Talent.com
Education Services Australia (ESA)
GRC & Security AnalystEducation Services Australia (ESA) • Melbourne, AU
GRC & Security Analyst

GRC & Security Analyst

Education Services Australia (ESA) • Melbourne, AU
5 days ago
Job description

Education Services Australia (ESA) was established by education ministers in 2010. We specialise in connecting policy, technology and practice. With this unique capability, we help advance nationally agreed education initiatives across Australia. Working with government and schools, we co-create and deliver technology-driven solutions that improve education outcomes – for everyone, everywhere.

The Technology business unit comprises Assessment, NSIP, ICT, Systems Development, Product Strategy Technology, PMO, Risk and Information Security teams at ESA.

Why work with us

  • Work for a not-for-profit organization that provides true impact for students, teachers, parents, and carers
  • We have received Xref Engage Best Workplace & Change Champion Awards 2025
  • Flexible working policy – 40% in the office and 35 hour week
  • Office in a convenient location in the heart of the CBD
  • Learn more about life at ESA here: Careers at ESA | Help shape the future of education

About the role

We’re seeking a skilled and motivated Governance, Risk, Compliance (GRC) & Security Analyst to join our Security team. In this role, you will support ESA in strengthening our information security practices, ensuring we meet our obligations, and helping build a cyber‑resilient and risk‑aware culture across the organisation.

Key focus includes:

Governance

  • Maintain and improve security governance frameworks, policies, and documentation.
  • Administer operational security governance forums and ensure appropriate escalation.
  • Drive continuous improvement in oversight and security controls.

Risk

  • Conduct information security risk assessments for vendors, systems, and projects.
  • Maintain risk registers and enhance risk management processes.
  • Support business units with risk mitigation planning and decision‑making.

Compliance

  • Conduct or support internal security compliance reviews and assessments.
  • Manage compliance assessments conducted by 3rd party vendors end-to-end (e.g., IRAP, Essential Eight).
  • Develop templates and provide guidance to ensure security compliance requirements are met.
  • Maintain and enhance incident response methodologies and processes to strengthen organisational readiness.
  • Coordinate responses to moderate-level security incidents.
  • Conduct incident training, simulations, and capability uplift activities.

Reporting, Advice & Support

  • Develop dashboards and metrics that communicate security posture.
  • Manage cyber awareness and phishing simulation activities.
  • Provide expert advice on security obligations, secure design, and technical controls.
  • Coordinate the organisation’s response to vulnerabilities identified through the ASD CHIPs program.

Who we're looking for

  • Someone who brings expertise, energy, and a collaborative mindset
  • Extensive experience in information security GRC, including policy development, stakeholder consultation, compliance activities, incident coordination, and awareness initiatives.
  • Strong communication and interpersonal skills, with the ability to engage both technical and non‑technical audiences
  • Ability to work independently and within a multi‑disciplinary team
  • Strong problem‑solving ability and sound judgement
  • Practical experience implementing ASD ISM and Essential Eight
  • Experience with frameworks such as PSPF, ISO 27001, NIST CSF, OWASP
  • Knowledge of cloud and on‑prem environments (Microsoft, Linux)
  • Familiarity with secure development practices and CMS and LMS platforms, such as Umbraco or Moodle
  • Experience or interest in the EdTech sector
  • Understanding of privacy frameworks including the Australian Privacy Act, APPs, and GDPR
  • Certifications include ISO 27001, CISM, CRISC, CISA, CISSP, and IRAP.

What ESA offer

At ESA we want everyone to succeed, irrespective of their gender, ethnicity, sexuality, physical ability or age. We welcome applications from Aboriginal and Torres Strait Islander peoples. In addition to a competitive remuneration package, ESA offers lifestyle benefits and a culture that allows people and ideas to flourish.

Application Process

If you don’t feel you meet every requirement we would still love to hear from you, you may be the right candidate for this or one of our other opportunities in the future.

Please send your resume and cover letter through.

