Cyber Security Governance, Risk

2 weeks ago


Sydney, New South Wales, Australia GWA Group Full time

Join our vibrant team at GWA, where our rich Australian and New Zealand heritage, technical expertise, and innovative drive, combine with our iconic brands to create something truly extraordinary. For over a century, we've been crafting innovative, high-quality products for homes and offices, including market-leading brands like Caroma, Methven and Clark.

Your new role

We take cyber security seriously at GWA and it is pivotal to supporting our digital transformation and managing the direction of the infrastructure underpinning our digital growth. To bring all of this to life, we are looking for a Cyber Security Governance, Risk & Compliance Engineer in all facets of modern enterprise technologies to help us bring this transformation to life. Internally this role will be known as a Cyber Security Engineer.

This is a permanent, full-time position based in our Prestons office.

You will proactively partner with your stakeholders and the Technology team to drive best practice cyber security leadership across our transformation projects, all whilst supporting ongoing operational security activities.

As our new Cyber Security GRC Engineer, your key responsibilities will include but will not be limited to:

  • Lead the development, implementation, and improvement of cyber governance frameworks, policies, and procedures.

  • Oversee compliance with ISO27001standards.

  • Manage risk assessments, audits, and incident response planning for clinical and digital environments.

  • Advise on regulatory changes and ensure organizational readiness for compliance.

  • Collaborate with internal and external stakeholders to promote a culture of security and compliance.

  • Monitor and report on compliance metrics, risk posture, and audit outcomes to executive leadership.

  • Support integration of AI governance, data protection, and privacy controls in clinical systems.

  • Champion secure-by-design principles in service architecture and digital transformation initiatives.

Secondary Responsibilities

  • Provide hands-on engineering capability for securing cloud services, especially Microsoft Azure.

  • Support system troubleshooting and resolution of high-priority security issues.

  • Design and develop resilient, secure patterns for cloud services and infrastructure.

  • Implement and manage Microsoft Purview for Data Loss Prevention (DLP), Insider Risk Management, and Information Protection, PIM, Azure AD, Sentinel, Defender, Cloud App Security, VWAN.

  • Oversee vulnerability and patch management tools (e.g., Rapid7).

  • Apply secure code practices and automation pipelines.

  • Conduct logging and monitoring using cloud-native SIEM architecture.

About you

You bring at least 3+ years of experience in cyber governance, risk management, and compliance—ideally within regulated environments. Your background includes:

  • Implementing ISO27001 or similar frameworks in IoT settings.

  • Deep understanding of ISO27001requirements and regulations.

  • Experience with AI governance, data loss prevention, insider risk management, and information protection.

  • Familiarity with public cloud infrastructure, Azure platforms, and Microsoft Purview.

  • Strong stakeholder engagement and communication skills.

Technical Qualifications (Required/Highly Desirable):

  • Certified ISO/IEC 27001 Lead Implementer

  • Cybersecurity industry certifications such as CISSP, CISM

  • Microsoft Azure AZ-500 certification.

  • Experience with MS Azure Security services (PIM, Azure AD, Sentinel, Defender, etc.).

Why you'll love it here

At GWA, you'll join a supportive, customer‑focused team that values collaboration and growth. We're on a journey from Good to Great, working with iconic brands and making a real difference for our customers every day.

You'll enjoy a great team environment, hybrid work options, onsite parking, and great product discounts, plus wellbeing support and an onboarding program that sets you up for success from day one.

Ready to make a difference?

Apply now and help us deliver service that stands out.

Ready to apply? Great Just click the apply button to build your career with us Please note: You must be a citizen, permanent resident or hold all the relevant employment visas and other approvals for the location and duration of this position to apply for this role. Please note that we are not accepting applications from agencies for this position.



  • Sydney, New South Wales, Australia Cuscal Limited Full time

    Forward with CuscalAt Cuscal, we're not just shaping the future of payments - we're pioneering it. From launching Australia's first ATM to being the first certified NPP PayTo Payer and Initiator in 2022, we've spent over 59 years building solutions that millions of Australians rely on every day.Now, we're preparing for what's next, and we want you to be part...

  • Cyber Security

    10 hours ago


    Sydney, New South Wales, Australia Deloitte Services Pty Ltd Full time

    Learn from the best in the business Flexible work arrangements – work in a way that suits you best, including part-time options Access to free and confidential coaching for you and your family including wellbeing, financial and nutrition coachingWe're looking for talented Cyber Professionals from various backgrounds and levels to express their interest in...


  • Sydney, New South Wales, Australia KPMG Full time

    Job DescriptionAbout the TeamAt KPMG Australia, our Consulting Technology Risk and Cyber team is at the forefront of enabling organisations to navigate the complex world of technology, cyber threats, and information security. We deliver impactful and innovative solutions tailored to our clients' needs, helping them identify and manage technology risks,...


  • Sydney, New South Wales, Australia KPMG Australia Full time

    Job DescriptionAbout the TeamAt KPMG Australia, our Consulting Technology Risk and Cyber team is at the forefront of enabling organisations to navigate the complex world of technology, cyber threats, and information security. We deliver impactful and innovative solutions tailored to our clients' needs, helping them identify and manage technology risks,...

  • Cyber Security Lead

    2 weeks ago


    Sydney, New South Wales, Australia Project Pathway Recruitment Full time

    Company BackgroundThis organisation is a fast-growing financial services scale-up building modern technology, operations, and customer platforms for major brands and partners across the industry. With a strong reputation for service excellence and a people-driven culture, they combine deep domain expertise with a rapidly evolving technology environment. The...


  • Sydney, New South Wales, Australia FTI Consulting Full time

    About The RoleFTI Consulting is the number one global expert firm for organisations facing crisis, transformation and moments of truth. The Cybersecurity Practice within FTI Consulting is a leading provider of independent cyber and risk management advisory services with a core offering focused on (but not limited to) Cyber Readiness including Cyber Risk...


  • Sydney, New South Wales, Australia CDC Data Centres Full time

    About Us:CDC Data Centres is Australia's leading operator of sovereign, secure, world-class data centre facilities.Headquartered in Canberra with multiple facilities across ACT, NSW, VIC and New Zealand, CDC's diversified operations provide secure data centre configurations that support co-location, containerised and hyperscale compute environments with...

  • Cyber Security Lead

    2 weeks ago


    Sydney, New South Wales, Australia The Network Technology Recruitment Full time

    Cyber Security LeadHybrid - Sydney$212k PackageHow about the opportunity to take ownership of security in a high-growth tech environment leading hands-on initiatives, driving maturity and shaping how critical systems are protected?About the CompanyJoin a fast-moving technology-led organisation that's transforming how people access and interact with essential...


  • Sydney, New South Wales, Australia Precision Sourcing Full time

    Senior Cyber Security Operations Analyst (IT/OT)Role highlightsSenior, autonomous cyber operations role with strong OT exposureClear integration with external SOC and defined in-house ownershipHigh-volume change, risk, and incident environmentSalary$145,000 - $175,000 DOE + short term bonus incentiveBenefitsFlexible working arrangementsHigh-trust role with...


  • Sydney, New South Wales, Australia FTI Consulting Full time

    About The RoleFTI Consulting is the number one global expert firm for organisations facing crisis, transformation and moments of truth. The Cybersecurity Practice within FTI Consulting is a leading provider of independent cyber and risk management advisory services with a core offering focused on (but not limited to) Cyber Readiness including Cyber Risk...