18 Sep
|
Decipher Bureau
|
New South Wales
18 Sep
Decipher Bureau
New South Wales
Job Description
n
Build the security, risk and compliance function for a high-growth technology scale-up.
n
We're working with a rapidly growing technology business.
n
As the business scales across Australia and internationally, they're looking for an experienced GRC / Information Security specialist to take ownership of the information security and GRC function.
n
This isn't a role focused solely on maintaining a compliance register. You'll have the opportunity to build and mature the security and GRC framework, working closely with senior stakeholders, technology teams and external partners.
n
You'll own key certifications and frameworks including ISO 27001, ISO 27701, SOC 2, NIST, Essential Eight and PSPF, translating these requirements into practical security controls and processes.
The Role n
n
- Own and mature the GRC program, with a focus on ISO 27001 and SOC 2.
n
- Lead internal and external security audits and certification programs.
n
- Develop and maintain group-wide frameworks covering Information Security, Privacy, Governance and ESG.
n
- Own the annual policy review cycle and develop new policies, standards and guidelines.
n
- Lead GRC working groups and committees.
n
- Act as the key contact for auditors, certification bodies, penetration testing providers and technology evaluations.
n
- Monitor compliance across security platforms and controls, identifying gaps and driving remediation.
n
- Develop security guidance and communications to improve security awareness.
n
- Provide practical advice on information and cyber security risk.
n
What We're Looking For n
We're looking for someone who combines strong GRC fundamentals with enough technical understanding to engage credibly with security and technology teams.
You'll ideally bring: n
n
- Senior experience in Information Security, GRC, Risk or Compliance, preferably within a technology-led organisation.
n
- Strong hands-on experience with ISO 27001 and SOC 2; ISO 27701 and/or ISO 22301 advantageous.
n
- Experience leading certification and audit programs.
n
- Understanding of information and cyber security, including SIEM, EDR/XDR, vulnerability management and security operations.
n
- Ability to translate security and compliance requirements into practical controls and business outcomes.
n
- Experience managing vendors, auditors and security partners.
n
- Experience with international compliance frameworks or multinational technology businesses.
n
- Exposure to AI technologies and modern AI-driven environments.
n
- Experience with Australian Government or Defence security requirements.
n
- Existing Baseline clearance, or the ability to obtain NV1.
n
Why This Role? n
This is an opportunity to join a business at a genuinely interesting stage of growth.
n
If you're a GRC skilled who enjoys building rather than maintaining, influencing rather than simply auditing, and wants to work in a technology environment where security is genuinely important to the business, this is worth a conversation.
n
#J-18808-Ljbffr
📌 Technical GRC Lead (New South Wales)
🏢 Decipher Bureau
📍 New South Wales