Senior GRC Specalist
Emanate Technology · Brisbane QLD ·
- Work mode
- Hybrid
- Seniority
- Senior
- Employment
- Full time
- Category
- Security
- Salary
- AUD 130,000 – 145,000 / year
A Senior GRC Specialist joins e2Cyber's cyber security team in Brisbane, maintaining the ISMS, running cyber risk assessments and audits, and ensuring compliance with frameworks like ISO 27001, Essential Eight, ASD ISM, and PCI-DSS, while reporting to leadership and engaging stakeholders.
Salary: AUD 130000 - 145000 per annum
e2Cyber is seeking an experienced Senior GRC Specialist to join a high-performing cyber security team. This role is ideal for a cyber professional who enjoys working across governance, risk, compliance, security assurance, and stakeholder engagement within a complex enterprise environment.You will play a key role in maintaining and enhancing cyber security governance frameworks, managing risk activities, supporting audits, and ensuring ongoing compliance with industry standards and regulatory requirements.
Key Responsibilities
- Lead the maintenance and continual improvement of the organisation's Information Security Management System (ISMS).
- Conduct cyber security risk assessments across systems, projects, and third-party suppliers.
- Manage cyber risk registers, treatment plans, and governance reporting.
- Coordinate internal and external audits, including evidence gathering, control reviews, and remediation activities.
- Support compliance initiatives across frameworks including ISO 27001, Essential Eight, ASD ISM, and PCI-DSS.
- Deliver cyber security awareness programs and phishing simulation activities.
- Prepare reports, metrics, and presentations for leadership and governance forums.
- Assist with policy development, standards management, and security governance activities.
- Proven experience in Cyber Security Governance, Risk & Compliance (GRC).
- Strong understanding of ISO 27001, ISO 31000, ASD ISM, Essential Eight, and cyber risk management principles.
- Experience supporting or leading security audits and compliance programs.
- Ability to engage with both technical and non-technical stakeholders.
- Experience conducting supplier and third-party security assessments.
- Strong written communication and reporting skills.
- Ability to work independently and contribute to strategic cyber security initiatives.
- CISA
- CISM
- CRISC
- CISSP
- ISO 27001 Lead Auditor
- Opportunity to work within a mature and evolving cyber security environment.
- Exposure to enterprise-wide cyber security initiatives.
- Supportive and collaborative team culture.
- Long-term career development opportunities.
- Competitive salary package and benefits.
For a confidential discussion, please contact the team at e2Cyber.
We are an inclusive employer committed to fostering a diverse and accessible workplace. We encourage applications from Aboriginal and Torres Strait Islander peoples, people with disabilities, LGBTQIA+ individuals, people of all ages, and those from culturally and linguistically diverse backgrounds.
#SCR-ben-rogalsky