- Staff benefits including 5 weeks leave and Salary Packaging
- We are committed to your success and will support you
About the opportunity
We are seeking a full-time, permanent Technical Security and Compliance Officer to coordinate cybersecurity governance, risk, compliance, assurance and improvement across internal teams and our managed service provider.
You will translate organisational risks, regulatory obligations and business needs into a prioritised roadmap with clear owners, milestones, evidence and treatment actions. As a key contact for auditors, partners and stakeholders, you will provide clear reporting, prompt follow-up and audit-ready evidence.
Tasks include
- Maintain the security and compliance roadmap, remediation backlog, priorities, dependencies, owners, target dates and delivery status with ICT leadership.
- Coordinate security audits and assurance, including evidence validation, secure sharing, stakeholder follow-up, and tracking findings and actions to closure.
- Test and report on assigned controls across Microsoft 365, identity, endpoint, application and data environments; work with control owners and the MSP to remediate gaps and verify closure.
- Maintain and exercise incident response and disaster recovery playbooks, contacts, escalation paths and communications; coordinate post‑incident reviews and close corrective actions.
- Maintain security policies, standards, control documentation, risk and exception registers, compliance obligations and governance reporting.
- Coordinate security risk assessments for projects, suppliers and material technology changes, and support organisation‑wide security awareness and compliance.
Role requirements
- Experience in cybersecurity governance, risk, compliance, control assurance, audit coordination and technology risk management; security product or control portfolio experience is desirable.
- Knowledge of the ASD Essential Eight, security frameworks, access governance, privacy, risk and audit evidence, and the ability to convert requirements into testable controls.
- Experience coordinating internal teams, managed service providers, auditors and specialist vendors to deliver security outcomes.
- Knowledge of Microsoft 365 security and compliance, including identity, privileged access, endpoints, data protection, logging, monitoring and reporting.
- Strong documentation, analysis, prioritisation and communication skills, with the ability to translate technical risks into practical business actions.
- Relevant qualifications or certifications in cybersecurity, IT, risk, audit or compliance are desirable.
- The successful candidate must meet all role‑specific pre‑employment screening and probity requirements.
- Flexible Work: A mix of office, community and remote work.
- Salary Packaging: $15,900 plus $2,650 for entertainment through not‑for‑profit salary packaging.
- Parental Leave: 14 weeks’ paid maternity leave.
- Learning Support: Ten days’ development leave plus a $1,000 allowance.
- Wellness: Fitness Passport, reduced health and general insurance, and Perkbox discounts.
- Professional Support: Access to clinical services colleagues across NSW, QLD and ACT, with peer supervision.
- Accessibility and Wellbeing: Tailored adjustments, flexible options, a psychologically safe workplace and staff networks.
Diversity and Inclusion Statement
Northcott actively promotes diversity and inclusion in the recruitment process and throughout employment. We are committed to providing a workplace where every person is valued, respected and supported to progress. Northcott welcomes applications from and ensures no one is disadvantaged on the basis of their Aboriginal and Torres Strait Islander identity, culture, LGBTQIA+ identity, neurodivergence, disability, gender, age, religion or caring responsibilities. We welcome bilingual and multilingual applicants, recognising the important role language and cultural understanding play in connecting with and supporting our diverse communities. If you require any adjustments to participate in the recruitment process, have a preferred contact method, or need information provided in an alternative format, please contact recruitment at recruitment@northcott.com.au We are here to support you — reasonable adjustments are available throughout the application process and are also available to employees in their roles beyond recruitment.