A complete application in a minute — tailored resume and cover letter, ready to send.
Jenny Barbour IT And Project Recruitment in Port Melbourne is seeking an IT GRC Analyst to support a major digital transformation within a highly regulated setting. You will identify control objectives, document walkthroughs, and validate risk treatment closures, working with IT, security and business teams.
You will develop RACMs, define control objectives, and lead control testing, producing audit-quality risk documentation and reports while engaging stakeholders across technical and senior
Jenny Barbour IT And Project Recruitment - Port Melbourne VIC
An exciting opportunity for an IT GRC Analyst to join a high-profile digital transformation program within a complex and highly regulated environment.
Working closely with senior stakeholders and cross-functional teams, you will identify control objectives, document process walkthroughs, identify and document expected and existing controls, develop test procedures, and validate the closure of risk treatment plans for high-priority risks.
Demonstrated experience across IT risk, controls, governance, audit or GRC, with strong knowledge of Information Technology General Controls (ITGCs), application controls and control testing.
Hands-on experience developing Risk and Control Matrices (RACMs), defining control objectives and assessing control design and operating effectiveness.
Proven ability to develop and perform IT control testing, identify control gaps, recommend improvements and validate remediation activities and supporting evidence.
Strong experience documenting processes, controls, policies and procedures and producing audit-quality GRC reports and risk documentation.
Excellent stakeholder engagement skills, with the ability to work effectively with IT, security, technical and senior business stakeholders.
Experience working in regulated or complex environments such as Defence, Aerospace, Manufacturing, Financial Services or Utilities is highly desirable.
Relevant qualifications or certifications such as CISA, CRISC, CISM or ISO 27001 will be highly regarded.
Knowledge of NIST, COBIT, ISO 27001 or ISO 31000 is advantageous.