Some of your responsibilities include and are not limited to:
Cyber GRC Strategy & Operating Model
- Own and deliver the Cyber GRC roadmap, aligned to business priorities, risk appetite and regulatory requirements.
- Establish clear governance, accountability, reporting and measures of effectiveness.
- Lead and develop Cyber GRC capability, including internal and external stakeholders.
Risk, Controls & Policy Governance
- Own the information security risk management framework and register, including risk assessment, treatment, acceptance and reporting.
- Oversee the information security policy framework, ensuring policies, standards and procedures remain current and effective.
- Establish sustainable control ownership, testing and remediation practices.
Assurance, Audits & Certifications
- Lead ongoing readiness and compliance for ISO 27001 and SOC 2, including audit planning, evidence coordination, control testing and remediation.
- Develop readiness for additional obligations and certifications, including ISO 42001, CPS 230, CPS 234 and the ASD Essential Eight.
- Manage audit relationships, findings and customer/partner security assurance requests.
Third-Party Risk, Resilience & Incident Governance
- Own the cyber components of third-party risk management, including due diligence, reassessments and security requirements.
- Provide governance oversight across cyber incident readiness, business continuity, disaster recovery and operational resilience.
- Partner with Engineering, DevOps, IT and Security Engineering to translate risks and control gaps into practical remediation plans.
AI Governance & Business Enablement
- Lead responsible AI governance, including policy, risk, assurance and accountability.
- Establish proportionate governance and guardrails for approved AI use cases.
- Promote security and compliance as business enablers through clear, practical and streamlined requirements.
Our ideal candidate
- Proven experience leading or owning Cyber Security GRC programs within SaaS, technology, financial services or regulated environments.
- Strong experience with ISMS, ISO 27001 and/or SOC 2, including audit readiness, evidence management, findings and continuous improvement.
- Strong knowledge of cyber risk, controls, policy governance, third-party risk and customer assurance.
- Ability to translate regulatory, contractual and framework requirements into practical, business-owned controls.
- Strong understanding of incident management, business continuity, disaster recovery and operational resilience.
- Exposure to CPS 230, CPS 234 and the ASD Essential Eight is highly regarded; AI governance/ISO 42001 experience is desirable.
- Experience with GRC and workflow tools, such as Drata, Jira, Confluence or equivalent.
- Strong communication and stakeholder management skills, with the ability to challenge constructively and make complex risk easy to understand.
- Hands-on and commercially minded, comfortable balancing strategy, stakeholder leadership and day-to-day program execution.