21 Sep
|
Client 1
|
Brisbane City
21 Sep
Client 1
Brisbane City
Role Title
Cyber GRC Analyst
Location
Brisbane, QLD
Working Arrangement
Full-time
Clearance Required
Baseline AGSVA clearance or above.
Company Overview
Our client is a growing national security and technology organisation delivering advanced cyber, digital, and mission-critical capabilities within highly regulated environments. Supporting government and defence-related outcomes, the organisation is focused on maintaining the highest standards of security, compliance, and operational excellence.
Job Description
We are seeking a motivated and detail-oriented Cyber Governance, Risk and Compliance (GRC) Analyst to support cybersecurity governance and assurance activities within a classified Microsoft Azure environment.
This role is responsible for maintaining the security compliance of critical systems and services through the development, review, and management of accreditation, risk, and governance documentation. Working closely with technical teams, security practitioners, project stakeholders, and governance bodies, you will help ensure information systems remain secure, compliant, and aligned with Australian Government cyber security requirements.
The successful candidate will contribute to security accreditation activities, risk management processes, compliance assessments, governance forums, and security assurance initiatives while providing trusted advice to internal stakeholders.
Duties and Responsibilities
- Develop, review, maintain, and update cybersecurity governance and accreditation documentation including System Security Plans (SSPs), Security Risk Management Plans (SRMPs), risk assessments, procedures, and Plans of Action and Milestones (POA&Ms;).
- Support system accreditation and re-accreditation activities within classified environments.
- Ensure ongoing compliance with the Information Security Manual (ISM), Protective Security Policy Framework (PSPF), Essential Eight, and internal security requirements.
- Conduct security compliance reviews, audits, and assurance assessments.
- Identify, assess, document, and manage cyber security risks and control gaps.
- Monitor remediation activities and ensure audit findings are effectively addressed.
- Provide cyber security advice to project teams, governance forums, and business stakeholders.
- Participate in investigations relating to cyber security incidents, compliance concerns, and security breaches.
- Prepare compliance reporting and risk status updates for senior stakeholders.
- Collaborate with technical teams to validate security controls and implementation effectiveness.
- Support the development and continuous improvement of cyber security policies, standards, procedures, and governance frameworks.
- Maintain compliance evidence repositories and accreditation artefacts.
- Deliver cyber security awareness and training activities to system users.
- Engage with internal and external stakeholders to support security and compliance objectives.
Education/Certifications Required
- Bachelor's degree in Cyber Security, Information Security, Information Technology, Computer Science, Risk Management, Governance, or a related discipline.
- Relevant industry experience may be considered in lieu of formal qualifications.
Highly desirable certifications include:
- CRISC
- CISA
- CGRC
- ISO 27001 Lead Auditor
- ITIL 4 Foundation
- Microsoft Certified: Azure Fundamentals (AZ-900)
- Microsoft Certified: Security Fundamentals (SC-900)
- Microsoft Certified: Information Protection and Compliance Administrator (SC-400)
- Microsoft Certified:
Cybersecurity Architect Expert (SC-100)
Knowledge/Skills Required
- Extensive experience in cybersecurity governance, risk and compliance, security assurance, risk management, or information security roles.
- Experience working within Defence, Government, Critical Infrastructure, or other highly regulated environments.
- Experience supporting systems operating at PROTECTED or higher classifications is highly desirable.
- Solid understanding of the Australian Government Information Security Manual (ISM) and Protective Security Policy Framework (PSPF).
- Experience developing and maintaining accreditation and cybersecurity documentation.
- Exposure to IRAP assessments or formal IRAP training.
- Strong analytical, problem-solving, and critical thinking skills.
- Ability to manage competing priorities and work independently.
- High levels of integrity, professionalism, and discretion.
- Excellent written and verbal communication skills.
- Strong stakeholder engagement and documentation management capabilities.
- Commitment to continuous improvement and security best practices.
Employment Benefits
- Private health insurance
- Generous annual leave entitlements
- Annual incentive programme
- Paid parental leave
- Life and disability insurance
- Income protection insurance
- Employee Assistance Programme
- Novated leasing options
Diversity and Inclusion
Our client is committed to fostering an inclusive workplace that values diversity of thought, background, and experience. Applications are encouraged from all qualified candidates, and employment decisions are based on capability, potential, and alignment with organisational values.
Veterans
Veterans, reservists, and transitioning Australian Defence Force personnel are strongly encouraged to apply. Experience gained in military, intelligence, security, and operational environments is highly regarded.
#J-18808-Ljbffr
📌 Cyber GRC Analyst (Brisbane City)
🏢 Client 1
📍 Brisbane City