Governance & Risk Compliance Analyst

3 days ago


Melbourne, Victoria, Australia Mcmillan Shakespeare Full time

The McMillan Shakespeare Group (MMS) is a trusted provider of salary packaging, novated leasing, disability plan management and support co-ordination, asset management and related financial products and services. From our origins in 1988 when we created Australia's salary packaging industry to today, MMS has a proud history of innovation and exceptional service.

Through our subsidiaries, we offer a breadth of services and expertise designed to responsibly deliver superior long-term value to our clients and customers, which include Federal and State governments and some of the largest public and private sector, health and charitable organisations.

At the heart of achieving this mission is our team. Driven by a passion for the work we do, we work together with our customers to make a real difference to people's lives.

MMSG has several compliance obligations imposed by the regulatory and contractual environment in which we operate. The Governance Risk and Compliance Analyst role is tasked with coordinating and performing MMS security assessment and control testing reporting, analysing and monitoring strict compliance of internal IT controls, regulatory and information security policies and procedures. This role works with internal and external audit firms to provide supportive documentation as applicable.

The role can be done from Adelaide, Brisbane, Melbourne or Sydney.

A key component of the role is monitoring compliance of IT security controls (ISO27001, ASD (Essential Eight), NIST), conducting risk assessments, supporting security education and awareness programs, ensuring staff and 3rd parties are abreast of due diligence and compliance requirements, writing business communications about new security threats and working with IT functional teams and business stakeholders to ensure baseline security requirements are met and assets remain protected within these functional areas.

The Governance Risk and Compliance Analyst is also responsible in ensuring the security of all protected information collected, used, maintained, or released by MMS.

The Role:

- Implement security controls, maintaining and reporting risk assessment frameworks, ensuring documented and ongoing compliance that aligns and advances MMS business objectives
- Evaluate risks and develop security procedures, and controls to manage risks, improving MMS's security positioning through process improvement, policy, automation, and the continuous evolution of capabilities
- Conduct regular risk assessments and workshops to ensure risks to MMS are assessed and understood, and are fed back to stakeholders to ensure the continued effectiveness of the risk management strategy
- Provide support and relevant guidance to external auditors and ensure relevant artefacts are timely provided
- Evaluate cyber-security standards including NIST, ASD (Essential Eight), ISO27001 and PCI DSS for alignment with internal frameworks
- Implement processes, such as GRC (governance, risk and compliance), to automate and continuously monitor information security controls, exceptions, risks, testing
- Ensure internal security standards, policy, audit, and contracted security requirements are communicated across the business and with 3rd Parties
- Develop reporting metrics, dashboards, and evidence artefacts
- Define and document business process responsibilities and ownership of the controls
- Schedule regular assessments and testing of effectiveness and efficiency of controls and creates GRC reports
- Document and report control failures and gaps to stakeholders, providing remediation guidance and prepare management reports to track remediation activities
- Assists other Cyber Security team members in the management and oversight of security program functions
- Contribute to improve risk posture, contribute solutions for remediating or mitigating risks and assess residual risks
- Train, guide, and act as a resource on security assessment functions to other departments
- Any other security risk and compliance initiatives, as requested.

You will bring:

- Experience in IT Security and Risk Management such as ISO 31000.
- Experience with legal and regulatory obligations such as the Australian Privacy Principles.
- Experience with ISO27001, ASD Essential Eight, NIST PCI DSS
- Tertiary qualification in a Computing/IT discipline is preferable.
- CRISC Certification

What we can offer you:
- Our strong people-first culture- Flexible/hybrid working to enhance your work/life balance- Novated lease benefits and discounts- 12 weeks Paid Parental leave and access to our Parents Portal- Exempt Employee Share Plan- Paid Income Protection Insurance under MMSG default Super plan- Access to a broad range of learning and development programs- Career break and volunteering leave- Access to Employee Assistance Program and annual Flu vaccination- Lifestyle Rewards program

As an employer who embraces Diversity, Equity & Inclusion, we hold a collective commitment to foster an en



  • Melbourne, Victoria, Australia Staffx Pty Ltd Full time

    **About the Company**This IT Services and IT Consulting company is an Australian company that has core competencies in banking and financial services. They work with leading and local companies across the APAC region.Their highly skilled, talented IT specialists are experts in their fields, and employees are placed in key value-adding roles with our...


  • Melbourne, Victoria, Australia Nixil Full time

    You will work with a range of stakeholders across the business providing information security compliance and risk management support and guidance.Additionally, you will manage cyber security policies and standards, ensure they are periodically updated and aligned them with the overall Banking Information Security Policy framework.Reporting to the Manager,...


  • Melbourne, Victoria, Australia Ryman Healthcare Full time

    Join to apply for the Risk and Compliance Analyst role at Ryman HealthcareJoin to apply for the Risk and Compliance Analyst role at Ryman HealthcareAre you a curious Risk and Compliance Analyst who enjoys collaborating with a diverse range of stakeholders and has a keen eye for insightful and meaningful risk reporting?Unlock your full potential in a...


  • Melbourne, Victoria, Australia Ryman Healthcare Full time

    Join to apply for the Risk and Compliance Analyst role at Ryman HealthcareJoin to apply for the Risk and Compliance Analyst role at Ryman HealthcareAre you a curious Risk and Compliance Analyst who enjoys collaborating with a diverse range of stakeholders and has a keen eye for insightful and meaningful risk reporting?Unlock your full potential in a...


  • Melbourne, Victoria, Australia Amp Full time

    Adviser Education AnalystIf you live in Australia or New Zealand, you've likely heard of AMP. But at a time when society is changing, we are too. We're now a nimbler business with new leadership and thinking.For us, these are exciting times. There's a real potential for big thinkers to help us redefine what financial services could be. And turn our legacy...


  • Melbourne, Victoria, Australia Robert Walters Australia Full time

    Overview Our client is seeking a Risk and Compliance Analyst to join their team.In this role, you will be instrumental in supporting the design and implementation of key initiatives, including the uplift of the Governance, Risk, and Compliance (GRC) system, enhancements to the Operational Due Diligence process, and ensuring compliance.This position offers an...


  • Melbourne, Victoria, Australia ROBERT WALTERS AUSTRALIA Full time

    OverviewOur client is seeking a Risk and Compliance Analyst to join their team. In this role, you will be instrumental in supporting the design and implementation of key initiatives, including the uplift of the Governance, Risk, and Compliance (GRC) system, enhancements to the Operational Due Diligence process, and ensuring compliance. This position offers...


  • Melbourne, Victoria, Australia ROBERT WALTERS AUSTRALIA Full time

    OverviewOur client is seeking a Risk and Compliance Analyst to join their team. In this role, you will be instrumental in supporting the design and implementation of key initiatives, including the uplift of the Governance, Risk, and Compliance (GRC) system, enhancements to the Operational Due Diligence process, and ensuring compliance. This position offers...


  • Melbourne, Victoria, Australia ROBERT WALTERS AUSTRALIA Full time

    OverviewOur client is seeking a Risk and Compliance Analyst to join their team. In this role, you will be instrumental in supporting the design and implementation of key initiatives, including the uplift of the Governance, Risk, and Compliance (GRC) system, enhancements to the Operational Due Diligence process, and ensuring compliance. This position offers...


  • Melbourne, Victoria, Australia Robert Walters Australia Full time

    OverviewOur client is seeking a Risk and Compliance Analyst to join their team. In this role, you will be instrumental in supporting the design and implementation of key initiatives, including the uplift of the Governance, Risk, and Compliance (GRC) system, enhancements to the Operational Due Diligence process, and ensuring compliance. This position offers...