Cyber Security GRC Analyst
1 week ago
About Us
Making a meaningful difference with mission-critical software that empowers communities to thrive.
ReadyTech is more than just a one-trick pony playing in one market with one product, or one customer. We re-imagine, design, develop and deliver technology to solve our customer's diverse problems – supporting multiple businesses across a variety of markets to be ready for anything.
We're an ASX-listed company which means we are stable, have a strong track record of sustainable growth and have a significant number of long-term customers. So, what does this mean for you? It means we can offer you an experience that will push you to be your best, provide career-building challenges, and that will offer you numerous growth opportunities that can't be found in any other company.
It's an inclusive environment where there is no place for politics, where we get our heads together to solve the problems that really matter to our customers, and where we always stay focused on our north star – the communities we serve, and society at large.
The Key Accountabilities Of The Role
- Lead the implementation and continuous improvement of ReadyTech's cyber security GRC framework aligned with IRAP, SOC 2, and ISO 27001 standards.
- Coordinate and manage external audits and assessments, ensuring audit readiness, evidence collection, and timely remediation of findings.
- Maintain and oversee the cyber risk register, including risk identification, analysis, treatment, and ongoing monitoring.
- Develop, update, and maintain information security policies, procedures, standards, and guidelines that reflect compliance requirements under IRAP, ISM, SOC 2, and related frameworks.
- Report and communicate cyber performance, compliance status, and risk indicators to executive and governance forums.
- Support the integration of compliance controls into IT and cloud environments to ensure secure-by design operations.
- Promote a strong security and compliance culture through collaboration, education, and awareness initiatives across the business.
The Key Responsibilities Of The Role
Governance & Policy
- Develop, maintain, and align ReadyTech's information security policies and control library with ISM, IRAP, SOC 2, ISO 27001, and NIST frameworks.
- Map control requirements across frameworks to reduce duplication and simplify compliance activities.
- Ensure all policies and standards are reviewed, approved, and communicated to relevant stakeholders.
Risk & Compliance Management
- Manage the cyber risk management process, including assessment, documentation, and reporting of risks.
- Lead compliance activities to maintain certification and attestation under IRAP and SOC 2.
- Support the creation and maintenance of System Security Plans (SSP), Security Plans and Risk Registers, and Plans of Action and Milestones (POA&M) for IRAP.
- Manage vendor and third-party risk assessment programs to ensure compliance with regulatory and contractual obligations.
Audit & Assurance
- Coordinate and facilitate IRAP, ISO assessments and SOC 2 audits, including evidence collection, gap analysis, remediation tracking, and reporting.
- Maintain detailed audit logs and assurance documentation to support external review and internal reporting.
- Conduct internal control testing and assurance reviews to assess compliance effectiveness and identify improvement opportunities.
Awareness & Culture
- Champion a strong security and compliance culture across ReadyTech.
- Deliver targeted training and communication to increase awareness of regulatory and framework requirements.
- Support teams in embedding compliance controls within business processes, development pipelines, and infrastructure management.
Skills
The key requirements for the role:
- Strong analytical, communication, and presentation skills.
- Ability to translate technical risks and controls into business-relevant language.
- Exceptional organizational and time management skills with a focus on meeting compliance deadlines.
- Demonstrated initiative, accountability, and stakeholder management across technical and non-technical teams.
Knowledge
Deep understanding of security and risk frameworks, including:
IRAP, ASD ISM, and PSPF
- SOC 2 Trust Services Criteria
ISO 27001/27002, NIST CSF, and ITIL
Familiarity with GRC tools and platforms.
- Understanding of cloud and SaaS architectures, especially within Microsoft Azure environments.
- Awareness of relevant data privacy and protection regulations
Experience
- Minimum 4+ years in information security, with 2+ years in a GRC, compliance, or audit coordination role.
- Demonstrated experience coordinating external audits or assessments (IRAP, SOC 2, ISO 27001, or FedRAMP).
- Proven experience in managing audit evidence, remediation, and control effectiveness testing.
- Background in systems administration or cloud infrastructure preferred, to bridge operational and compliance considerations.
- Experience developing and maintaining documentation such as SSPs, POA&Ms, and audit reports.
Performance Indicators
- Successful completion and maintenance of IRAP and SOC 2 compliance with minimal findings.
- On-time completion of audit and assessment milestones.
- Measurable improvement in compliance maturity and risk reduction.
- Effective communication of compliance and risk status to executive leadership.
- Increased staff awareness and adherence to compliance obligations.
