25 Aug
|
The Decipher Bureau
|
Sydney
25 Aug
The Decipher Bureau
Sydney
Build the security, risk and compliance function for a high-growth technology scale-up.
We're working with a rapidly growing technology business.
As the business scales across Australia and internationally, they're looking for an experienced GRC / Information Security specialist to take ownership of the information security and GRC function.
This isn't a role focused solely on maintaining a compliance register. You'll have the opportunity to build and mature the security and GRC framework, working closely with senior stakeholders, technology teams and external partners.
You'll own key certifications and frameworks including ISO 27001, ISO 27701, SOC 2, NIST, Essential Eight and PSPF, translating these requirements into practical security controls and processes.
The Role
- Own and mature the GRC program, with a focus on ISO 27001 and SOC 2.
- Lead internal and external security audits and certification programs.
- Develop and maintain group-wide frameworks covering Information Security, Privacy, Governance and ESG.
- Own the annual policy review cycle and develop new policies, standards and guidelines.
- Lead GRC working groups and committees.
- Act as the key contact for auditors, certification bodies, penetration testing providers and technology evaluations.
- Monitor compliance across security platforms and controls, identifying gaps and driving remediation.
- Develop security guidance and communications to improve security awareness.
- Provide practical advice on information and cyber security risk.
What We're Looking For
We're looking for someone who combines strong GRC fundamentals with enough technical understanding to engage credibly with security and technology teams.
You'll ideally bring:
- Senior experience in Information Security, GRC, Risk or Compliance, preferably within a technology-led organisation.
- Robust hands-on experience with ISO 27001 and SOC 2; ISO 27701 and/or ISO 22301 advantageous.
- Experience leading certification and audit programs.
- Understanding of information and cyber security, including SIEM, EDR/XDR, vulnerability management and security operations.
- Ability to translate security and compliance requirements into practical controls and business outcomes.
- Experience managing vendors, auditors and security partners.
Desirable
- Experience with international compliance frameworks or multinational technology businesses.
- Exposure to AI technologies and modern AI-driven environments.
- Experience with Australian Government or Defence security requirements.
- Existing Baseline clearance, or the ability to obtain NV1.
Why This Role?
This is an opportunity to join a business at a genuinely interesting stage of growth.
If you're a GRC professional who enjoys building rather than maintaining, influencing rather than simply auditing, and wants to work in a technology environment where security is genuinely important to the business, this is worth a conversation.
Please reach out to: *****@decipherbureau.com
📌 Technical GRC Lead (Sydney)
🏢 The Decipher Bureau
📍 Sydney