Business Analyst – GRC
vor 2 Wochen
Job Description — Business Analyst – Governance, Risk & Compliance – (GRC) Specialist (6‑Month Contract) Contract: 6 months (with potential to extend based on outcomes) Reports to: Risk Controls & Compliance Lead Role Purpose Drive audit readiness and uplift governance, risk, and compliance practices across the security program. You’ll lead the preparation for NIST 2.0, streamline evidence collection, and design automation to enhance the consistency and efficiency of controls—especially those aligned to JSOX/SOX and the Essential Eight. Key Outcomes Audit‑ready posture: Clear, complete, traceable evidence sets and control operation narratives for internal/external review. Automation‑first compliance: Repeatable, technology‑enabled control testing and evidence capture that reduces manual effort and error. Actionable risk remediation: Prioritized findings, tracked remediation, and validated corrective actions with measurable improvements. Core Responsibilities Assessment & Gap Analysis Plan and perform control testing across NIST 800‑series/NIST 2.0, SOX/JSOX, and Essential Eight requirements. Run a pre‑audit readiness review for NIST 2.0, highlighting gaps, risks, and pragmatic remediation paths. Map regulatory/standard requirements to technical controls and operational processes. Evidence & Audit Support Assemble and maintain audit artifacts: procedures, walkthroughs, test results, control descriptions, and evidence logs. Facilitate auditor interactions and stakeholder walkthroughs; ensure accuracy, completeness, and traceability. Automation & Process Improvement Identify manual control steps suitable for automation; design and implement technology‑enabled workflows. Build or enhance scripts/workflows/dashboards for control monitoring and evidence capture. Improve risk registers and reporting cadence; uplift alignment to the Risk Management Framework. Remediation & Governance Track findings through to closure; verify corrective actions and sustainability of fixes. Maintain clear documentation standards (templates, versioning, lineage) for repeatable audits. Skills & Experience Framework Expertise: Hands‑on exposure to NIST (incl. 2.0) or ISO/IEC 27001; experience implementing or auditing security frameworks. Controls & Tooling: Familiarity with SIEM, endpoint management, GRC platforms, and audit management systems. Requirements & Mapping: Strong ability to interpret regulatory controls and translate them into technical and process controls. Delivery Methods: Comfortable operating in Agile and Waterfall environments; able to tailor artifacts and ceremonies accordingly. Tool Proficiency: Microsoft 365, Jira, Confluence, and process modelling (e.g., Visio). Stakeholder Engagement: Clear communicator with the ability to collaborate across business, engineering, and senior leadership. Ways of Working / Competencies Team‑first, flexible: Willing to lean in and support adjacent workstreams. Outcome‑driven & meticulous: Strong documentation, traceability, and evidence hygiene. Proactive risk management: Early identification of issues; options‑led escalation with crisp recommendations. Success Measures (Indicative) Pre‑audit assessment completed with documented gaps, risk ratings, and remediation plans. Automated workflows implemented for priority controls/evidence capture, reducing manual effort and cycle time. Audit artifacts delivered on time with minimal rework; findings tracked to closure and validated. What You’ll Work With (Examples) Frameworks: NIST 800‑series/NIST 2.0, SOX/JSOX, Essential Eight. Platforms: SIEM and endpoint tools, GRC/audit systems, Microsoft 365, Jira/Confluence. Artifacts: Control catalogs, test plans, walkthrough scripts, evidence repositories, remediation trackers. Location Melbourne, Victoria, Australia #J-18808-Ljbffr
-
Business Development Manager
vor 2 Wochen
Melbourne, Österreich GRC Solutions VollzeitOverview Sales/Business Development Manager – Company: GRC Solutions · Employment Type: Full-time About Us At GRC Solutions, we specialise in delivering world-class governance, risk, and compliance training solutions designed to meet the unique challenges of modern businesses. Our award-winning adaptive compliance training and software solutions empower...
