Cyber Security & GRC Analyst (Melbourne)

Cyber Security & GRC Analyst (Melbourne)

23 Sep
|
David Jones
|
Melbourne

23 Sep

David Jones

Melbourne

Protect what matters. Strengthen cyber resilience. Help shape a security-conscious culture.

At David Jones, we are committed to creating secure, seamless and trusted experiences for our customers and our people. We are looking for a Cyber Security & GRC Analyst who can combine hands-on security operations with practical governance, risk and compliance expertise.

This is a broad and highly collaborative role where you will monitor and respond to security events, coordinate vulnerability remediation, strengthen our cyber control environment and help embed secure behaviours across the organisation.

Working across Technology and the broader business, you will translate technical security information into clear, risk-based actions that protect our operations while enabling innovation and progress.

What will your day look like?

In this role, you will:

- Monitor and triage security alerts, events and reported concerns, escalating and coordinating responses in line with established processes
- Support the investigation of security incidents, including evidence gathering, root-cause analysis and identification of recurring issues
- Coordinate vulnerability scanning and work with system owners to prioritise remediation, patching and risk treatment
- Track vulnerabilities, control gaps and remediation actions through to closure
- Support identity and access management activities, including access reviews, privileged access checks and least-privilege assurance
- Maintain cyber security policies, standards, procedures and the security control framework
- Support cyber and technology risk assessments, control assurance activities and continuous control monitoring
- Coordinate evidence and stakeholder responses for internal and external audits
- Help maintain alignment with frameworks and obligations including the Essential Eight, NIST Cybersecurity Framework, ISO 27001/27002 and PCI DSS




- Coordinate cyber security awareness campaigns, training and phishing simulations
- Prepare operational and GRC reporting across incidents, vulnerabilities, risks, controls, audits and awareness measures
- Provide clear, practical security advice to Technology teams, project teams and stakeholders across the business
- Identify opportunities to automate, simplify and strengthen security processes, controls and reporting

What will you need to thrive?

You will bring approximately three years of experience across cyber security operations, cyber GRC, technology risk, audit or a comparable role combining these disciplines.

You will also have:

- Hands-on experience in security alert triage, incident analysis, vulnerability management and remediation coordination
- Experience supporting cyber risk assessments, control assurance, policy maintenance, audits and remediation tracking
- Working knowledge of security frameworks and standards such as the Essential Eight, NIST Cybersecurity Framework, ISO 27001/27002 and PCI DSS
- Exposure to security technologies across identity, email, endpoint, cloud and vulnerability management
- Experience with Microsoft security solutions and tools such as Proofpoint, CrowdStrike, Cortex, Rapid7 or Tenable
- The ability to analyse security information, identify patterns and translate technical findings into practical business actions
- Strong stakeholder engagement, organisation and follow-through
- The ability to balance operational security priorities with scheduled governance and compliance activities




- Solid written communication skills, with the ability to develop concise policies, procedures, reports, training materials and management updates
- Experience delivering cyber awareness communications, training or phishing simulations
- A relevant qualification in cyber security, information technology, risk or a related discipline, or equivalent practical experience

Relevant industry certifications, or active progress toward certification, will be highly regarded.

Why join David Jones?

Our purpose is to inspire like no other , and our people bring this to life every day.

At David Jones, you will join a culture where people are encouraged to be customer obsessed, empowered, inclusive and innovative. You will have the opportunity to work across a complex and iconic retail organisation, partnering with diverse teams to improve cyber resilience and build greater security capability across the business.

This role offers the chance to broaden your exposure across both cyber security operations and GRC, contribute to meaningful security improvements and help shape a culture where protecting our customers, people and business is everyone’s responsibility.

Ready to inspire like no other?

If you are curious, collaborative and motivated by turning cyber risk into practical action, we would love to hear from you.

Apply now and help us build secure, resilient and trusted experiences across David Jones.

David Jones is committed to creating an inclusive workplace where everyone feels respected, valued and empowered to thrive. We welcome applications from people of all backgrounds, experiences and perspectives.

Be careful - Don’t provide your bank or credit card details when applying for jobs. Don't transfer any money or complete suspicious online surveys. If you see something suspicious, report this job ad .

#J-18808-Ljbffr

📌 Cyber Security & GRC Analyst (Melbourne)
🏢 David Jones
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber security & grc analyst (melbourne) / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: cyber security & grc analyst (melbourne) / melbourne