Cyber GRC Lead

CreditorWatch

Sydney

Hybrid

AUD 180,000 - 240,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Fitness First gym membership
Barista-made coffee and breakfast
Wellness days
Monthly massages
Employee share scheme

Job summary

CreditorWatch is seeking a hands-on Cyber GRC Lead to own and mature our information security management and assurance framework. You will lead cyber risk management, policy governance, audit readiness and third-party resilience while partnering with Engineering, Legal, IT and business leaders to ensure decisions are evidence-based.

You will report to the Head of IT & InfoSec in a hybrid role, based out of our Sydney CBD office.

Qualifications

  • Proven experience leading or owning Cyber Security GRC programs within SaaS, technology, financial services or regulated environments.
  • Strong experience with ISMS, ISO 27001 and/or SOC 2, including audit readiness, evidence management and continuous improvement.
  • Deep knowledge of cyber risk, controls, policy governance, third-party risk and customer assurance.
  • Ability to translate regulatory, contractual and framework requirements into practical, business-owned controls.
  • Strong understanding of incident management, business continuity, disaster recovery and operational resilience.
  • Exposure to CPS 230, CPS 234 and ASD Essential Eight; AI governance/ISO 42001 experience desirable.
  • Experience with GRC and workflow tools such as Drata, Jira, Confluence or equivalent.

Responsibilities

  • Cyber GRC Strategy & Operating Model: Own the roadmap aligned to priorities, risk appetite and regulatory requirements.
  • Risk, Controls & Policy Governance: Manage the information security risk framework and policy suite; establish ownership and testing.
  • Assurance, Audits & Certifications: Lead readiness for ISO 27001 and SOC 2; prepare for additional obligations and certifications.
  • Third-Party Risk, Resilience & Incident Governance: Oversee third-party risk management and incident readiness with engineering and IT.
  • AI Governance & Business Enablement: Lead governance for AI use cases and ensure practical security/compliance requirements.

Skills

Cyber GRC leadership
ISMS/ISO 27001
SOC 2 readiness
Third-party risk
Incident management

Tools

Drata
Jira
Confluence

Job description

Newly Create Role!!

Who are we?

So you might ask, who’s CreditorWatch? We are a leading Australian data and technology company that provides businesses with access to unique data and innovative products. By using our platform, our customers can confidently manage their commercial relationships, improve productivity and reduce financial risk.

As a commercial credit reporting bureau, we offer a complete suite of credit reporting products and data insights covering the entire customer lifecycle—from customer onboarding and credit decision automation to credit risk management and automated collections.

We were established in 2010 and have been named one of AFR’s Top 10 Best Places to Work, as well as certified by Great Place to Work consecutively across 2022–2025.

We are scaling at pace, making this an exciting time to join CreditorWatch.

Our Purpose

Empower Australian businesses to trade confidently with their customers.

Our Mission

We aim to be number one in our industry by delivering unique data insights and innovative products.

Your Role & Team

As CreditorWatch strengthens its core cyber governance,riskand compliance capability, we areestablishinga Cyber GRC Lead role to own and mature our information security management and assurance program.

This is a hands‑on leadership role responsible for turning regulatory, certification,customerand business expectations into a practical, sustainable control environment. You will lead cyber risk management, assurance, policy governance, audit readiness, third-partysecurityand resilience activities, while building strong ownership across the business.

You will work closely with Engineering, Legal,P&C,IT,and business leaders to ensure cyber risk isunderstood,decisions are evidence-based, and controlsoperateeffectively. The role is accountable for the Cyber GRCprogram, butsucceeds by enabling control owners rather than becoming a central bottleneck.

You’ll report directly to our Head of IT & InfoSec.

Please note, it's a full‑time opportunity offering hybrid working conditions out of our Sydney CBD Office.

Some of your responsibilities include and are not limited to:

Cyber GRC Strategy & Operating Model

  • Own and deliver the Cyber GRC roadmap, aligned to business priorities, risk appetite and regulatory requirements.
  • Establish clear governance, accountability, reporting and measures of effectiveness.
  • Lead and develop Cyber GRC capability, including internal and external stakeholders.

Risk, Controls & Policy Governance

  • Own the information security risk management framework and register, including risk assessment, treatment, acceptance and reporting.
  • Oversee the information security policy framework, ensuring policies, standards and procedures remain current and effective.
  • Establish sustainable control ownership, testing and remediation practices.

Assurance, Audits & Certifications

  • Lead ongoing readiness and compliance for ISO 27001 and SOC 2, including audit planning, evidence coordination, control testing and remediation.
  • Develop readiness for additional obligations and certifications, including ISO 42001, CPS 230, CPS 234 and the ASD Essential Eight.
  • Manage audit relationships, findings and customer/partner security assurance requests.

Third-Party Risk, Resilience & Incident Governance

  • Own the cyber components of third-party risk management, including due diligence, reassessments and security requirements.
  • Provide governance oversight across cyber incident readiness, business continuity, disaster recovery and operational resilience.
  • Partner with Engineering, DevOps, IT and Security Engineering to translate risks and control gaps into practical remediation plans.