Why You Should Become a ReadyTecher
- A day off for your birthday- hip hip hooray
- Additional 4 days of leave each year
- ReadyTecher Awards each quarter with the chance to win flights and accommodation to Hamilton Island
- Hybrid work, with in-house baristas in Australia via the Ready Beans team
- Access to Sonder- a technology-driven platform supported by safety, medical and mental health experts - available 24/7
- Paid parental leave
- Additional paid leave for miscarriage, endometriosis and menopause
- Volunteer leave
- Flu vaccinations
- And plenty of ReadyTech merch drops along the way
ReadyTech is committed to seeing things through each other's eyes. We invest deeply in relationships by offering positivity, fairness and empathy in every interaction and love that everyone is different. We're proud to be an equal opportunity employer that celebrates our diversity of race, beliefs, sexual orientations, gender identities, age, disability status, marital status and more - so that every single one of us can feel like we belong.
As part of our commitment to ensuring a safe and secure working environment for all employees and in compliance with Australian regulations, please note that if selected for this role, you will be required to complete a comprehensive police check and an Australian working rights check. Should you have any questions or concerns regarding these requirements, please feel free to contact us.
So, if you are ready for anything, please apply today. Please note that if your application is progressed to the next stage, we will send you some testing to complete as part of your application as we have found this helps us to quickly identify potential ReadyTechers
Position description Apply now
Share
-
Cyber Security GRC Analyst
6 days ago
Sydney, New South Wales, Australia Leidos Full time $80,000 - $120,000 per yearWe're a 'Family Friendly' certified workplace – we understand the diverse roles our team members need to play within their own unique family setting and actively support them. Our team feel Leidos is a great place to work. Learn more about our culture and benefits by visiting us here Do Work That Matters Leidos Australia delivers IT and...
-
Cyber Security
6 days ago
Sydney, Australia Firesoft People Full time**Cyber Security - Associate Director (GRC)** **Global Professional Services** **$180k - $200k + Super** **Brisbane Based** Our client a renowned organization consistently recognized as one of the best companies to work for. As an Associate Director in Cyber Security Governance, Risk, and Compliance, you will have the opportunity to work on some of the...
-
Senior GRC Consultant
6 days ago
Sydney, New South Wales, Australia e2 Cyber Full timeWe are seeking aCyber Security GRC Consultantto join a growing advisory team delivering high impact security and compliance outcomes for clients across Australia. This is aclient facing consulting rolewhere you will work directly with stakeholders across financial services, healthcare, critical infrastructure, and government sectors to strengthen cyber...
-
Cyber Security Analyst
2 weeks ago
Greater Canberra Area, Australia Strategic Partners Australia Full time $120,000 - $180,000 per yearWe are hiring for aPrincipal Cyber Security Analyst - (EL2 Level)for one of our Clients.Role:Principal Cyber Security Analyst - (EL2 Level)Location of work:Canberra (Hybrid)Contract duration:12 months + 24 months extensionSecurity clearance:NV1 security clearanceJob detailsKey duties and responsibilitiesThe Cyber Operations Section requires a Senior Cyber...
-
Cyber GRC Consultant
2 weeks ago
Greater Brisbane Area, Australia Sekuro Full time $80,000 - $120,000 per yearAbout UsAt Sekuro, we lead the charge in cybersecurity innovation and protecting digital landscapes with cutting-edge solutions. Join our dynamic team where creativity, collaboration, and excellence drive our mission to secure Australian organisations.About the RoleWe're on the hunt for a talented mid to senior-level Cyber GRC Consultant to join our growing...
-
Grc Analyst
1 week ago
Sydney, Australia Latitude Full timeGRC Analyst opportunity focused towards SOX compliance frameworks - Work with a leading company who are expanding their presence Nationally - Flexible hybrid working conditions on offer We have a rewarding new permanent opportunity available for a **Governance, Risk, and Compliance Analyst (GRC & SOX Analyst), **to join a supportive and growing technology...
-
GRC Cyber Security Contractor
18 minutes ago
Greater Brisbane Area, Australia Epsilon 3 Full time $100,000 - $150,000 per yearGRC and Cyber Specialist Contract Brisbane CBD location with hybrid after onboarding and familiarisation period 6 months contract working on the completion and delivery of outstanding documentation and accreditation artefacts, compliance activities, and corrective actions remediation, relevant evidence completionKey responsibilities include:Compliance...
-
Cyber Security Analyst
9 hours ago
Sydney, Australia Security Centric Full time**Role**: Cyber Security Analyst **Location**: Sydney + Hybrid **Division**: Multiple Opportunities **About The Role** **Your Responsibilities**: - Develop software, integrate solutions and automate processes for internal and customer facing systems - Identify security threats to clients' operations - Develop processes, products, services and...
-
IT Security Grc Manager
1 week ago
Sydney, Australia MinterEllison Full time**Location**: Sydney, Brisbane, Melbourne **Contract Type**: Permanent MinterEllison is one of Australia’s largest law firms, with nearly 200 years of business history. We're known for our legal and consulting expertise - and for our inclusive and authentic character. Our purpose is to create sustainable value with our clients, people and communities....
-
Lead Cyber Security Consultant
6 days ago
Sydney, New South Wales, Australia Skylight Cyber Security Full timeAbout Skylight CyberAt Skylight Cyber, we're young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are...