09 Sep
|
Robert Half
|
Melbourne
09 Sep
Robert Half
Melbourne
Company Robert Half is proud to be partnering with a global technology and business services organisation operating in a complex, highly regulated and technology-intensive environment.
With a significant technology footprint and a strong focus on security, risk, compliance and operational resilience, the organisation has established a sophisticated governance, risk and control environment.
This is an opportunity to join a business where technology risk and assurance are genuinely important to the organisation, with exposure across internal audit, cybersecurity, risk, compliance and broader GRC activities.
The role also offers excellent scope for professional development, with the prospect to broaden your experience across the GRC function and potentially progress into other areas of the business.
The Role Reporting into a highly impressive CISO, this role will provide independent, risk-based internal audit and assurance across the organisation's governance, risk and control environment.
The successful candidate will assess whether risks are appropriately identified and managed, whether controls are suitably designed and operating effectively, and whether regulatory and contractual obligations are being met.
While internal audit and technology assurance will be the core focus, this is a GRC role which is deliberately broad in nature, and would suit a generalist.
The appointed candidate will have the opportunity to provide additional support across risk, compliance, security assurance, ISMS, third-party assurance and governance reporting.
Key responsibilities will include: Develop and execute risk-based internal audit plans.
Conduct technology, IT and control audits from scoping through to reporting and remediation.
Gather, validate and assess audit evidence.
Conduct stakeholder interviews and risk/control workshops.
Identify control deficiencies, findings and root causes and assess associated risk.
Develop practical recommendations and produce transparent audit reports for management and governance committees.
Track remediation activities and independently validate the closure of findings.
Support follow-up audits and continuous improvement initiatives.
Work closely with external auditors, coordinating meetings, workshops, evidence requests and audit activities through to completion.
Support external certification, regulatory and customer audits.
Assist with risk assessments, risk register maintenance and risk treatment activities.
Undertake control and compliance assessments, including regulatory and contractual obligations.
Support ISO ***** / ISO ***** activities and ISMS evidence management.
Provide third-party/vendor assurance.
Contribute to governance and Risk Committee reporting, dashboards and management papers.
Assist with control mapping, security and compliance questionnaires and audit preparation.
A key part of the role will be maintaining an evidence-driven approach to assurance understanding not simply that a control exists, but whether there is sufficient evidence that it is appropriately designed, implemented and operating effectively.
Your Profile The client is looking for a Technology Assurance / Internal Audit professional with relevant experience across IT audit, cybersecurity, technology risk, assurance or GRC.
You will ideally have: Demonstrated experience conducting end-to-end internal or technology audits.
Strong understanding of information security controls and technology environments.
Some practical experience with ISO ***** / ISO *****.
Experience developing audit scopes,
test procedures and evidence requirements.
Strong risk and control assessment capabilities.
Experience identifying findings, assessing risk and tracking remediation through to closure.
The confidence to challenge management constructively and operate with professional independence.
Exceptional written and verbal communication skills and comfort in stakeholder engagement.
Experience working with external auditors and managing evidence requests and audit activities.
Broader exposure to GRC, risk, compliance or security assurance.
In addition, some technical exposure to areas such as cybersecurity, vulnerability and patch management, security monitoring, incident response, network and endpoint security, cloud, SaaS, infrastructure, applications, APIs, databases, SDLC and change management would be highly valuable.
Experience in critical infrastructure, transport, government, highly regulated industries or technology-intensive organisations would be particularly attractive.
Backgrounds in financial services, utilities, telecommunications, defence, health, energy or large technology organisations would also transfer well.
Most importantly, you will be someone who can operate independently, communicate effectively with senior stakeholders and bring a pragmatic, commercially minded approach to assurance.
This is an excellent opportunity for an IT Audit / Technology Assurance professional looking to broaden their career into a genuinely multidisciplinary GRC environment, with significant scope to grow and develop into other roles within the organisation.
Reference number: *****- - PM Please send your resume by clicking on the apply button.
Your application will be assessed within 3-5 working days.
Please note only shortlisted candidates will be contacted.
Learn more about our recruitment services: PLEASE NOTE THAT ONLY APPLICANTS WITH FULL WORKING RIGHTS IN AUSTRALIA WILL BE CONSIDERED
📌 It Assurance & Grc Specialist (Melbourne)
🏢 Robert Half
📍 Melbourne