Cyber GRC Analyst

Whizdom ·whizdom.shazamme.com

Location Canberra, Australian Capital Territory, Australia
Salary AUD 183,680 / year
Type Full time
Level Mid
Source Shazamme
Information & Communication Technology (ICT)
Apply direct
Seeking a Cyber GRC Analyst with Knowledge of PSPF, ISM, Essential 8, NIST.

The Cyber GRC Specialist supports the organisations information system authorisation activities by embedding governance, risk, and regulatory compliance practices that are aligned to Australian Government frameworks – particularly the Information Security Manual (ISM), Protective Security Policy Framework (PSPF), and  Essential 8. Working under the Cyber GRC Manager and as part of the broader cybersecurity team, this role supports the implementation, monitoring, and continuous improvement of security controls to ensure compliance, maturity uplift, and informed risk management is in line with organisational objectives and Government standards.

Responsibilities
  • Develop, deliver and maintain security authorisation documentation (e.g., System Security Plans, Security Risk Management Plans, and Cyber Incident Response Plans) to support Government processes.
  • Implement security standards, ISM, Essential 8, NIST, etc.
  • Provide cyber security advice that assists with the monitoring of infrastructure components, the design of infrastructure, identify areas for improvements and assist with the implementation of upgrades, or enhancements as required.
  • Conduct cyber security risk assessments to identify and evaluate potential threats and vulnerabilities.
  • Provide SME recommendations and advice on compliance and regulatory requirements to support continuous improvement of cyber security posture.
  • Assist with the development of comprehensive security policies to address and mitigate risks.
Skills and Abilities
  • Minimum 3 years working as a Cyber Security or GRC Analyst.
  • Knowledge of security standards and frameworks such as PSPF, ISM, Essential 8, NIST.
  • Ability to identify risks, provide risk reduction strategies, and collaborate with business teams to secure stakeholders’ approval and support.
  • Experience working within an enterprise security environment.
  • Previously worked in heavily regulated environments such as federal government, telco, energy, etc.
  • Excellent communication skills and ability to communicate with stakeholders varying in seniority and technical understanding.
  • Desirable: ISO27000 series, NIST 800 series, CIS.
Permanent role - $164k + Super 

Security Required:  NV1 or NV2 Security Clearance required 

Location  - Canberra

How to Apply - Please upload your resume to apply. Candidates will need to be willing to undergo pre-employment screening checks which may include, ID and work rights, security clearance verification and any other client requested checks

Closing date: Thursday 27 August by 9am

Call Joanne Finchett on 0480 002454 or email Joanne@whizdom.com.au for any further information

 

Frequently asked questions

Who is hiring for the Cyber GRC Analyst role?
Whizdom is hiring for the Cyber GRC Analyst position, a Shazamme client. Apply directly on the employer's career site.
Where is the Cyber GRC Analyst job located?
The Cyber GRC Analyst role with Whizdom is based in Canberra, ACT, AU.
What does the Cyber GRC Analyst role pay?
Whizdom lists the Cyber GRC Analyst role at up to AUD 183,680 per year.
Is the Cyber GRC Analyst role full-time or contract?
This is a full time position at Whizdom.
What experience level is the Cyber GRC Analyst role?
The Cyber GRC Analyst position is aimed at mid-level candidates.
How do I apply for the Cyber GRC Analyst role at Whizdom?
Apply directly on Whizdom's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS — no third-party form, no resume database.
Apply direct