Cyber Security & GRC Analyst

David Jones Ltd.

City of Melbourne

On-site

AUD 110,000 - 150,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

David Jones is seeking a Cyber Security & GRC Analyst to blend hands-on security operations with governance, risk and compliance expertise. You will monitor security events, coordinate remediation and help embed secure behaviours across the organisation.

Working with Technology and the business, you will translate complex security information into practical actions, support audits, and contribute to a robust cyber control environment that enables safe innovation.

Qualifications

  • 3+ years of experience in cyber security operations or GRC
  • Experience with security frameworks such as Essential Eight, NIST CSF, ISO 27001/27002 and PCI DSS
  • Experience with vulnerability management, incident response and remediation tracking
  • Strong written communication and ability to translate security findings for business stakeholders
  • Proactive, collaborative mindset and stakeholder engagement skills

Responsibilities

  • Monitor and triage security alerts, events and incidents with escalation as needed
  • Coordinate vulnerability scanning and remediation prioritisation with system owners
  • Support identity and access management activities including access reviews
  • Maintain cyber security policies, standards and control framework
  • Coordinate evidence and responses for internal and external audits
  • Provide practical security guidance to Technology teams and stakeholders
  • Assist with security awareness campaigns, training and phishing simulations

Skills

Cyber security operations
GRC / risk management
Incident response
Vulnerability management
Access management
Policy development
Security awareness training
Audit coordination
Stakeholder engagement
Security reporting

Education

Relevant cyber security/IT risk qualification
Industry certifications encouraged

Tools

Microsoft security solutions
Proofpoint
CrowdStrike
Cortex
Rapid7
Tenable

Job description

Protect what matters. Strengthen cyber resilience. Help shape a security-conscious culture.

At David Jones, we are committed to creating secure, seamless and trusted experiences for our customers and our people. We are looking for a Cyber Security & GRC Analyst who can combine hands‑on security operations with practical governance, risk and compliance expertise.


This is a broad and highly collaborative role where you will monitor and respond to security events, coordinate vulnerability remediation, strengthen our cyber control environment and help embed secure behaviours across the organisation.


Working across Technology and the broader business, you will translate technical security information into clear, risk-based actions that protect our operations while enabling innovation and progress.


What will your day look like?

In this role, you will:



  • Monitor and triage security alerts, events and reported concerns, escalating and coordinating responses in line with established processes

  • Support the investigation of security incidents, including evidence gathering, root‑cause analysis and identification of recurring issues

  • Coordinate vulnerability scanning and work with system owners to prioritise remediation, patching and risk treatment

  • Track vulnerabilities, control gaps and remediation actions through to closure

  • Support identity and access management activities, including access reviews, privileged access checks and least‑privilege assurance

  • Maintain cyber security policies, standards, procedures and the security control framework

  • Support cyber and technology risk assessments, control assurance activities and continuous control monitoring

  • Coordinate evidence and stakeholder responses for internal and external audits

  • Help maintain alignment with frameworks and obligations including the Essential Eight, NIST Cybersecurity Framework, ISO 27001/27002 and PCI DSS

  • Coordinate cyber security awareness campaigns, training and phishing simulations

  • Prepare operational and GRC reporting across incidents, vulnerabilities, risks, controls, audits and awareness measures

  • Provide clear, practical security advice to Technology teams, project teams and stakeholders across the business

  • Identify opportunities to automate, simplify and strengthen security processes, controls and reporting


What will you need to thrive?

You will bring approximately three years of experience across cyber security operations, cyber GRC, technology risk, audit or a comparable role combining these disciplines.


You will also have:



  • Hands‑on experience in security alert triage, incident analysis, vulnerability management and remediation coordination

  • Experience supporting cyber risk assessments, control assurance, policy maintenance, audits and remediation tracking

  • Working knowledge of security frameworks and standards such as the Essential Eight, NIST Cybersecurity Framework, ISO 27001/27002 and PCI DSS

  • Exposure to security technologies across identity, email, endpoint, cloud and vulnerability management

  • Experience with Microsoft security solutions and tools such as Proofpoint, CrowdStrike, Cortex, Rapid7 or Tenable

  • The ability to analyse security information, identify patterns and translate technical findings into practical business actions

  • Strong stakeholder engagement, organisation and follow‑through

  • The ability to balance operational security priorities with scheduled governance and compliance activities

  • Strong written communication skills, with the ability to develop concise policies, procedures, reports, training materials and management updates

  • Experience delivering cyber awareness communications, training or phishing simulations

  • A relevant qualification in cyber security, information technology, risk or a related discipline, or equivalent practical experience


Relevant industry certifications, or active progress toward certification, will be highly regarded.


Why join David Jones?

Our purpose is to inspire like no other, and our people bring this to life every day.


At David Jones, you will join a culture where people are encouraged to be customer obsessed, empowered, inclusive and innovative. You will have the opportunity to work across a complex and iconic retail organisation, partnering with diverse teams to improve cyber resilience and build greater security capability across the business.


This role offers the chance to broaden your exposure across both cyber security operations and GRC, contribute to meaningful security improvements and help shape a culture where protecting our customers, people and business is everyone’s responsibility.


Ready to inspire like no other?

If you are curious, collaborative and motivated by turning cyber risk into practical action, we would love to hear from you.


David Jones is committed to creating an inclusive workplace where everyone feels respected, valued and empowered to thrive. We welcome applications from people of all backgrounds, experiences and perspectives.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security & GRC Analyst
Cyber Security & GRC Analyst

David Jones • City of Melbourne

On-site
AUD 110,000 - 140,000
Cyber Security & GRC Analyst: Drive Risk & Resilience
Cyber Security & GRC Analyst: Drive Risk & Resilience

David Jones • City of Melbourne

On-site
AUD 110,000 - 140,000
Cyber Risk & GRC Specialist — Operations, Audits & Compliance
Cyber Risk & GRC Specialist — Operations, Audits & Compliance

David Jones Ltd. • City of Melbourne

On-site
AUD 110,000 - 150,000
Cyber Security Analyst
Cyber Security Analyst

Blackroc • City of Brisbane

On-site
AUD 110,000 - 160,000
Cyber Security Manager
Cyber Security Manager

Xceltium • Sydney

Hybrid
AUD 150,000 - 190,000
Onsite parking
Hybrid work arrangement
Loss Prevention Manager | Doncaster
Loss Prevention Manager | Doncaster

David Jones Ltd. • City of Manningham

On-site
AUD 100,000 - 140,000
Annual bonus
Employee discounts
Birthday leave
+5
Cyber GRC Analyst
Cyber GRC Analyst

Client 1 • City of Brisbane

On-site
AUD 110,000 - 160,000
Private health insurance
Generous annual leave entitlements
Annual incentive programme
+5
Cyber GRC Analyst
Cyber GRC Analyst

Paxus • City of Brisbane

On-site
AUD 110,000 - 150,000
Cyber Security Consultant - GRC
Cyber Security Consultant - GRC

Teamified • Canberra

On-site
AUD 70,000 - 110,000
Senior Cloud Engineer
Senior Cloud Engineer

CyberCX • Central Coast Council

On-site
AUD 100,000 - 140,000
Flexible working in a hybrid arrangement
Additional paid leave options
Health & Wellbeing program
+2