Cyber Security GRC Analyst

FourQuarters Recruitment

City of Melbourne

On-site

AUD 148,000 - 203,000

Full time

35 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

FourQuarters Recruitment represents a well established financial services organisation in Melbourne seeking a hands-on cyber GRC specialist to uplift regulatory controls aligned to APRA CPS 230/234, NIST CSF and ISO 27001. You will assess controls, support third-party risk, map assets, conduct testing, and contribute to ISMS documentation, liaising with risk, vendor management and security teams.

Contract role with short notice start, Melbourne based, offering a competitive day rate and exposure

Qualifications

  • Experience in cyber security GRC or information security within regulated industries.
  • Knowledge of NIST CSF and ISO/IEC 27001; ISO Lead Auditor/Implementer is a plus.
  • Familiarity with APRA CPS 230/CPS 234 or similar regimes.
  • Ability to translate technical findings into business risk language for stakeholders.
  • Contract role; Melbourne-based; available on short notice.

Responsibilities

  • Assess and uplift security controls against ISO/IEC 27001 and the NIST CSF functions.
  • Support third-party risk assessments, including security due diligence and control testing.
  • Map critical operations/assets against frameworks and identify gaps.
  • Conduct control testing, evidence collection, and maturity assessments ahead of audits.
  • Contribute to ISMS documentation, policies, standards, risk treatment plans.

Skills

Cyber security GRC experience
Regulatory knowledge
Stakeholder communication
Financial services domain

Tools

NIST CSF
ISO/IEC 27001
APRA CPS 230/ CPS 234

Job description

Our client, a well established financial services organisation, is continuing its cyber security and operational resilience uplift program, aligned to APRA CPS 230 and CPS 234, and benchmarked against NIST and ISO/IEC 27001. As the business moves through third-party risk remediation and control maturity assessment, the team needs additional hands-on cyber GRC capability to maintain momentum.

This is a contract role suited to someone who has worked on a live regulatory or standards aligned cyber uplift program (CPS 230, CPS 234, NIST CSF, or ISO 27001) and can hit the ground running.

What you'll be doing
  • Assessing and uplifting security controls against ISO/IEC 27001 and the NIST CSF functions.
  • Supporting third-party/material service provider risk assessments, including security due diligence and control testing
  • Mapping critical operations and technology assets against control frameworks and identifying gaps
  • Conducting control testing, evidence collection, and maturity assessments ahead of internal and external audits
  • Contributing to ISMS documentation, policies, standards, risk treatment plans, Statements of Applicability
  • Liaising with security engineering, risk, audit, and vendor management stakeholders to close out findings
What we're looking for
  • Proven experience in a cyber security GRC or information security role within financial services or other highly regulated industries.
  • Working knowledge of NIST CSF and ISO/IEC 27001 (certification such as ISO 27001 Lead Auditor/Implementer highly regarded)
  • Exposure to APRA CPS 230/CPS 234 or comparable regulatory frameworks
  • Comfortable running control assessments and translating technical findings into risk language for stakeholders
  • Contract background strongly preferred, available to start on short notice, based in Melbourne
What's on offer
  • Competitive day rate, negotiable based on experience
  • High-profile program with genuine extension/renewal potential
  • Exposure to a live, well-resourced cyber security transformation program benchmarked against leading frameworks
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Cyber Security Analyst (ISO/NIST) - Melbourne Contract
GRC Cyber Security Analyst (ISO/NIST) - Melbourne Contract

FourQuarters Recruitment • City of Melbourne

On-site
AUD 148,000 - 203,000
Cyber GRC Analyst
Cyber GRC Analyst

Paxus • City of Brisbane

On-site
AUD 110,000 - 150,000
Senior It Security Grc Delivery Analyst
Senior It Security Grc Delivery Analyst

Linfox Pty Ltd. • City of Melbourne

On-site
AUD 120,000 - 180,000
Cyber Security Consultant (GRC)
Cyber Security Consultant (GRC)

Anitech Pty Ltd • City of Melbourne

Hybrid
AUD 120,000 - 160,000
Cyber Governance, Risk & Compliance Specialist
Cyber Governance, Risk & Compliance Specialist

Bespoke Careers • City of Brisbane

On-site
AUD 91,000 - 152,000
Technical GRC Lead
Technical GRC Lead

Decipher Bureau • Sydney

On-site
AUD 150,000 - 230,000
Cyber GRC Specialist
Cyber GRC Specialist

Client 1 • Canberra

On-site
AUD 120,000 - 150,000
14% superannuation
6 weeks paid annual leave
Mentoring & professional development
GRC Specialist
GRC Specialist

Client 1 • Canberra

On-site
AUD 110,000 - 150,000
14% superannuation
6 weeks annual leave
Professional development
+2
Cyber Security Program Manager
Cyber Security Program Manager

Natural Selection Group • City of Melbourne

On-site
AUD 140,000 - 190,000
Lead a highly visible cyber security—?
Influence enterprise-wide security, 위험
Partner with senior stakeholders
+1
Cyber GRC Manager (PSTV Cleared)
Cyber GRC Manager (PSTV Cleared)

Sirius. • Canberra

On-site
AUD 120,000 - 160,000