GRC Specialist
U&U Recruitment Partners · Brisbane QLD · onsite
Are you a cyber security GRC professional who enjoys working at the intersection of risk, governance, policy, technology and operational environments?
We are seeking a GRC Specialist to join a Government department and play a key role in strengthening its cyber security governance and compliance capability across both Information Technology (IT) and Operational Technology (OT) environments.
This is an opportunity to work in a complex and highly operational environment where cyber security has a direct connection to safety, security and frontline operations.
The opportunity:
- Working within the Security Standards Unit, you will support the development and implementation of a unified Information Security Management System (ISMS), including policies, standards, processes, governance and risk management;
- You will work closely with frontline operational teams, technology specialists, policy and process owners, vendors, other government commands and external stakeholders to ensure cyber security requirements are understood, embedded and effectively governed; and
- The role will give you the opportunity to influence how cyber security risk and compliance are managed across a complex environment, while also contributing to the maturity of the organisation's broader security framework.
What you'll be doing:
- Support the development, implementation and ongoing maturity of the IT/OT Information Security Management System;
- Develop and maintain cyber security policies, standards, processes, templates and framework artefacts;
- Undertake information and cyber security risk assessments across complex Operational Technology environments;
- Assess security controls against frameworks including ISO 27001, Essential Eight, Queensland Protective Security Framework and IS18;
- Support the integration of electronic security and cyber security requirements into the ISMS;
- Work with operational teams on cyber security requirements for planned works and projects; and
- Establish governance and compliance processes to monitor policy implementation and ongoing performance.
What we're looking for:
We're looking for a well-rounded GRC professional who can operate comfortably between technical cyber security, policy, risk and business stakeholders.
You'll ideally bring:
- Strong experience in cyber security governance, risk and compliance;
- Experience developing or implementing ISMS frameworks, policies, standards and controls;
- A good understanding of both information and cyber security, with exposure to Operational Technology (OT) highly regarded;
- Strong risk assessment, compliance monitoring and assurance capability;
- Excellent written communication skills, with the ability to produce high-quality briefing notes, business cases, reports, presentations and policy documentation; and
- Strong stakeholder engagement skills and the ability to build relationships across technical, operational and executive environments.
Your background:
Experience within a large, complex or highly regulated environment would be highly regarded.
Exposure to government, corrections, criminal justice, critical infrastructure, utilities, healthcare or another operationally complex environment would be advantageous.
Desirable qualifications or experience include:
ISO 27001 Lead Implementer or Lead Auditor
Why this role?
This is a chance to work on something with genuine enterprise impact. You'll be helping to shape the way cyber security governance, risk and compliance operates across a complex IT and OT environment, where security requirements have a direct connection to operational outcomes.
You'll work with a diverse range of stakeholders, have exposure to senior decision-makers and play an important role in strengthening the organisation's security maturity.
If you're a GRC professional who enjoys making frameworks practical, navigating complexity and working with people across both technology and operational environments, we'd like to hear from you.
How to apply:
For more information or a confidential discussion please call Nicky Stanway at u&u on 3232 9133 quoting reference number 46677.
At u&u Recruitment Partners, we value diversity, equity and inclusion. We welcome applications from Aboriginal and Torres Strait Islander people, people with diverse cultural and linguistic backgrounds and people with disability.
Should you require reasonable adjustments throughout the recruitment process (including alternate formats to apply), or have a preferred method of communication, we encourage you to make a request via adjustments@uandu.com or contact u&u on 07 3232 9100 to discuss. In response to these requests, we will collaborate closely with you to implement the appropriate adjustments.
Additionally, for a barrier-free and inclusive online experience, you can access u&u’s opportunities using accessibility software Recite Me at https://www.uandu.com/jobs.
Please submit your resume in Word format only.