AI Governance & Business Enablement

  • Lead responsible AI governance, including policy, risk, assurance and accountability.
  • Establish proportionate governance and guardrails for approved AI use cases.
  • Promote security and compliance as business enablers through clear, practical and streamlined requirements.
Our ideal candidate
  • Proven experience leading or owning Cyber Security GRC programs within SaaS, technology, financial services or regulated environments.
  • Strong experience with ISMS, ISO 27001 and/or SOC 2, including audit readiness, evidence management, findings and continuous improvement.
  • Strong knowledge of cyber risk, controls, policy governance, third-party risk and customer assurance.
  • Ability to translate regulatory, contractual and framework requirements into practical, business-owned controls.
  • Strong understanding of incident management, business continuity, disaster recovery and operational resilience.
  • Exposure to CPS 230, CPS 234 and the ASD Essential Eight is highly regarded; AI governance/ISO 42001 experience is desirable.
  • Experience with GRC and workflow tools, such as Drata, Jira, Confluence or equivalent.
  • Strong communication and stakeholder management skills, with the ability to challenge constructively and make complex risk easy to understand.
  • Hands‑on and commercially minded, comfortable balancing strategy, stakeholder leadership and day‑to‑day program execution.
More than just work

Keep Active –All employees get a Fitness First Platinum gym membership.

Daily Fuel –Barista‑made coffee, breakfast, snacks, lunches and drinks on us – we got you!

Phone Credits - We pay you $50 per month to put towards your plans - how good.

Wellness Days –Receive an additional day off each month. Whether you’re pursuing physical activities, cultivating your mental wellbeing or supporting your community… this is your time to switch off from work.

Monthly Massages –We offer monthly in‑house massages to soothe those sore spots and tight knots. Poor posture? Stressful week? We get it.

Bonus Shares –We offer our dedicated employees’ performance‑based bonuses. Our employees are also permitted to gain access to our bespoke Employee Share Scheme, giving you the rare opportunity to invest in a growing technology company.

Fun Activities –We love escaping the workplace to do fun stuff. Whether its pasta‑making, sailing classes, touch footy, winery tours, go karting or relaxing on the company boat (yeah… we own a boat) – these monthly team building activities will keep you feeling valued and connected.

Legal Services –Our employees get access to free legal services – from conveyancing and property advice to legal assistance around wills, trusts, powers of attorney and more. We make life easier for you, saving you time, money and unnecessary headaches.

Our Values

The 1%’ers add up –Your commitment to going that one step further sets us apart, as we believe that small efforts or improvements in any aspect of our work collectively lead to significant success.

We are dependable and trustworthy –Our clients are everything to us and we are passionate about maintaining and delivering reliable and trusted services to them.

We are committed to growth –Our success comes from our ability to grow and adapt; both collectively and individually. We set the bar high to ensure we continue to innovate and exceed expectations. We are dedicated to the development of our business and our people.

Our people make the difference –Just as we help small businesses think big, we help our employees achieve their aspirations. We provide our people with challenges and opportunities, supporting them to live their best lives.

Recruitment Process – We like to keep it simple!

  1. Phone Screening –A deep dive into the company, role and experience required, including a thorough review of your match to the role – let’s get to know each other and ensure the opportunity is a match!
  2. Hiring Manager Meeting –This is an opportunity to showcase why your background and skill set aligns to the role and ask questions – be as curious as you want!
  3. Functional Meeting – Here you’ll be set up with a take home case‑challenge that is designed to look into the way you think and approach certain situations.
  4. Values Meeting –We’d love to hear why CreditorWatch and see how you’d fit into our world.
We are committed to you

We offer a fantastic culture with open communication and rewards and recognition that include probation celebrations, all‑staff birthday and service anniversary celebrations.

We are an equal opportunity employer and committed to excellence through diversity. We do not discriminate on race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevOps Engineer
Senior DevOps Engineer

CreditorWatch • Sydney

Hybrid
AUD 180,000 - 230,000
Fitness First Platinum gym membership
Barista coffee, breakfasts and snacks
Phone credits $50/month
+5
Business Development Manager (FinTech) - NSW
Business Development Manager (FinTech) - NSW

Creditorwatch • Council of the City of Sydney

Hybrid
AUD 100,000 - 150,000
Fitness membership
Coffee & meals
Phone stipend
+5
SaaS Account Manager – Renewals & Upsell (Hybrid Sydney)
SaaS Account Manager – Renewals & Upsell (Hybrid Sydney)

Creditorwatch • Sydney

Hybrid
AUD 90,000 - 120,000
Fitness first gym membership
Barista-made coffee and meals
Phone credits $50/mo
+5
Senior Product Specialist (SaaS)
Senior Product Specialist (SaaS)

CreditorWatch • Sydney

Hybrid
AUD 100,000 - 150,000
Gym membership
Coffee & meals
Phone allowance
+4
Business Development Manager (FinTech) - VIC
Business Development Manager (FinTech) - VIC

Creditorwatch • City of Melbourne

On-site
AUD 90,000 - 150,000
Fitness gym membership
Coffee & meals provided
Phone credits
+5
Security Engineer (SaaS)
Security Engineer (SaaS)

CreditorWatch • Sydney

Hybrid
AUD 140,000 - 210,000
Gym membership
Free coffee/services
Phone allowance
+5
Account Manager
Account Manager

Creditorwatch • Sydney

On-site
AUD 90,000 - 120,000
Fitness first gym membership
Barista-made coffee and meals
Phone credits $50/mo
+5
Business Development Manager (Corporate) (SaaS) - VIC
Business Development Manager (Corporate) (SaaS) - VIC

CreditorWatch • City of Melbourne

Hybrid
AUD 70,000 - 90,000
Fitness First Platinum gym membership
Barista-made coffee, snacks, lunches
Phone credits ($50/month)
+5
Talent Acquisition Partner (Contract)
Talent Acquisition Partner (Contract)

Creditorwatch • Sydney

Hybrid
AUD 90,000 - 110,000
Fitness membership
Coffee, breakfast, snacks and drinks
Phone credits
+5
Account Manager (FinTech) - NSW
Account Manager (FinTech) - NSW

CreditorWatch • Council of the City of Sydney

Hybrid
AUD 90,000 - 130,000
Fitness First gym membership
Barista-made coffee, snacks, lunches,
Monthly $50 allowance
+6