Cyber Security & GRC Analyst

David Jones

City of Melbourne

On-site

AUD 110,000 - 140,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

David Jones is seeking a Cyber Security & GRC Analyst to blend hands-on security operations with governance, risk and compliance expertise. You will monitor events, coordinate remediation and help embed secure behaviours across the organisation.

In this role you will translate technical findings into practical actions, support audits, and contribute to the cyber control framework while collaborating with Technology and business teams.

Qualifications

  • Three years of experience across cyber security operations, GRC, technology risk, audit or related discipline.
  • Experience in security alert triage, incident analysis and remediation coordination.
  • Knowledge of security frameworks such as Essential Eight, NIST CSF, ISO 27001/27002, PCI DSS.
  • Exposure to identity, email, endpoint, cloud security technologies.

Responsibilities

  • Monitor and triage security alerts, events and concerns; escalate and coordinate responses.
  • Investigate security incidents; perform root-cause analysis and identify recurring issues.
  • Coordinate vulnerability scanning and partner with system owners for remediation and patching.
  • Track vulnerabilities, control gaps and remediation actions through to closure.
  • Assist with risk assessments, control assurance and audit preparations.

Skills

Cyber security operations
GRC
Incident analysis
Vulnerability management
Stakeholder engagement
Policy maintenance
Security awareness
Phishing simulations

Education

Bachelor's degree in cyber security / information technology

Tools

Proofpoint
CrowdStrike
Cortex
Rapid7
Tenable

Job description

Protect what matters. Strengthen cyber resilience. Help shape a security-conscious culture.

At David Jones, we are committed to creating secure, seamless and trusted experiences for our customers and our people. We are looking for a Cyber Security & GRC Analyst who can combine hands-on security operations with practical governance, risk and compliance expertise.

This is a broad and highly collaborative role where you will monitor and respond to security events, coordinate vulnerability remediation, strengthen our cyber control environment and help embed secure behaviours across the organisation.

Working across Technology and the broader business, you will translate technical security information into clear, risk-based actions that protect our operations while enabling innovation and progress.

What will your day look like?

In this role, you will:

  • Monitor and triage security alerts, events and reported concerns, escalating and coordinating responses in line with established processes
  • Support the investigation of security incidents, including evidence gathering, root-cause analysis and identification of recurring issues
  • Coordinate vulnerability scanning and work with system owners to prioritise remediation, patching and risk treatment
  • Track vulnerabilities, control gaps and remediation actions through to closure
  • Support identity and access management activities, including access reviews, privileged access checks and least-privilege assurance
  • Maintain cyber security policies, standards, procedures and the security control framework
  • Support cyber and technology risk assessments, control assurance activities and continuous control monitoring
  • Coordinate evidence and stakeholder responses for internal and external audits
  • Help maintain alignment with frameworks and obligations including the Essential Eight, NIST Cybersecurity Framework, ISO 27001/27002 and PCI DSS
  • Coordinate cyber security awareness campaigns, training and phishing simulations
  • Prepare operational and GRC reporting across incidents, vulnerabilities, risks, controls, audits and awareness measures
  • Provide clear, practical security advice to Technology teams, project teams and stakeholders across the business
  • Identify opportunities to automate, simplify and strengthen security processes, controls and reporting

What will you need to thrive?

You will bring approximately three years of experience across cyber security operations, cyber GRC, technology risk, audit or a comparable role combining these disciplines.

You will also have:

  • Hands-on experience in security alert triage, incident analysis, vulnerability management and remediation coordination
  • Experience supporting cyber risk assessments, control assurance, policy maintenance, audits and remediation tracking
  • Working knowledge of security frameworks and standards such as the Essential Eight, NIST Cybersecurity Framework, ISO 27001/27002 and PCI DSS
  • Exposure to security technologies across identity, email, endpoint, cloud and vulnerability management
  • Experience with Microsoft security solutions and tools such as Proofpoint, CrowdStrike, Cortex, Rapid7 or Tenable
  • The ability to analyse security information, identify patterns and translate technical findings into practical business actions
  • Strong stakeholder engagement, organisation and follow-through
  • The ability to balance operational security priorities with scheduled governance and compliance activities
  • Strong written communication skills, with the ability to develop concise policies, procedures, reports, training materials and management updates
  • Experience delivering cyber awareness communications, training or phishing simulations
  • A relevant qualification in cyber security, information technology, risk or a related discipline, or equivalent practical experience

Relevant industry certifications, or active progress toward certification, will be highly regarded.

Why join David Jones?

Our purpose is to inspire like no other, and our people bring this to life every day.

At David Jones, you will join a culture where people are encouraged to be customer obsessed, empowered, inclusive and innovative. You will have the opportunity to work across a complex and iconic retail organisation, partnering with diverse teams to improve cyber resilience and build greater security capability across the business.

This role offers the chance to broaden your exposure across both cyber security operations and GRC, contribute to meaningful security improvements and help shape a culture where protecting our customers, people and business is everyone’s responsibility.

Ready to inspire like no other?

If you are curious, collaborative and motivated by turning cyber risk into practical action, we would love to hear from you.

Apply now and help us build secure, resilient and trusted experiences across David Jones.

David Jones is committed to creating an inclusive workplace where everyone feels respected, valued and empowered to thrive. We welcome applications from people of all backgrounds, experiences and perspectives.

Be careful - Don’t provide your bank or credit card details when applying for jobs. Don't transfer any money or complete suspicious online surveys. If you see something suspicious, report this job ad .

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security & GRC Analyst
Cyber Security & GRC Analyst

David Jones Ltd. • City of Melbourne

On-site
AUD 110,000 - 150,000
Loss Prevention Manager | Doncaster
Loss Prevention Manager | Doncaster

David Jones Ltd. • City of Manningham

On-site
AUD 100,000 - 140,000
Annual bonus
Employee discounts
Birthday leave
+5
Cyber Security & GRC Analyst: Drive Risk & Resilience
Cyber Security & GRC Analyst: Drive Risk & Resilience

David Jones • City of Melbourne

On-site
AUD 110,000 - 140,000
Cyber Risk & GRC Specialist — Operations, Audits & Compliance
Cyber Risk & GRC Specialist — Operations, Audits & Compliance

David Jones Ltd. • City of Melbourne

On-site
AUD 110,000 - 150,000
Cyber Security Adviser - Risk and Compliance Analyst
Cyber Security Adviser - Risk and Compliance Analyst

Clicks IT Recruitment • City of Melbourne

On-site
AUD 165,000 - 220,000
Cyber GRC Analyst
Cyber GRC Analyst

Paxus • City of Brisbane

On-site
AUD 110,000 - 150,000
Senior Security Risk Analyst
Senior Security Risk Analyst

Credit Corp • Australia

Hybrid
AUD 150,000 - 190,000
Wellbeing support (EAP)
Gym discounts
Health insurance benefits
+4
Defence Cyber SOC Analyst – Onsite Sydney
Defence Cyber SOC Analyst – Onsite Sydney

C4i Solutions • Sydney

On-site
AUD 90,000 - 120,000
Long Service Leave
Health & wellbeing allowance
First year leave (5 days)
+6
Loss Prevention Officers| Aus & NZ
Loss Prevention Officers| Aus & NZ

David Jones • Canberra

On-site
AUD 56,000 - 72,000
Employee discounts
Incentive scheme
Training & development
+1
Security Risk Analyst
Security Risk Analyst

Credit Corp • Sydney

Hybrid
AUD 130,000 - 170,000
Flexible hybrid working
Health insurance benefits
Novated leasing options
+2