This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Senior Security Governance, Risk and Compliance Analyst - Are you a seasoned GRC professional looking to drive meaningful cultural change and technical excellence? We are seeking a Senior Security Governance, Risk and Compliance Analyst to join a high-performing team dedicated to safeguarding the future through smarter solutions. In this role, you will influence the strategic security roadmap, lead third-party risk management efforts, and play a pivotal part in transforming the organisation’s approach to risk-based decision-making. If you thrive in fast-paced environments and enjoy building strong relationships across a business to promote a robust security culture, this is the perfect opportunity to elevate your career.
Job Responsibility:
Lead Framework Development: Enhance and maintain the Security Controls Testing Framework and the Information Security Management System (ISMS) to ensure robust organisational protection
Manage Third-Party Risk: Define and lead overall vendor due-diligence and third-party risk management efforts to secure the broader supply chain
Support Regulatory Compliance: Assist in meeting APRA prudential standards and guidelines, contributing to the development of a robust risk management framework and responding to audits
Assess and Monitor: Perform comprehensive security and compliance assessments on new and existing systems, processes, and technologies throughout their lifecycle
Collaborate and Report: Interface across the business to provide guidance, track Key Risk Indicators (KRIs), and create insightful reports for management regarding governance and risk topics
General Cyber Security Activities: Stay informed on changing IT trends while providing general information security guidance and support to Technology and business units
Requirements:
At least 5 years of experience as a GRC Analyst, or a minimum of 2 years operating at a Senior GRC level
A strong understanding of fundamental information security concepts, cloud computing, and competency in Windows and Linux operating systems
Demonstrated experience with security controls testing frameworks and a deep understanding of regulatory requirements
Excellent written and oral communication skills, with the ability to negotiate, resolve conflict, and act as a security ambassador across the business
A Bachelor’s degree in a related field or equivalent significant work experience in information security and risk practices