Job description
The GRC Analyst will play a key role in ensuring governance, risk, and compliance processes are effectively managed within the technology department. This permanent role is based in Cremorne and offers a competitive salary package.
An organisation within the FMCG industry, located in Burnley.
Description
- Execute and report on the organisation's multi-year cybersecurity uplift roadmap.
- Maintain security policies, standards and controls aligned to ISO 27001, ISM and ASD Essential Eight.
- Coordinate internal and external security audits, including evidence collection and remediation tracking.
- Manage risk assessments, business impact assessments and third-party security reviews.
- Maintain and improve the Information Security Management System (ISMS).
- Monitor security compliance, identify control gaps and drive remediation activities.
- Provide governance reporting and cybersecurity guidance to key stakeholders.
Profile
A successful GRC Analyst should have:
- 3-5 years' experience in Cybersecurity Governance, Risk & Compliance (GRC).
- Strong working knowledge of ISO 27001, ISM and ASD Essential Eight.
- Experience maintaining ISMS frameworks and security documentation.
- Proven experience supporting security audits and audit-ready evidence management.
- Experience in vendor risk management, risk assessments and control reviews.
- Strong stakeholder engagement and communication skills.
- Relevant tertiary qualifications and certifications such as CISSP, CISM or CRISC are advantageous.
Job Offer
- Exposure to enterprise cybersecurity governance and audit programmes.
- Broad role combining strategic GRC activities with hands‑on security support.
- Permanent, full-time position based in Melbourne.
#J-18808-Ljbffr