05 Oct
|
News
|
Melbourne
- Join a collaborative team that enables REA to manage cyber risk confidently while supporting secure business growth
- Lead cyber security risk assessments across products,platformsand key initiatives
- Permanent role based in Melbourne
We're REA
With bold and ambitious goals, REA Group (about-us/about-rea-group/) is changing the way the world experiences property. No matter where you're at on your property journey, we're here to help with every step - whether that's finding or financing your next home.
Our people are the key to our success. At the heart of everything we do, is a thriving culture centred around high performance and care. We are purpose driven and collaborative, which drives innovation and our ability to make a real impact. As such, we're proud to have been named one of Australia's Best Workplaces (about-us/#our-awards) four times since 2021 — including third place in 2025 — plus Best Workplace for Women in 2023 and Best Workplace in Technology in 2024 and 2025. These listings are testament to every person who helps make REA a great place to work.
Where the team fits in
The Cyber Security GRC team provide advice and guidance across governance, risk and compliance, helping teams understand their security responsibilities, assess and treat risks, meet regulatory and contractual obligations, and embed secure-by-design practices into products, platforms and initiatives. We also support security assessments, third-party due diligence, compliance programs, reporting and continuous improvement across REA.
What the role is all about
The Senior Cyber GRC Analystis a key role within theGRC team andstrengthens REA's cyber resilience by leading theidentification, assessment and treatment of technology and information security risks, ensuring our products and platforms comply with relevant security, privacy and regulatory requirements, and enabling informed, risk-based decisions that protect our customers, people and brand while supporting sustainable business growth.
Day to day of the job
- Design, implement and continuously improve cyber GRC frameworks, policies,
standards and supporting processes to fit REA's operating model
- Work closely with other teams within REA Security to ensure they are effectivelyprioritisingthe building andoperationof cyber security controls, in line with theorganisation’srisk profile
- Coordinate and oversee control assurance activities (e.g.control testing, audits, attestations) and track remediationthroughclosure.Where possible, automate this assurance work
- Ensure that external compliance obligations and audits are appropriately prepared forand managed
- Provide specialist cyber GRC advice andcoaching totechnology and product teams to embed secure-by-design and risk-based thinking
- Monitor changes in relevant cyber, privacy and technologystandards, contracts andregulations and translate these into practical requirements and guidance for REA
- Prepare and present concise, insightful risk and compliance reporting for technology leadership, riskcommittees, the board of directorsand other stakeholders
- Support third-party and supplier security assessments, including due diligence, ongoingassuranceand contract requirement reviews
- Contribute to incident preparedness activities (e.g.playbooks, table-top exercises) and support post-incident reviews from a GRC perspective
- Champion consistent use of cyber GRC tools and data, helping tomaintainaccuraterisk,controland issue registers
- Drive and support uplift initiatives that improve security culture,awarenessand ownership of cyber risk across theorganisation
- Championacultureofinnovationand automationaround GRC
Who we're looking for
- Significant experiencein cyber security governance, risk and compliance, technologyriskor related fields, ideally in digital or technology-ledorganisations
- Demonstrated experience working closely with product and engineering teams to embed security and risk management into delivery practices
- Proficiencywith GRC and security tooling (e.g.risk registers, control libraries, workflow tools, vulnerability/issue management platforms) and using data to produce clear risk insights
- Solid understanding of modern cloud and product engineering environments (e.g.AWS, CI/CD, microservices) and common security patterns,controlsand failure modes
- Experience coordinating or supporting security audits,certificationsor regulatory reviews (e.g.ISO27001, SOC 2,PCI-DSSor similar)
- Relevant tertiaryqualificationin Information Security, IT, Risk or related discipline, or equivalent practical experience
The REA experience
The physical, mental, emotional and financial health of our people is something we’ll never stop caring about. This is a place to learn and grow.
Some of our Perks & Advantages include:
- A hybrid and flexible approach to working
- Flexible leave options including, birthday leave and purchase additional leave
- Flexible parental leave offering for primary and secondary carers
- Our Because We Care program offers employees volunteering leave, community grants, matched payroll giving and our Community Café donates 100% of revenue to charity
- Hackdays so you can bring your big ideas to life
Our commitment to Diversity, Equity, and Inclusion
We are committed to providing a working environment that embraces and values diversity, equity and inclusion. We believe teams with diverse ideas and experiences are more creative, more eu00f5ffective and fuel disruptive thinking. If you've got the skills, dedication and enthusiasm to learn but don't necessarily meet every single point on the job description, please still get in touch.
Join our Talent Neighbourhood
Keen to be part of REA but didn't find a perfect match with this opportunity? Perhaps the timing isn't right? You should join our Talent Neighbourhood! (careers-talentneighbourhood)
Req ID R
#J-18808-Ljbffr
📌 Senior Cyber GRC Analyst (Melbourne)
🏢 News
📍 Melbourne