Senior GRC Specialist (BBBH8015) Melbourne CBD, Melbourne, Australia
| Salary: | AUD160000 - AUD165000 per annum |
- Lead cyber risk, assurance and compliance across a complex enterprise
- Work closely with senior cyber and technology leaders
- Permanent, hybrid opportunity based in Melbourne
We are partnering with a large enterprise organisation to appoint a Senior Cyber GRC Specialist as it continues to strengthen its cyber governance, risk and assurance capability.
This role will suit someone who is comfortable taking ownership of complex GRC initiatives rather than operating purely in an advisory capacity. You will lead audit and assurance activity, oversee key risk and compliance processes, and help improve how cyber risk is managed and reported across the organisation.
You will work across cyber, technology and the broader business, translating regulatory, audit and risk requirements into practical actions and measurable outcomes.
The Role
- Coordinate cyber audit and assurance programs across internal and external requirements
- Manage and maintain the organisation’s ISO 27001 ISMS
- Lead audit preparation, evidence collection, findings management and remediation tracking
- Own key cyber risk processes, including risk assessments, risk registers and treatment plans
- Prepare clear reporting for senior leadership on risk exposure, compliance and remediation progress
- Review and improve cyber governance policies, standards and frameworks
- Support alignment with recognised frameworks including ISO 27001 and NIST
- Improve GRC systems, processes and reporting to increase visibility and reduce manual effort
- Partner with cyber, technology and business teams to embed consistent risk and compliance practices
- Provide guidance and support to other members of the GRC function
About You
- Significant experience across cyber GRC, technology risk, audit or assurance
- Experience working within a large or complex enterprise environment
- Demonstrated ownership of ISO 27001 audits, internal audits or broader assurance programs
- Strong practical knowledge of cyber risk assessments, risk registers and treatment planning
- Experience preparing risk and compliance reporting for senior or executive stakeholders
- Working knowledge of frameworks such as ISO 27001 and NIST
- Experience using GRC platforms or similar risk and compliance tools
- Strong written and verbal communication skills
- Able to work autonomously, manage competing priorities and drive initiatives through to completion
This is an opportunity to take ownership of meaningful GRC work within an organisation continuing to invest in and mature its cyber security capability.
Apply now to learn more.