Cyber GRC Analyst

Client 1

City of Brisbane

On-site

AUD 110,000 - 160,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Private health insurance
Generous annual leave entitlements
Annual incentive programme
Paid parental leave
Life and disability insurance
Income protection insurance
Employee Assistance Programme
Novated leasing options

Job summary

Client 1 in Brisbane is seeking a motivated Cyber Governance, Risk and Compliance (GRC) Analyst to support cybersecurity governance and assurance activities within a classified Microsoft Azure environment.

This role involves developing, reviewing and managing accreditation, risk and governance documentation while working with technical teams, project stakeholders and governance bodies to keep information systems secure, compliant and aligned with Australian Government cyber security requirements.

Qualifications

  • Extensive experience in cybersecurity governance, risk and compliance roles.
  • Experience in Defence, Government or highly regulated environments.
  • Knowledge of ISM and PSPF.
  • Ability to develop accreditation documentation.
  • IRAP experience or training.

Responsibilities

  • Develop and maintain cybersecurity governance and accreditation documentation (SSPs, SRMPs, POA&Ms).
  • Support system accreditation and re-accreditation in classified environments.
  • Ensure compliance with ISM, PSPF, Essential Eight.
  • Conduct security reviews, audits and assurance assessments.
  • Provide cyber security advice to project teams and governance forums.
  • Prepare compliance reports for senior stakeholders.
  • Collaborate with technical teams to validate controls.

Skills

Cyber GRC
Governance
Risk management
Security assurance
Stakeholder engagement
Documentation management
IRAP knowledge
Communication

Education

Bachelor's degree in Cyber Security

Job description

Role Title
Cyber GRC Analyst



Location
Brisbane, QLD



Working Arrangement
Full-time



Clearance Required
Baseline AGSVA clearance or above.



Company Overview
Our client is a growing national security and technology organisation delivering advanced cyber, digital, and mission-critical capabilities within highly regulated environments. Supporting government and defence-related outcomes, the organisation is focused on maintaining the highest standards of security, compliance, and operational excellence.



Job Description
We are seeking a motivated and detail-oriented Cyber Governance, Risk and Compliance (GRC) Analyst to support cybersecurity governance and assurance activities within a classified Microsoft Azure environment.



This role is responsible for maintaining the security compliance of critical systems and services through the development, review, and management of accreditation, risk, and governance documentation. Working closely with technical teams, security practitioners, project stakeholders, and governance bodies, you will help ensure information systems remain secure, compliant, and aligned with Australian Government cyber security requirements.



The successful candidate will contribute to security accreditation activities, risk management processes, compliance assessments, governance forums, and security assurance initiatives while providing trusted advice to internal stakeholders.


Duties and Responsibilities



  • Develop, review, maintain, and update cybersecurity governance and accreditation documentation including System Security Plans (SSPs), Security Risk Management Plans (SRMPs), risk assessments, procedures, and Plans of Action and Milestones (POA&Ms).

  • Support system accreditation and re-accreditation activities within classified environments.

  • Ensure ongoing compliance with the Information Security Manual (ISM), Protective Security Policy Framework (PSPF), Essential Eight, and internal security requirements.

  • Conduct security compliance reviews, audits, and assurance assessments.

  • Identify, assess, document, and manage cyber security risks and control gaps.

  • Monitor remediation activities and ensure audit findings are effectively addressed.

  • Provide cyber security advice to project teams, governance forums, and business stakeholders.

  • Participate in investigations relating to cyber security incidents, compliance concerns, and security breaches.

  • Prepare compliance reporting and risk status updates for senior stakeholders.

  • Collaborate with technical teams to validate security controls and implementation effectiveness.

  • Support the development and continuous improvement of cyber security policies, standards, procedures, and governance frameworks.

  • Maintain compliance evidence repositories and accreditation artefacts.

  • Deliver cyber security awareness and training activities to system users.

  • Engage with internal and external stakeholders to support security and compliance objectives.


Education/Certifications Required



  • Bachelor's degree in Cyber Security, Information Security, Information Technology, Computer Science, Risk Management, Governance, or a related discipline.