-
GRC Analyst
vor 3 Wochen
City of Melbourne, Österreich Kinetic VollzeitGRC Analyst | Cybersecurity Transformation 12 Month Fixed-Term Contracts About the Role Kinetic is on a major cyber security uplift journey. This is a greenfield role: you will help build Kinetic GRC capability from the ground up, establishing risk registers, compliance calendars, policies, and vendor risk frameworks where none currently exist. The role is...
-
GRC Analyst
Vor 6 Tagen
City of Melbourne, Österreich Natural Selection Group VollzeitThis is: the job A new 6‑month contract opportunity has opened for an experienced GRC Analyst to support a major security uplift program across governance, risk, and compliance frameworks. This role plays a central part in preparing for a formal NIST 2.0 audit while contributing to automation, process optimisation, and enhanced regulatory controls...
-
Cyber Defence GRC Analyst
Vor 2 Tagen
City of Melbourne, Österreich ClearCompany VollzeitJob Title: Defence Cyber GRC Analyst Location: Melbourne Engagement: 12-month fixed term contract Salary: $150,000 - $160,000 inclusive of super Clearance: Baseline (minimum) We are seeking an experienced Cyber GRC Analyst to join a major Work Order Management Upgrade Program within the Defence sector. This role will play a critical part in supporting...
-
Cyber Security GRC Analyst
Vor 2 Tagen
City of Brisbane, Österreich Subscribe to job alerts VollzeitRole: Cyber Security GRC Analyst Location: Brisbane (Hybrid) Remuneration / Benefit : Negotiable up to a $ (Total remuneration including superannuation) About the role: We’re seeking an up-and-coming cybersecurity GRC analyst to help implement and operate robust governance activities and frameworks ensuring cyber security risk and compliance objectives are...
-
Hybrid GRC Data Analyst | Digital Systems Specialist
vor 3 Wochen
City of Melbourne, Österreich Jemena group VollzeitAn Australian energy company is seeking a Business Analyst (Digital Specialist) to enhance their GRC system, Protecht. The ideal candidate will have expertise in JavaScript and SQL, with 2-5 years of digital business analysis experience, focusing on governance and risk management. This hybrid role offers the chance to make a meaningful impact toward...
-
Cyber GRC Analyst
vor 2 Wochen
City of Brisbane, Österreich BOQ VollzeitCyber GRC Analyst page is loaded## Cyber GRC Analystlocations: Brisbane Office - Newstead Villagetime type: Full timeposted on: Posted Todayjob requisition id: JR **About the role**BOQ Group are looking for a Cyber GRC Analyst to join our Group Technology division. We are looking for someone who is keen to learn and build their career in Cyber GRC. The...
-
Cyber GRC Analyst
vor 1 Woche
City of Brisbane, Österreich BOQ Group VollzeitJoin to apply for the Cyber GRC Analyst role at BOQ Group About The Role BOQ Group is looking for a Cyber GRC Analyst to join our Group Technology division. We are looking for someone who is keen to learn and build their career in Cyber GRC. The perfect candidate would have a good mix of Data Analytics (utilising Power BI) and Cyber GRC experience....
-
Cyber GRC Analyst
vor 2 Wochen
Melbourne, Österreich AusNet VollzeitJoin to apply for the Cyber GRC Analyst role at AusNet 11 hours ago Be among the first 25 applicants Join to apply for the Cyber GRC Analyst role at AusNet Direct message the job poster from AusNet Talent Acquisition Leader I Recruitment Manager | Talent Partner Play a pivotal role in Cyber Governance, Risk, and Compliance (GRC), driving initiatives that...
-
Cyber Security GRC Analyst
vor 1 Woche
City of Brisbane, Österreich Leidos Australia VollzeitCyber Security GRC Analyst Join Leidos Australia as a Cyber Security Governance, Risk & Compliance (GRC) Analyst. Leidos delivers IT and airborne solutions that protect and advance the Australian way of life, supporting national security and government, intelligence, defence, aviation, border protection and health markets. Responsibilities: Evaluate the...