Cyber Governance, Risk, and Compliance (GRC) Specialist

apartmentAI Talent Pty Ltd placeSydney calendar_month 

About the Role

We are seeking an experienced Cyber Governance, Risk, and Compliance (GRC) Specialist to lead the implementation and continuous improvement of our organisation’s cybersecurity governance framework. This position is pivotal in ensuring that our systems, data, and infrastructure adhere to internal policies and external regulatory obligations, while proactively managing cyber risk and compliance across the enterprise.

You will work closely with executive leadership, IT teams, and external stakeholders to develop strategies, monitor controls, and report on risk posture, audit outcomes, and compliance metrics.

Key Responsibilities

Lead the design, implementation, and management of cybersecurity governance frameworks, including policies, standards, and procedures aligned to ISO 27001, NIST, Essential Eight, and other relevant standards.
Perform risk assessments and control evaluations to identify cybersecurity risks across infrastructure, applications, and third-party vendors.
Develop and maintain the organisation’s information security risk register and assist in the treatment planning and mitigation strategies.
Coordinate internal and external audits related to cybersecurity and manage compliance reporting (e.g., SOC 2, ISO 27001, CPS 234, GDPR).

Provide expert advice to business and IT leaders regarding security requirements, regulatory changes, and risk implications of new projects or technologies.

Monitor compliance with security policies, identify gaps, and drive remediation in collaboration with system and security teams.
Develop metrics and reporting dashboards for executive oversight of cyber risk, control effectiveness, and incident trends.
Lead training and awareness initiatives to embed a culture of security and compliance across all departments.

Liaise with external auditors, regulators, and compliance authorities where required.

Required Skills & Experience
Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or related field.
Minimum 5 years of experience in a cybersecurity GRC or Information Security Compliance role.
Strong understanding of risk management frameworks (e.g., ISO 27005, NIST RMF, FAIR), and regulatory standards (e.g., CPS 234, GDPR, PCI-DSS, SOX).
Demonstrated experience leading internal/external security audits and vendor risk assessments.
Excellent communication and stakeholder engagement skills, including report writing and executive briefings.

Familiarity with GRC platforms and SIEM tools (e.g., Archer, ServiceNow GRC, Splunk, Microsoft Defender).

Relevant certifications preferred: CISM, CISSP, CRISC, ISO 27001 Lead Auditor, or equivalent.

Why Join Us?
Work with a dedicated team driving cyber resilience across the organisation.
High-visibility role influencing security posture and risk culture at the executive level.
Career development and upskilling opportunities in a supportive environment.

Flexible working arrangements with a hybrid or remote-friendly structure.

local_fire_departmentUrgent

Compliance Officer (12 month FTC)

apartmentRobert HalfplaceChatswood NSW, 8 km from Sydney
Job Title: Compliance Officer (12-Month Fixed Term Contract - Maternity Leave Cover) Location: Chatswood, Sydney (3 days in office / 2 days WFH) We are seeking a Compliance Officer to join a dynamic and supportive team on a 12-month fixed term...
business_centerHigh salary

APAC Compliance Officer

placeNorth Sydney NSW, 3 km from Sydney
network spans the globe with more than 400,000 consumer touchpoints. Learn more at BHN.com. Overview: This individual, based in Blackhawk Network Australia will manage all regulatory compliance functions and programs in the APAC region by developing...
apartmentAmazonplaceSydney NSW
by the applicable export control regulations Key job responsibilities  •  Set Australia and New Zealand regional trade compliance strategy covering programs including customs valuation, broker management, and compliance with Other Government Agency requirements...