- Port Melbourne Location
- High-profile digital transformation program
An exciting opportunity for an IT GRC Analyst to join a high-profile digital transformation program within a complex and highly regulated environment.
Working closely with senior stakeholders and cross-functional teams, you will identify control objectives, document process walkthroughs, identify and document expected and existing controls, develop test procedures, and validate the closure of risk treatment plans for high‑priority risks.
Key Skills & Responsibilities
- Demonstrated experience across IT risk, controls, governance, audit or GRC, with strong knowledge of Information Technology General Controls (ITGCs), application controls and control testing.
- Hands-on experience developing Risk and Control Matrices (RACMs), defining control objectives and assessing control design and operating effectiveness.
- Proven ability to develop and perform IT control testing, identify control gaps, recommend improvements and validate remediation activities and supporting evidence.
- Strong experience documenting processes, controls, policies and procedures and producing audit-quality GRC reports and risk documentation.
- Excellent stakeholder engagement skills, with the ability to work effectively with IT, security, technical and senior business stakeholders.
- Experience working in regulated or complex environments such as Defence, Aerospace, Manufacturing, Financial Services or Utilities is highly desirable.
- Relevant qualifications or certifications such as CISA, CRISC, CISM or ISO 27001 will be highly regarded.
- Knowledge of NIST, COBIT, ISO 27001 or ISO 31000 is advantageous.
To submit your interest for this role, click on the Apply button quoting reference #6012.
As we receive a high volume of applications, we appreciate your understanding that we are unable to respond to individual enquiries. We kindly ask that you do not contact us directly regarding application status.
Thank you for taking the time to apply we truly appreciate your interest.
Employer questions
Your application will include the following questions:
- Which of the following statements best describes your right to work in Australia?
- How many years' experience do you have as a Governance Risk and Compliance Analyst?
- Which of the following cybersecurity certifications have you completed?
An opportunity has become available for an experienced IT Security & Compliance Analyst to join a well-established professional services organisation in Sydney.
This is a hands-on role suited to someone with a strong understanding of cyber security, compliance, risk and governance, who enjoys working across both technical and non-technical areas.
The Role
You’ll work closely with the broader technology team to support and improve the organisation’s security and compliance environment across multiple offices.
Key areas of responsibility include:
- Supporting the development and ongoing improvement of information security services;
- Maintaining cyber security policies, procedures and controls;
- Monitoring and responding to security incidents and alerts;
- Supporting Business Continuity and Disaster Recovery planning and testing;
- Conducting security risk and compliance assessments;
- Identifying gaps against regulatory and security requirements;
- Supporting security audits and third-party assessments;
- Preparing security KPI/KRI reporting for management;
- Supporting cyber security awareness, training and education;
- Providing security input across applications, infrastructure and technology processes;
- Supporting access management, patching and security configuration; and
- Monitoring security trends and helping improve the organisation's security posture.
About You
We're looking for someone with 3+ years' experience in cyber security, information security or a similar role, ideally within professional services or another highly regulated environment.
You'll bring experience across:
- Security frameworks and standards such as ISO 27001 and NIST CSF;
- Microsoft Entra ID / Azure AD;
- MFA and identity/access management;
- Microsoft Intune or similar;
- Security risk, compliance and audit activities;
- Cyber security policies, procedures and reporting;
- Security awareness and training; and
- Strong stakeholder management and communication skills.
Experience working within a law firm or professional services environment would be highly regarded.
What’s on offer?
- Sydney-based permanent opportunity;
- Join a collaborative and established professional services environment;
- Broad exposure across security, risk, compliance and governance;
- Opportunity to contribute to ongoing security improvements;
- Strong focus on learning and development; and
- Additional annual leave and wellbeing benefit.