Principal Cyber Security Governance Risk and Audit Analyst

10 hours ago


Melbourne City Centre, Victoria, Australia Victorian Government - Department of Health Full time $120,000 - $180,000 per year

About the role:

The Principal Cyber Security Analyst Governance, Risk & Audit is responsible for leading and executing end-to-end activities related to internal and external audits, governance forums, cyber security performance reporting, and cyber risk management. This role plays a key part in strengthening the department's cyber resilience by identifying opportunities to enhance the capture, consolidation, alignment, and analysis of cyber and information security risks. The Principal Cyber Security Analyst will apply relevant frameworks, including the Victorian Protective Data Security Standards (VPDSS), the Essential 8, and the National Institute of Standards and Technology (NIST) to ensure continuous improvement and a robust approach to cyber risk governance.

About us:

At the Victorian Department of Health we want a future where Victorians are the healthiest people in the world. A Victoria where our children and people thrive, our workplaces are productive and safe, and our communities are more connected.

We see it as our job to support Victorians to stay healthy and safe. And to deliver a world-class healthcare system that ensures every single Victorian can access safe, quality care that leads to better health outcomes for all.

About you:

We are looking for someone who can:

  • Lead and establish a consistent process with the Cyber Security Management Team so that assurance and security risks are captured, assessed, reviewed and managed.
  • Coordinate and manage internal and external stakeholder involvement in risk, compliance and audits activities.
  • Lead, establish and deliver regular reporting of KPIs, risks and treatments for relevant senior governance forums by evolving the cyber dashboard.
  • Manage end-to-end ongoing review of risk with risk owners and maintain currency of all cyber risks in alignment with the relevant risk registers.
  • Produce simple and effective analysis and content for use in branch reports and senior governance forums and briefing papers for steering committees.

Qualifications/Specialist expertise:

  • A tertiary qualification in fields related to public policy, governance, risk and audit, or experience in cyber security would be desirable.
  • High level competency in Microsoft office, data analysis, Power BI reporting and a high level of computer literacy.
  • High level competency in writing departmental memorandums, briefs and other documentation, following defined processes, writing style and visual style guides.
  • Experience with risk management, audits and the requirements of governance committees.
  • Experience analysing and reporting cyber / information security risks.
  • Experience with common information security frameworks e.g. Victorian Protective Data Security Standards, Essential 8, NIST.

For more information please refer to the attached Position Description.

What we offer: .

  • The opportunity to perform meaningful work, making direct contributions toward enabling Victorians to be the healthiest people in the world.
  • A wide range of growth and development opportunities within the department and wider Victorian Public Service & Sector.
  • A strong commitment to work-life balance, including a diverse array of flexible working arrangements.

How to apply:

Applications should include a resume and a cover letter. Click the `Apply' button to view further information about the role including key contact details and the advertisement closing date.

We are committed to developing and supporting a workforce that is well equipped and highly motivated to provide responsive and quality services to all Victorians. We continue to build an inclusive workplace that embraces diversity of backgrounds and differences to realise the potential of our employees for innovation and delivering services aimed at enhancing the lives of all Victorians. All roles can be worked flexibly and we encourage applications from Aboriginal people, people with disability, LGBTIQ+ and people from culturally diverse backgrounds. Please contact us if you require any adjustments to participate in the recruitment process at For more information on our commitment to inclusion and diversity see inclusion and diversity at the Department of Health.

If you have any queries in relation to recruitment processes at Health, or experience any issues in applying, please feel free to email Please note that unsolicited applications will not be replied to. If you have questions regarding the role specifically, we would advise you to reach out to the contact listed on the advertisement directly.

Preferred applicants may be required to complete a police check and other pre-employment checks. Information provided will be treated in the strictest confidence in line with our Privacy Policy.



  • Melbourne, Victoria, Australia Department of Health Full time $70,000 - $120,000 per year

    About the role:The Principal Cyber Security Analyst Governance, Risk & Audit is responsible for leading and executing end-to-end activities related to internal and external audits, governance forums, cyber security performance reporting, and cyber risk management. This role plays a key part in strengthening the department's cyber resilience by identifying...


