Cyber GRC Analyst – Government Frameworks

Whizdom

Canberra

On-site

AUD 160,000 - 190,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Whizdom is seeking a Cyber GRC Analyst to embed governance, risk and regulatory practices aligned to Australian Government frameworks such as PSPF, ISM and Essential 8 and NIST across information systems. The role reports to the Cyber GRC Manager within the cybersecurity team and focuses on implementing controls to ensure compliance and informed risk management.

The position supports authorisation activities, risk assessments, and continuous improvement of cyber security posture in heavily

Qualifications

  • Minimum 3 years working as a Cyber Security or GRC Analyst.
  • Knowledge of PSPF, ISM, Essential 8, NIST.
  • Ability to identify risks, provide risk reduction strategies, and collaborate with business teams to secure stakeholders’ approval and support.
  • Experience in enterprise security environments.
  • Experience in heavily regulated environments (e.g., federal government, telco, energy).
  • Excellent communication skills with stakeholders at varying seniorities.

Responsibilities

  • Develop, deliver and maintain security authorisation documentation (e.g., System Security Plans, Security Risk Management Plans, and Cyber Incident Response Plans) to support Government processes.
  • Implement security standards, ISM, Essential 8, NIST, etc.
  • Provide cyber security advice that assists with monitoring infrastructure components, the design of infrastructure, identify areas for improvements and assist with upgrades or enhancements as required.
  • Conduct cyber security risk assessments to identify and evaluate potential threats and vulnerabilities.
  • Provide SME recommendations and advice on compliance and regulatory requirements to support continuous improvement of cyber security posture.
  • Assist with the development of comprehensive security policies to address and mitigate risks.

Skills

GRC
Risk assessment
Regulatory compliance
Stakeholder communication
Security governance

Job description

Whizdom is seeking a Cyber GRC Analyst to embed governance, risk and regulatory practices aligned to Australian Government frameworks such as PSPF, ISM and Essential 8 and NIST across information systems. The role reports to the Cyber GRC Manager within the cybersecurity team and focuses on implementing controls to ensure compliance and informed risk management.

The position supports authorisation activities, risk assessments, and continuous improvement of cyber security posture in heavily

Get your free, confidential resume review.
or drag and drop your file here.