  • Relevant industry experience may be considered in lieu of formal qualifications.


Highly desirable certifications include:



  • CRISC

  • CISA

  • CGRC

  • ISO 27001 Lead Auditor

  • ITIL 4 Foundation

  • Microsoft Certified: Azure Fundamentals (AZ-900)

  • Microsoft Certified: Security Fundamentals (SC-900)

  • Microsoft Certified: Information Protection and Compliance Administrator (SC-400)

  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)


Knowledge/Skills Required



  • Extensive experience in cybersecurity governance, risk and compliance, security assurance, risk management, or information security roles.

  • Experience working within Defence, Government, Critical Infrastructure, or other highly regulated environments.

  • Experience supporting systems operating at PROTECTED or higher classifications is highly desirable.

  • Strong understanding of the Australian Government Information Security Manual (ISM) and Protective Security Policy Framework (PSPF).

  • Experience developing and maintaining accreditation and cybersecurity documentation.

  • Exposure to IRAP assessments or formal IRAP training.

  • Strong analytical, problem-solving, and critical thinking skills.

  • Ability to manage competing priorities and work independently.

  • High levels of integrity, professionalism, and discretion.

  • Excellent written and verbal communication skills.

  • Strong stakeholder engagement and documentation management capabilities.

  • Commitment to continuous improvement and security best practices.


Employment Benefits



  • Private health insurance

  • Generous annual leave entitlements

  • Annual incentive programme

  • Paid parental leave

  • Life and disability insurance

  • Income protection insurance

  • Employee Assistance Programme

  • Novated leasing options


Diversity and Inclusion
Our client is committed to fostering an inclusive workplace that values diversity of thought, background, and experience. Applications are encouraged from all qualified candidates, and employment decisions are based on capability, potential, and alignment with organisational values.



Veterans
Veterans, reservists, and transitioning Australian Defence Force personnel are strongly encouraged to apply. Experience gained in military, intelligence, security, and operational environments is highly regarded.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber GRC Specialist
Cyber GRC Specialist

Client 1 • Canberra

On-site
AUD 120,000 - 150,000
14% superannuation
6 weeks paid annual leave
Mentoring & professional development
GRC Specialist
GRC Specialist

Client 1 • Canberra

On-site
AUD 110,000 - 150,000
14% superannuation
6 weeks annual leave
Professional development
+2
Cyber Governance, Risk and Compliance Specialist
Cyber Governance, Risk and Compliance Specialist

Metrea • City of Brisbane

On-site
AUD 110,000 - 170,000
Private Health Insurance
Generous Annual Leave
Annual incentive plan
+5
Defence Cyber Security GRC Specialist
Defence Cyber Security GRC Specialist

C4I Solutions Pty • Sydney

Hybrid
AUD 140,000 - 190,000
Cyber Security- GRC Manager- AU Citizen with Security Clearance
Cyber Security- GRC Manager- AU Citizen with Security Clearance

Accenture • City of Melbourne

On-site
AUD 120,000 - 150,000
Flexible work arrangements
Career development program
Diversity & Inclusion initiatives
Technology Specialist Cyber GRC
Technology Specialist Cyber GRC

C4i Solutions • Penrith City Council

On-site
AUD 110,000 - 140,000
Long Service Leave
Health & wellbeing allowance
First year leave
+6
Technology Specialist Cyber GRC
Technology Specialist Cyber GRC

C4I Solutions Pty • Penrith City Council

On-site
AUD 140,000 - 200,000
Long Service Leave
Wellbeing Allowance
First-Year Leave
+7
Cyber Security GRC
Cyber Security GRC

c4isolutions • Sydney

On-site
AUD 140,000 - 200,000
Long Service Leave
Health & wellbeing allowance
First year leave
+6
Cyber Security SME
Cyber Security SME

Compas PTY • Canberra

On-site
AUD 120,000 - 160,000
Security Engineer (SIEM)
Security Engineer (SIEM)

Client 1 • City of Brisbane

Hybrid
AUD 140,000 - 180,000
Private health insurance
Generous annual leave entitlements
Annual incentive programme
+5