THE COMPANY
This company is an innovative and entrepreneurial mid-sized Financial Services-based organisation who employ approx. 2500+ staff across Australia.
Having seen rapid growth over the past 5 years, they are building out their internal cyber security GRC capabilities and require an additional headcount.
- Training, mentorship and a clear career path is available.
- Involvement in uplifting cyber governance, risk and compliance.
- Sydney CBD office location.
- Hybrid working available.
THE ROLE & RESPONSIBILITIES
Newly created Cyber Governance & Risk Analyst position focused on identity governance, data risk management, supplier assurance, ISO 27001 compliance, and cyber risk reporting.
It's a hands-on role involving policy writing, stakeholder engagement, security assessments, security training/awareness initiatives, and compliance reporting etc.
Operating in a close-knit team you'll have the opportunity to be developed and mentored by a fantastic manager.
Hybrid working available.
Key responsibilities:
Identity & Access Governance
- Support improvements to onboarding / offboarding processes.
- Coordinate User Access Reviews (UARs)
- Track remediation of access-related risks and control gaps.
Data Risk & Information Governance
- Coordinate data risk remediation activities arising from data governance and security reviews.
- Monitor progress of remediation actions and maintain action registers.
- Support reporting on data governance and information protection initiatives.
Supplier Risk Management
- Conduct supplier security assessments and due diligence reviews.
- Review security questionnaires, ISO certifications, penetration test reports and assurance documentation.
- Maintain supplier risk registers and track remediation activities.
ISO 27001 & Governance
- Support the ongoing maintenance of the ISO 27001-certified ISMS.
- Coordinate policy reviews, evidence collection, audits and compliance activities.
- Support preparation for ISO surveillance audits and management reviews.
Risk Reporting & Committees
- Support cyber risk assessments and risk register maintenance.
- Assist to prepare reports, KPI/KRI dashboards and committee packs, and contribute to board and executive cyber risk reporting.
- Involvement in ISMS Committee meetings, action tracking and follow-up activities.
Stakeholder Engagement
- Build strong relationships across Technology, Risk, HR, Procurement and business teams.
- Drive accountability for remediation actions and governance outcomes.
- Support cyber awareness and governance initiatives.
REQUIRED EXPERIENCE, KNOWLEDGE, PERSONAL QUALITIES
Suitable for either a Cyber Analyst with hand-on GRC experience OR an aspiring GRC professional looking to pivot into the cyber GRC space.
Ideal for someone who's keen to get hands-on, learn, absorb and proven themselves in a fast-paced and evolving environment.
The following is required:
- Cyber GRC exposure across identify & access governance, data governance, and supplier governance.
- A strong junior option with relevant experience in governance, compliance, audit, risk, project coordination, technology operations or similar functions can also be considered.
- Relevant Cyber Security credentials / degree.
- Demonstrate a keen interest in developing a career in Cyber Governance, Risk & Compliance.
- Personal qualities:
- Excellent attention to detail with strong report writing and organisational skills.
- Able to coordinate multiple initiatives and drive actions to completion.
- Strong stakeholder engagement and communication skills.
- Demonstrate a keen interest in developing a career in Cyber Governance, Risk & Compliance.
This is a full-time permanent role in the Sydney CBD (hybrid work) and is offering $100,000 - $120,000 (plus super) - depending on experience.
Australian Citizenship or Permanent Residency is required for this role, and successful applicants will be contacted.
Reference Number: 06800-0013479976
This is a hybrid position.
By clicking 'apply', you give your express consent that Robert Half may use your personal information to process your job application and to contact you from time to time for future employment opportunities. For further information on how Robert Half processes your personal information and how to access and correct your information, please read the Robert Half privacy notice: https://www.roberthalf.com/au/en/privacy. Please do not submit any sensitive personal data to us in your resume (such as government ID numbers, ethnicity, gender, religion, marital status or trade union membership) as we do not collect your sensitive personal data at this time.
