Cyber Governance, Risk and Compliance Analyst
Core
Maintain security compliance of classified mission-critical networks and support system accreditation within a Microsoft Azure environment.
Role type
Cybersecurity Governance, Risk and Compliance (GRC) Analyst
Builds
Security accreditation documentation, risk management plans, and compliance evidence for classified systems
Domain
National Security / Cybersecurity / Cloud Security (Azure)
Required skills
Australian Government Information Security Manual (ISM) knowledge, Protective Security Policy Framework (PSPF) knowledge, security accreditation processes, risk assessment, compliance auditing, cloud security concepts, documentation management, incident investigation support
Preferred skills
IRAP assessment experience, CRISC/CISA/CGRC certification, ISO 27001 Lead Auditor, ITIL 4 Foundations, Microsoft Azure certifications
Technologies
Microsoft Azure
Responsibilities
Develop and maintain System Security Plans (SSP) and Security Risk Management Plans (SRMP); Conduct security compliance reviews and audits; Identify and manage cybersecurity risks and control gaps; Provide cybersecurity advice to program and operational teams; Participate in security incident investigations; Deliver cybersecurity training and awareness; Interface with client cybersecurity stakeholders
Seniority
Mid-level, hands-on IC
