
Cyber Security GRC Team Lead
- Osborne Park, WA
- Permanent
- Full-time
- Lead the development, maintenance, and promotion of cyber security policies, standards, and guidelines.
- Oversee cyber risk management processes, including risk identification, analysis, treatment, and maintenance of the cyber risk register.
- Manage internal and external audit activities, collect evidence, track remediation, and ensure ongoing compliance with frameworks and regulatory obligations.
- Establish and manage third-party cyber risk assessment processes in collaboration with Procurement, Legal, and Technology stakeholders.
- Consolidate and report on cyber performance, risk indicators, and assurance findings for executive and governance audiences.
- Partner with the Data and Information Governance team to ensure alignment with data classification, retention, and privacy requirements.
- Foster a culture of learning, accountability, and collaboration.
- Demonstrated experience developing and managing policy frameworks aligned to organisational, regulatory, and industry requirements.
- Proven ability to maintain cyber risk registers, conduct risk assessments, and manage treatment plans effectively.
- Strong knowledge of NIST CSF 2.0 and the WA Government Cyber Security Policy, with experience in tracking and reporting compliance.
- Demonstrated experience leading internal and external audits, including evidence collection, control effectiveness reviews, and remediation tracking.
- Strong capability in assessing vendor and third-party cyber risk, working collaboratively to mitigate exposures.
- A proven track record of uplifting cyber awareness, influencing behaviours, and embedding security into business decision-making.
- Demonstrated ability to simplify complex concepts, engage stakeholders at all levels, and present compelling insights to governance forums.
- Industry experience in cyber security, with the ability to demonstrate leadership and technical depth. A tertiary qualification in information technology or cyber security, and/or relevant professional certifications, will be highly regarded.
- Real influence - help embed governance practices that strengthen our cyber resilience.
- Flexibility that works for you - hybrid work options, flexible hours, and the tools to work effectively anywhere.
- Investment in your growth - a personal learning & development budget, and access to leading tools and training.
- A workplace built for people - brand-new offices with wellness spaces, end-of-trip facilities, and modern collaboration zones.
- Recognition that matters - competitive remuneration, employee discounts, and reward programs that celebrate your achievements.
- Purpose and pride - play a critical role in safeguarding an organisation with deep roots in the WA community.