  • Melbourne City Centre, Victoria, Australia Department of Education Full time $80,000 - $120,000 per year

    RoleSecurity Assurance AnalystGroup/Division/BranchFinancial Policy and Information Services/ Information Management and Technology Division/ Information Security ServicesClassificationVPS5LocationCBD Melbourne (Hybrid)Reports ToFelix Chow - Security Assurance ManagerAbout the RoleThe Security Assurance Analyst is a key contributor to our information...


  • Melbourne, Victoria, Australia C9 Group Full time $120,000 - $150,000 per year

    Role: Cyber Governance Risk and Compliance SpecialistSalary: 100,000 AUD plus SUPERANNUATIONJob Type: Full-time, PermanentWorking Hours: 38 hours per weekLocation: Melbourne, Victoria, AustraliaKey ResponsibilitiesLead the governance, risk, and compliance (GRC) function for cyber security, ensuring alignment with organisational objectives, regulatory...


  • Melbourne, Victoria, Australia Experis Australia Full time $120,000 - $180,000 per year

    Principal Cyber Security Analyst - Splunk | ISO27001 | MITRE ATT&CK | Incident ResponseLocation:Melbourne (Hybrid) 3 days on-siteType:PermanentSalary:Competitive + SuperAbout the RoleA leading organisation is seeking a Principal Cyber Security Analyst to lead advanced cyber defence and incident response initiatives. You'll work alongside a high-performing...


  • Melbourne, Victoria, Australia The Citadel Group Full time $80,000 - $120,000 per year

    Short Summary:Reporting to the Chief Information Security Officer (CISO) this position carries out cyber security monitoring and ensures that security events are identified in the early stages to ensure that adverse effects are prevented. This position works to optimise cyber security monitoring and response throughout the enterprise.Who are we:At Citadel...


  • Melbourne, Victoria, Australia RJE Global Pty Ltd Full time

    RJE Global is an Australian owned company providing innovative and industry-leading Engineering, Procurement and Construction (EPC) services for the electrical industry.We excel in a variety of disciplines, encompassing design, engineering, construction, commissioning and maintenance. Our commitment to delivering innovative and client-centric solutions is...

  • Cyber GRC Analysts

    1 week ago


    Melbourne, Victoria, Australia Talent Full time $90,000 - $120,000 per year

    4 x Cyber GRC Analysts - NV1 Clearance - SCTY 5 - Flexible Location (Australia)We're looking forCyber Governance, Risk & Compliance Analyststo join Defence programs across Australia (work can be based anywhere in the country).You'll work with project teams, engineers and architects to analyse and document cyber security risks, develop Security Documentation...


  • Melbourne, Victoria, Australia Alinta Energy Full time $90,000 - $120,000 per year

    Drive third-party cyber resilience across critical business partnershipsApply your expertise in cyber risk frameworks and regulatory complianceEnjoy hybrid work options, energy discounts, and career growth opportunitiesAlinta Energy is one of Australia's biggest energy retailers, generators and developers with over 1.1 million customers. Australia's energy...


  • Melbourne City Centre, Victoria, Australia Hays Full time $104,000 - $130,878 per year

    Your new company This role sits with a reputed organisation in financial services to support the community for a better future. Your new role As a Security Operations Analyst, you will be responsible for the administration of Security Monitoring tools and execution of security procedures to maintain adequate system security controls,...


  • Melbourne, Victoria, Australia Torch Professional Services Pty Ltd Full time $120,000 - $180,000 per year

    *Must have NV1 or NV2 clearances (non-negotiable)*Immediate or 4 weeks notice start*Urgent rolesCyber Engineering4 x Cyber GRC Analysts - NV1 - SCTY 5 Cyber Governance Risk and Compliance Analysts will work alongside project teams, Engineers, Solution Architects and systems integrators to analyse and document cyber security risks.They will be responsible...