian Government's Protective...

  • IT Security Analyst

    5 days ago


    Melbourne, Australia Halcyon Knights - LogicMelon Full time

    A rare opportunity to sharpen your cybersecurity skills across a number of cyber domains - National business that values diversity, creativity, and encourages professional development. - Support the company's cybersecurity program and strategy at an operational level. Job Title: IT Security Analyst Location: Mount Waverly Key Responsibilities: - Ensure...

  • Security analyst

    1 week ago


    Melbourne, Victoria, Australia Kinetic IT Full time $80,000 - $120,000 per year

    About Kinetic IT:We are recognised market leaders in the delivery of high-quality technology solutions to large public, private, and government organisations. As an Australian-owned company, we take a lot of pride in delivering exceptional service that exceeds our customers' expectations and positively contributing to our industry and community.  We hire...

  • Security Analyst

    7 days ago


    Melbourne, Australia PRA Full time

    As a Security Analyst you will be responsible for maintaining, implementing and improving the cyber security strategy and ensuring the company’s digital assets are protected against unauthorised access. You will play a key role in the execution of the security compliance program, performing regular audits of systems and permissions, monitoring access,...


  • Melbourne, Australia McMillan Shakespeare Group Full time

    The McMillan Shakespeare Group (MMS) is a trusted provider of salary packaging, novated leasing, disability plan management and support co-ordination, asset management and related financial products and services. From our origins in 1988 when we created Australia's salary packaging industry to today, MMS has a proud history of innovation and exceptional...