05 Aug
|
Amazon Web Services (AWS)
|
City of Sydney
05 Aug
Amazon Web Services (AWS)
City of Sydney
G'day! You're looking at a role that could define your next chapter as a Governance, Risk, and Compliance (GRC) Specialist within AWS Security. Applicants must be Australian citizens and hold or be eligible to obtain an Australian Government Security Clearance and successfully complete an Organisational Suitability Assessment. More information about security clearances can be found at
As a GRC Specialist you will own assurance and authorisation activities for the cloud capability, translating regulatory intent into engineering reality. You’ll collaborate with internal teams and customers to establish security baselines, define control objectives and shape the security posture of a capability that will serve Australia for decades. Your work will start at the design table, involve cross‑functional working groups, and include creating thought‑leadership material on cloud and emerging technologies.
Key job responsibilities
You will be the GRC engine for designated physical and logical components within the cloud capability — owning assurance and authorisation activities end‑to‑end and ensuring every element adheres to the standards and protocols that underpin national trust.
Your work begins at the design table. You’ll collaborate with internal teams and customers to establish security baselines, level‑set requirements, and define the control objectives that shape how the capability is built. When ISM, PSPF, DSPF, ASIO T4, or NIST frameworks need to be woven into architecture, you’ll translate regulatory intent into engineering reality.
You’ll create, optimise, and champion cross‑functional working groups that drive security efficiency across the organisation, acting as a catalyst that keeps them focused and effective.
You’ll also serve as a mentor and advisor to teams across AWS, sharing expertise and elevating the security capability of the broader organisation.
Deadlines will be tight and the stakes high.
You’ll deliver with exceptional attention to detail, ensuring accuracy across every aspect of security management while maintaining programme momentum.
A day in the life
Your morning kicks off with a cross‑functional stand‑up where you brief the team on an upcoming authorisation milestone. You map evidence requirements, identify gaps, and assign actions.
Mid‑morning you work with an engineering team, translating ASIO T4 and ISM controls into practical design decisions for a component build.
Before lunch you review a draft security baseline document with a customer stakeholder, focusing on cooperative, trust‑based communication.
The afternoon is dedicated to deep work: developing a thought‑leadership piece on an emerging cloud security challenge.
Late in the day you mentor a colleague from another AWS team, paying forward guidance that accelerated your own growth.
Benefits
- Learning & development – AWS training and certification support, access to internal learning platforms.
- Health, income protection and life cover – Amazon subsidises private health insurance premiums; group salary continuance and life insurance are included at no cost to you.
- Military differential pay launching in Australia – employees taking defence reserve leave may receive up to 52 weeks of differential pay.
- Employee Assistance Program – free, confidential support 24 hours a day, 7 days a week for you and your family, including mental health, financial coaching, legal questions and everyday life events.
- Family‑building benefit – access to Maven for fertility treatment, adoption support, surrogacy and parenting coaching.
- Amazon Extras & employee discount – cashback and discounts across hundreds of retail, fitness, travel and lifestyle partners.
Basic Qualifications
- 4+ years of experience working in areas related to security assurance, such as cybersecurity, auditing, security architecture, regulatory affairs or public sector agencies involved in cybersecurity management.
- Experience working with governance, risk and compliance programmes that directly involve interaction with regulatory bodies.
- Proficient with government security frameworks, policies and standards (e.g. PSPF, ISM, DSPF, ASD Essential Eight).
- Experience working with cloud technologies.
Preferred Qualifications
- Degree or equivalent experience in Computer Science, Engineering, Cyber Security, IT Security Management, Security Risk Management or a related security field.
- Minimum 4 years of experience implementing and operationalising security to meet business outcomes.
- Proven ability to influence and lead business partners and supporting teams.
- Ability to credibly coordinate between technical teams and business stakeholders.
- Strong communication skills. Ability to produce detailed and complex written business cases without the use of PowerPoint.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. If you have a disability and need a workplace accommodation or adjustment, please visit for more information.
In the spirit of reconciliation Amazon acknowledges the Traditional Custodians of country throughout Australia and pays respect to their elders past and present and to all Aboriginal and Torres Strait Islander peoples today.
Company: Amazon Web Services Australia Pty Ltd – Job ID: A
#J-18808-Ljbffr
📌 Governance, Risk, and Compliance Specialist, AWS Security (City of Sydney)
🏢 Amazon Web Services (AWS)
📍 City of Sydney