Cyber Governance, Risk, and Compliance

20 hours ago


Sydney, New South Wales, Australia AI Talent Full time $70,000 - $120,000 per year

About the Role

We are seeking an experienced Cyber Governance, Risk, and Compliance (GRC) Specialist to lead the implementation and continuous improvement of our organisation's cybersecurity governance framework. This position is pivotal in ensuring that our systems, data, and infrastructure adhere to internal policies and external regulatory obligations, while proactively managing cyber risk and compliance across the enterprise.

You will work closely with executive leadership, IT teams, and external stakeholders to develop strategies, monitor controls, and report on risk posture, audit outcomes, and compliance metrics.

Key Responsibilities

  • Lead the design, implementation, and management of cybersecurity governance frameworks, including policies, standards, and procedures aligned to ISO 27001, NIST, Essential Eight, and other relevant standards.
  • Perform risk assessments and control evaluations to identify cybersecurity risks across infrastructure, applications, and third-party vendors.
  • Develop and maintain the organisation's information security risk register and assist in the treatment planning and mitigation strategies.
  • Coordinate internal and external audits related to cybersecurity and manage compliance reporting (e.g., SOC 2, ISO 27001, CPS 234, GDPR).
  • Provide expert advice to business and IT leaders regarding security requirements, regulatory changes, and risk implications of new projects or technologies.
  • Monitor compliance with security policies, identify gaps, and drive remediation in collaboration with system and security teams.
  • Develop metrics and reporting dashboards for executive oversight of cyber risk, control effectiveness, and incident trends.
  • Lead training and awareness initiatives to embed a culture of security and compliance across all departments.
  • Liaise with external auditors, regulators, and compliance authorities where required.

Required Skills & Experience

  • Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or related field.
  • Minimum 5 years of experience in a cybersecurity GRC or Information Security Compliance role.
  • Strong understanding of risk management frameworks (e.g., ISO 27005, NIST RMF, FAIR), and regulatory standards (e.g., CPS 234, GDPR, PCI-DSS, SOX).
  • Demonstrated experience leading internal/external security audits and vendor risk assessments.
  • Excellent communication and stakeholder engagement skills, including report writing and executive briefings.
  • Familiarity with GRC platforms and SIEM tools (e.g., Archer, ServiceNow GRC, Splunk, Microsoft Defender).
  • Relevant certifications preferred: CISM, CISSP, CRISC, ISO 27001 Lead Auditor, or equivalent.

Why Join Us?

  • Work with a dedicated team driving cyber resilience across the organisation.
  • High-visibility role influencing security posture and risk culture at the executive level.
  • Career development and upskilling opportunities in a supportive environment.
  • Flexible working arrangements with a hybrid or remote-friendly structure.

Job Types: Full-time, Permanent

Pay: $70,000.00 – $120,000.00 per year

Benefits:

  • Work from home

Work Authorisation:

  • Australia (Required)

Work Location: Hybrid remote in Sydney NSW 2000



  • Sydney, New South Wales, Australia Macquarie University Full time

    Cyber Security Governance, Risk and Compliance Manager Join to apply for the Cyber Security Governance, Risk and Compliance Manager role at Macquarie University About the Role Macquarie University is seeking a dynamic and experienced Cyber Security Governance, Risk and Compliance (GRC) Manager to lead the development and implementation of our cyber...


  • Sydney, New South Wales, Australia Stockland Full time $120,000 - $180,000 per year

    Company description: At Stockland we are a community delivering outcomes that benefit the community at large. We work collaboratively and inclusively, building strong working relationships. Our portfolio is diverse and so are the opportunities for professional and career development. We are committed to providing our people with broad experiences to build a...


  • Sydney, New South Wales, Australia Fujitsu Full time

    About the job Expression of Interest_ Governance, Risk and Compliance (GRC) We Are Fujitsu We use technology to make happier lives.We are a global leader in technology and business solutions that transform organizations and the world around us.We have a long heritage of bringing innovation and expertise, continuously working to contribute to the growth of...


  • Sydney, New South Wales, Australia Fujitsu Full time $120,000 - $150,000 per year

    About the job Expression of Interest_ Governance, Risk and Compliance (GRC)We Are FujitsuWe use technology to make happier lives. We are a global leader in technology and business solutions that transform organizations and the world around us. We have a long heritage of bringing innovation and expertise, continuously working to contribute to the growth of...

  • Cyber Security Risk

    5 days ago


    Sydney, New South Wales, Australia Interactive Pty Ltd Full time $90,000 - $120,000 per year

    At Interactive, we're not just another tech company – we've been recognised multiple times as one of Australia's Best Places to Work because we put our people first while solving big challenges for our clients.We're looking for a Cyber & GRC Consultant to join our growing Cyber team. This role is designed for someone early in their career (1–3 years'...


  • Sydney, New South Wales, Australia Skylight Cyber Security Full time $120,000 - $180,000 per year

    About Skylight CyberAt Skylight Cyber, we're young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are...


  • Sydney, New South Wales, Australia KPMG Australia Full time $120,000 - $180,000 per year

    Job DescriptionAbout the TeamAt KPMG Australia, our Consulting Technology Risk and Cyber team is at the forefront of enabling organisations to navigate the complex world of technology, cyber threats, and information security. We deliver impactful and innovative solutions tailored to our clients' needs, helping them identify and manage technology risks,...

  • Cyber Risk Analyst

    4 weeks ago


    Sydney, New South Wales, Australia NSW Government Full time

    OverviewCyber Risk Analyst, ongoing opportunity based in Sydney plus flexible/hybrid working options available. The Department of Customer Service is looking for a Cyber Risk Analyst to join our growing teamBenefitsFantastic ongoing clerk grade 7/8 opportunity.Salary range: $113,574 - $125,720 plus superannuation, commensurate with experience.Genuinely...

  • Cyber Risk Analyst

    4 weeks ago


    Sydney, New South Wales, Australia NSW Government Full time

    OverviewCyber Risk Analyst, ongoing opportunity based in Sydney plus flexible/hybrid working options available. The Department of Customer Service is looking for a Cyber Risk Analyst to join our growing teamBenefitsFantastic ongoing clerk grade 7/8 opportunity.Salary range: $113,574 - $125,720 plus superannuation, commensurate with experience.Genuinely...

  • Cyber Risk Analyst

    7 days ago


    Sydney, New South Wales, Australia NSW Government Full time $113,574 - $125,720 per year

    Cyber Risk Analyst, Ongoing opportunity based in Sydney plus flexible/hybrid working options availableThe Department of Customer Service is looking for a Cyber Risk Analyst to join our growing teamBenefitsFantastic ongoing clerk grade 7/8 Opportunity.Salary range: $113,574 - $125,720 plus superannuation, commensurate with experience.Genuinely flexible...