GRC Analyst - 5 months
Core
Provide governance authority and oversight across the delivery of Defence ICT capabilities, ensuring alignment with security standards, risk frameworks, and compliance requirements.
Role type
GRC Analyst (Defence ICT)
Builds
Governance, risk, and compliance documentation; evidence for Commonwealth acceptance and assurance activities
Domain
Defence, National Security, ICT
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC within ICT/Defence/government, security frameworks, risk management, compliance practices, ATO/accreditation/assurance processes, technical design review from governance perspective, stakeholder engagement
Preferred skills
Defence/national security environment experience, secure ICT systems/networks/geospatial capabilities, security control frameworks, system integration in governed environments
Technologies
ATO, ATO-C, DISA
Responsibilities
Provide GRC leadership and oversight across delivery activities; Lead development and review of governance, risk and compliance documentation; Ensure alignment with Defence security requirements and Authorisation to Operate (ATO/ATO-C) frameworks; Conduct and support security architecture reviews and assurance activities; Identify, assess and manage risks, vulnerabilities and compliance gaps; Provide guidance on security controls, governance frameworks and compliance obligations; Support embedded assessor and assurance processes; Collaborate with technical teams to ensure compliance is integrated into solution design and delivery; Contribute to evidence generation to support Commonwealth acceptance and assurance activities
Seniority
Mid-level, hands-on IC
