Role details
Six-month contract, GRC role across Sydney, Melbourne or Perth, one to two days in office each week.
You'll sit across a large enterprise technology environment, providing security governance, risk and compliance advice across active technology programmes. Day to day that means running risk assessments, reviewing controls, advising architecture and engineering teams, and producing governance reporting for senior leadership. You're the person who makes security workable, not a blocker.
The working arrangement is genuinely flexible. One or two days in the office per week, with your choice of Sydney, Melbourne or Perth as your base. The contract is six months with extensions on the table, so there's room to settle in and actually see the work through.
You'll be across a broad portfolio of technology initiatives, which keeps the work varied. One week you might be reviewing a vendor risk assessment, the next you're advising a delivery team on Secure by Design for a cloud migration. If you've got experience with Power BI for governance dashboards or you've worked in telecommunications, that's worth calling out. AI governance experience is also highly regarded here, as the organisation is starting to think seriously about responsible AI frameworks.
What You'll Do
- Lead GRC activities across enterprise technology programmes, including risk assessments and control assurance reviews for projects, systems and platforms.
- Develop and maintain security policies, standards and governance frameworks aligned to ISO 27001, NIST and equivalent.
- Produce risk and compliance reporting for senior leadership and governance forums, coordinating internal and external audits and remediation activities.
- Conduct third-party and vendor security risk assessments, advising architecture and engineering teams throughout the project lifecycle.
What You'll Need
- Solid GRC experience in enterprise environments, covering cyber security risk assessments, control assurance and security governance.
- Working knowledge of ISO 27001, NIST or equivalent frameworks, with experience applying Secure by Design methodologies in delivery contexts.
- Demonstrated ability to produce executive-level risk and compliance reporting and manage vendor or third-party security risk.
- Familiarity with tools such as Power BI, JIRA and Confluence is advantageous.
About the Company
They're a large enterprise operating in a complex technology environment, with programmes spanning cloud, digital transformation and infrastructure change. The security function is maturing and there's genuine appetite to improve governance capability, which means your input will carry real weight.
Apply
Please click the 'Apply' button. Don't worry if your CV isn't up to date - just send what you have.
