Security Specialist Cyber Governance (Sydney)

Security Specialist Cyber Governance (Sydney)

27 Aug
|
Job4online
|
Sydney

27 Aug

Job4online

Sydney

Posting on behalf of Security Specialist Cyber Governance.

What You'll Do

- Develop, implement, maintain and continuously improve cyber security policies, procedures, standards and guidelines in line with regulatory requirements, industry standards and recognised security practices.
- Lead cyber security risk management activities, including identifying, assessing and prioritising risks, maintaining risk assessments, developing risk treatment and mitigation plans, and reporting security risks to relevant stakeholders.
- Lead the planning, preparation and execution of security certification and assurance activities, including SOC 2 and ISO 27001, coordinating audits, evidence collection, documentation, remediation and ongoing compliance.
- Conduct security audits, compliance assessments and control reviews to identify security gaps, evaluate control effectiveness and recommend improvements.
- Identify and assess security vulnerabilities and control weaknesses across systems, applications and infrastructure, evaluate their associated business risk and coordinate risk-based remediation with engineering and technology teams.
- Build and maintain Kinde's cyber security governance framework, including security policies, procedures, controls, risk management processes and supporting documentation.
- Develop and maintain appropriate information and system classification requirements to support the prioritisation and implementation of security controls and risk mitigation activities.
- Collaborate with engineering, technology, operations and other cross-functional teams to embed security and compliance requirements throughout systems, products and development processes.
- Monitor security risks, incidents and control deficiencies,



coordinate remediation activities and support security incident investigations and post-incident reporting where required.
- Provide practical cybersecurity guidance to employees and stakeholders and develop security awareness and training initiatives covering security policies, best practices and incident response.
- Conduct compliance assessments and support alignment with applicable cybersecurity, privacy, data protection and regulatory requirements.
- Assess privacy risk associated with new and existing systems, products and data processing activities and recommend appropriate security and privacy controls.
- Prepare transparent security governance, risk, audit and compliance reports for management and relevant stakeholders, including findings, risk treatment activities and recommendations for continuous improvement.
- Assess cyber security and privacy risk associated with third-party providers and services and recommend appropriate risk treatment measures.

What You'll Bring

- Demonstrated professional experience in Cyber Security Governance, Risk and Compliance (GRC), including security risk assessments, risk treatment and mitigation, compliance assessments and security governance.
- Experience developing, implementing and maintaining cyber security policies, procedures, standards and controls aligned with regulatory requirements and recognised industry practices.




- Demonstrated experience supporting or leading security audits, assurance and certification activities, particularly ISO/IEC 27001 and SOC 2.
- Strong knowledge of cybersecurity and risk management frameworks, including ISO/IEC 27001 and the NIST Cybersecurity Framework, with the ability to translate framework requirements into practical organisational controls.
- Experience assessing security control effectiveness, identifying security and compliance gaps and coordinating appropriate remediation activities.
- Knowledge and practical experience in privacy, data protection and regulatory compliance, with the ability to translate legal and regulatory requirements into practical information security controls, policies and processes.
- Experience developing security governance documentation and providing practical cybersecurity guidance and awareness to technical and non-technical stakeholders.
- Strong stakeholder management and communication skills, with the ability to work collaboratively across engineering, technology, operations and business teams.

Qualifications

- Relevant tertiary qualifications in Cyber Security, Information Technology, Information Security, Risk Management, Data Protection, or a related discipline.

Desirable

- Experience within a SaaS, technology or cloud-based environment.
- Experience conducting privacy or data protection risk assessments.
- Relevant professional certification or training in ISO 27001, cybersecurity, risk, audit or privacy.

Why Join Kinde?

- Permanent full-time position.
- Competitive salary
- Flexible and remote working arrangements.
- Work closely with technology and engineering teams in a growing SaaS environment.
- Supportive and collaborative team culture.

📌 Security Specialist Cyber Governance (Sydney)
🏢 Job4online
📍 Sydney

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security specialist cyber governance (sydney) / sydney

Subscribe to this job alert:

Get the latest job offers by email for: security specialist cyber governance (sydney) / sydney