It Security Grc Manager

2 days ago


Sydney, New South Wales, Australia Minterellison Full time

**Location**: Sydney, Brisbane, Melbourne

**Contract Type**: Permanent

MinterEllison is one of Australia's largest law firms, with nearly 200 years of business history. We're known for our legal and consulting expertise - and for our inclusive and authentic character.

Our purpose is to create sustainable value with our clients, people and communities. That means we have a proud history of providing excellence to clients, nurturing our people and giving back to the communities in which we live and work.

We value excellence, curiosity and collaboration. Clients rely on us for our responsive, commercial approach. Our clients include government departments and agencies, private and publicly listed companies, and small and large businesses in Australia and overseas.

**The Role**

We are currently recruiting for an experienced IT Security GRC Manager to join our internal digital team based in either our Sydney, Melbourne or Brisbane office. In this role, you will be responsible for managing and maintaining the end to end IT security GRC portfolio under our IT security assurance practice. The IT security assurance practice covers: cyber risk management, compliance framework and certification program, client assurance and contract reviews, supply chain security, internal audit, and cyber awareness program.

Agile working arrangements are supported at the firm with a minimum or 3 days in the office required.

In this role you will have the opportunity to:

- Uplift and develop a high-performing IT security GRC practice across all IT security assurance areas, fostering a culture of excellence, collaboration, and continuous learning
- Implement a robust IT security compliance framework program integrating multiple compliance certification, frameworks, policies and standards
- Lead and maintain certifications across multiple standards/frameworks and internal audits
- Perform cyber hygiene audits to ensure compliance with external and internal policies, regulations, standards and compliance with client contracts
- Lead client assurance program including responding to client audits/questionnaires, reviewing client cybersecurity contracts, updating MinterEllison Trust Centre and maintaining a high client engagement & experience
- Collaborate with Chief Risk Office to manage and maintain cyber risk lifecycle including cyber risk registers and dashboards
- Lead supply chain cyber risk management program including annual reviews and spot checks
- Maintain cyber security awareness and training programs including role-based training across the Firm
- Provide high quality reporting and updates on cyber security to senior leadership including KPIs/KRIs
- Assist with IT security operations on any cybersecurity incidents during and, if required, after business hours
- Ensure efficient use of managed security services and/or external consultants in the GRC domain.
- People leadership responsibility for one direct report.

**More About You**
- 8 years+ demonstrated, direct, hands on experience in the above mentioned GRC areas, including 2-3 years hands on, direct experience in managing assurance programs
- Strong written and verbal communication skills to engage with all levels of business
- Pragmatic and collaborative with various stakeholders with the ability to bring people on a journey
- Demonstrated experience in writing high quality executive reports/briefings
- Expert knowledge of information security principles, standards and frameworks such as ISO27001. Familiarity with of NIST, SSAE16, APRA CPS234, ASD essential 8, VPDSF
- Knowledge of security policies, standards, and practices.
- Knowledge of the infrastructure, operations, and systems of information technology.
- Agile-mindset, incremental delivery over perfection, willingness to try new approaches to a problem
- Ability to manage projects and tasks independently with little supervision
- Relevant security trainings/certifications not mandatory but will be highly desirable
- Ability to use GenAI models and other pragmatic approaches to improve efficiencies/quality or delivery
- Be up-to-date with information security best practices and industry trends for security solutions and standards

**Why MinterEllison**

We offer flexible working options to encourage balance, wellbeing and support for sustainable ways of working and a range of social, financial and health benefits, including free gym membership - all with no minimum tenure.

**How to apply



  • Sydney, New South Wales, Australia Hastha Solutions Full time $90,000 - $120,000 per year

    Urgent requirement of SAP GRC Security Consultant - Contract - Sydney RequirementsDesign and Build Security Roles in SAP S/4HANA Troubleshoot access issues in SAP S/4HANA Security Roles (including Fiori) Configure SAP GRC Access Control 12.0 (ARA, BRM, EAM, ARM) and troubleshoot BRF , MSMP Issues Perform regular SOD Analysis for Roles, Users and...


  • Sydney, New South Wales, Australia Lumus Imaging Full time

    **Date**:23 Apr 2025**Location**: Sydney, New South Wales, AU, 2000**Company**:Healius**Job reference**: #15478**Brand**:Lumus Imaging**Location**: Sydney**Work type**: Full Time (Permanent)**About us**At Lumus Imaging, we are passionate about caring for your health and wellbeing at every stage of life.Lumus Imaging harnesses all of the knowledge and...


  • Sydney, New South Wales, Australia beBeeCybersecurity Full time $120,000 - $140,000

    Overview of the Role:Cyber security specialists are in high demand due to the increasing need for organizations to protect themselves from cyber threats. This role involves working at the intersection of cyber strategy, governance, risk, and technical execution.The primary objective of this position is to identify and address potential risks that could...

  • It Grc Analyst

    7 days ago


    Sydney, New South Wales, Australia Metcash Full time

    We have an excellent opportunity for an **IT GRC Analyst** (Governance, Risk & Compliance) on a 12mth Fixed Term Contract. The IT GRC Analyst has day-to-day responsibility for central coordination of the management of IT and cyber security risks, maintaining robust IT and security policies, standards, procedures, and guidelines, and ensuring compliance with...


  • Sydney, New South Wales, Australia Leidos Full time $90,000 - $120,000 per year

    Description We're a 'Family Friendly' certified workplace – we understand the often many and varied roles our team members need to play within their own unique family setting and actively support them. Our team feel Leidos is a great place to work. Learn more about our culture and benefits by visiting us here Do Work That Matters Leidos Australia...

  • Senior GRC Analyst

    3 days ago


    Sydney, New South Wales, Australia Oscar Zhao Full time

    Join a global insurance broker Your new company A global general insurance broker is seeking a permanent Senior GRC Analyst to join their Cybersecurity Team in Sydney. This role will involve owning the IT risk management process and cyber security governance processes. Your new role Reporting to the CISO, your new role will be varied and...

  • Security Analyst

    5 days ago


    Sydney, New South Wales, Australia Kinetic It Full time

    Security Analyst Apply now Job no: WWREQ0030592 Employment type: Full Time Location: Canberra, Sydney, Brisbane, Melbourne Categories: Cyber SecurityAbout Kinetic IT:We are recognised market leaders in the delivery of high-quality technology solutions to large public, private, and government organisations.As an Australian-owned company, we take a lot of...

  • Grc Lead

    6 days ago


    Sydney, New South Wales, Australia News Corp Australia Full time

    The Governance, Risk and Compliance (GRC) Lead will have a strong understanding of security and privacy principles as well as a sound understanding of regulatory and compliance requirements affecting the business. Support and maintain the Cyber GRC Program, including the development, implementation and maintenance of security policies, standards, guidelines...

  • Security Analyst

    1 week ago


    Sydney, New South Wales, Australia Kinetic IT Full time $90,000 - $120,000 per year

    About Kinetic IT:We are recognised market leaders in the delivery of high-quality technology solutions to large public, private, and government organisations. As an Australian-owned company, we take a lot of pride in delivering exceptional service that exceeds our customers' expectations and positively contributing to our industry and community. We hire for...


  • Sydney, New South Wales, Australia Naviro Full time

    OverviewItalian Speaking Cyber Security GRC Specialist – Naviro, Sydney, New South Wales, Australia.EngagementContract, up to 3 months.Base pay rangeA$120.00/hr - A$150.00/hrClient needThey have a contract requirement (up to 3 months) looking for an Italian speaking Cyber Security GRC Specialist. Client's need for Italy's Cloud Strategy Attestation: CSPs...