#J-18808-Ljbffr

Create a job alert for this search

GRC & Security Analyst • Melbourne, AU

Similar jobs

GRC Specialist, AWS Security

AmazonMelbourne, VIC, AU

Applicants must be Australian citizens and hold or be eligible to obtain an Australian Government Security Clearance with the ability to successfully complete an Organisational Suitability Assessme... Show more

Cyber GRC Analyst

AusNetMelbourne, AU

Be among the first 25 applicants.Direct message the job poster from AusNet.Talent Acquisition Leader I Recruitment Manager | Talent Partner.Play a pivotal role in Cyber Governance, Risk, and Compli... Show more

 • Promoted

Security Analyst

TalentMelbourne, AU

Initial 12 Month Contract | Potential For Extensions.Docklands Location | Hybrid Working Arrangements.CCTV | Access Control Systems | Network Infrastructure.The Security Analyst plays a key role in... Show more

 • Promoted

Senior Cyber Risk Analyst - Government ICT

Experis ManpowerGroup Sp. z o.o.Melbourne, AU

Cyber Security Risk Analyst for a 12-month contract in Melbourne.This role involves conducting detailed risk assessments and contributing to security documentation aligned with Australian Governmen... Show more

 • Promoted

GRC Security Specialist

EmmbrMelbourne, AU

Cybersecurity Talent Scout @Emmbr – I connect Top Cybersecurity professionals with leading companies.Full time, permanent and hybrid – Melbourne.This is an opportunity to work within a large, compl... Show more

 • Promoted

Senior Cyber Security Engineer - Defence Systems & GRC

Hanwha Defence AustraliaMelbourne, AU

Hanwha Defence Australia, based at the Avalon H-ACE facility, seeks a Senior Engineer – Cyber Security to lead system‑level cybersecurity across major defence programs.You will define requirements,... Show more

 • Promoted

SOC Analyst - Cyber Security

QuorumMelbourne, AU

Founded in 2004, Quorum is an award‑winning team of industry‑leading professionals who deliver world‑class solutions and services that provide businesses modern and secure Microsoft Cloud Solutions... Show more

 • Promoted

Infra Security Architect | Cloud & OT Security Lead

ALOIS AustraliaMelbourne, AU

A leading recruitment firm in Melbourne is seeking an experienced Infra Security Architect to develop robust security architecture frameworks for IT and OT systems.The ideal candidate has over 7 ye... Show more

 • Promoted

Defence Cyber Security Lead | GRC & Delivery Leader

LeidosMelbourne, AU

Leidos Australia is seeking a Cyber Security Lead to support a major Defence program in Melbourne CBD.This critical role involves guiding cyber security obligations, managing stakeholder engagement... Show more

 • Promoted

Principal Security Analyst

Experis AustraliaMelbourne, AU

Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.This range is provided by Experis Australia.Your actual pay will be based on your skills and experienc... Show more

 • Promoted

Security Operations Center Analyst

Kaizen Global TechnologiesMelbourne, AU

Senior Talent Acquisition Specialist @ Kaizen Global Technologies | MBA in Finance and Human Resources.Hiring: Security Analyst / SOC Analyst.Eligibility: Must have valid Australian work rights (Ci... Show more

 • Promoted

Tech Risk & Awareness GRC Manager

Reece GroupMelbourne, AU

Tech Risk & Awareness GRC Manager.Tech Risk & Awareness GRC Manager.You probably know Reece as Australia’s largest supplier of plumbing and bathroom products.But we are much more than that.We are a... Show more

 • Promoted

Defence Cyber Security Lead: Governance & Risk

Leidos AustraliaMelbourne, AU

Leidos Australia is seeking a Cyber Security Lead to support a major Defence program in Melbourne CBD.This is a full-time opportunity where you will lead cyber security obligations and guide teams ... Show more

 • Promoted

GRC Security Lead (Hybrid) — Policy & Compliance

EmmbrMelbourne, AU

A global distribution organisation is seeking a GRC Specialist to enhance governance, risk, and compliance capabilities within their cybersecurity function.This full-time role in Melbourne requires... Show more

 • Promoted

Senior Cyber Security Analyst: Threat Hunter & Incident

PFD Food Services Pty LtdMelbourne, AU

A leading food services company in Melbourne is seeking a Senior Cyber Security Analyst to monitor and respond to threats, strengthen cyber resilience, and drive initiatives in security management.... Show more

 • Promoted

GRC Specialist, AWS Security

Amazon Web Services (AWS)Melbourne, AU

Applicants must be Australian citizens and hold or be eligible to obtain an Australian Government Security Clearance with the ability to successfully complete an Organisational Suitability Assessme... Show more

 • Promoted

SOC Analyst - Cyber Security (Hybrid)

QuorumMelbourne, AU

A leading Cyber Security firm in Australia seeks a SOC Analyst to join its Cyber Defense team.The ideal candidate will have hands-on experience with Microsoft Sentinel and the Microsoft Defender su... Show more

 • Promoted

Full Time Senior Cyber Security Analyst - Offensive Managing Consultant

Triskele LabsMelbourne, AU

Full Time Senior Cyber Security Analyst - Offensive Managing Consultant.Full Time Senior Cyber Security Analyst - Offensive Managing Consultant.Be among the first 25 applicants.Direct message the j... Show more