28 Aug
|
Decipher Bureau
|
New South Wales
28 Aug
Decipher Bureau
New South Wales
Job Description
Build the security, risk and compliance function for a high-growth technology scale-up.
n
We're working with a rapidly growing technology business.
n
As the business scales across Australia and internationally, they're looking for an experienced GRC / Information Security specialist to take ownership of the information security and GRC function.
n
This isn't a role focused solely on maintaining a compliance register. You'll have the chance to build and mature the security and GRC framework, working closely with senior stakeholders, technology teams and external partners.
n
You'll own key certifications and frameworks including ISO *****, ISO *****, SOC 2, NIST, Essential Eight and PSPF, translating these requirements into practical security controls and processes.
n
The Role
n
n
Own and mature the GRC program, with a focus on ISO ***** and SOC 2.
n
Lead internal and external security audits and certification programs.
n
Develop and maintain group-wide frameworks covering Information Security, Privacy, Governance and ESG.
n
Own the annual policy review cycle and develop new policies, standards and guidelines.
n
Lead GRC working groups and committees.
n
Act as the key contact for auditors, certification bodies, penetration testing providers and technology evaluations.
n
Monitor compliance across security platforms and controls, identifying gaps and driving remediation.
n
Develop security guidance and communications to improve security awareness.
n
Provide practical advice on information and cyber security risk.
n
n
What We're Looking For
n
We're looking for someone who combines strong GRC fundamentals with enough technical understanding to engage credibly with security and technology teams.
n
You'll ideally bring:
n
n
Senior experience in Information Security, GRC, Risk or Compliance, preferably within a technology-led organisation.
n
Strong hands-on experience with ISO ***** and SOC 2; ISO ***** and/or ISO ***** advantageous.
n
Experience leading certification and audit programs.
n
Understanding of information and cyber security, including SIEM, EDR/XDR, vulnerability management and security operations.
n
Ability to translate security and compliance requirements into practical controls and business outcomes.
n
Experience managing vendors, auditors and security partners.
n
Experience with international compliance frameworks or multinational technology businesses.
n
Exposure to AI technologies and modern AI-driven environments.
n
Experience with Australian Government or Defence security requirements.
n
Existing Baseline clearance, or the ability to obtain NV1.
n
n
Why This Role?
n
This is an opportunity to join a business at a genuinely interesting stage of growth.
n
If you're a GRC professional who enjoys building rather than maintaining, influencing rather than simply auditing, and wants to work in a technology environment where security is genuinely important to the business, this is worth a conversation.
📌 Technical Grc Lead (New South Wales)
🏢 Decipher Bureau
📍 New South Wales