Security Governance Officer

MSSP (Managed Security Service Provider)
|
12-Month Fixed Term Contract
Melbourne (Hybrid)
$140k to $160k + super

Company overview

Our client is a pioneering Australian networking organisation known for building world-class infrastructure. They enable seamless data access and global collaboration to drive cutting-edge research across various disciplines. Their work enhances architecture capabilities and strengthens cybersecurity practices across the enterprise. They play a key role in driving innovation and maintaining robust cybersecurity measures.

Job Purpose

The primary purpose of this role is to support the Head of Cyber Security in aligning technology solutions, policies, and procedures with industry best practices and regulatory requirements. This role focuses on developing, implementing, and continuously improving governance, risk, and compliance (GRC) programmes, especially related to ISO27001 certification and SOC 2 reporting. The role is crucial in maintaining a strong security posture, fostering collaboration across teams, and ensuring the protection of sensitive data and system integrity.

Responsibilities

  • Maintain Information Security policies and standards in line with industry-recognised frameworks such as ISO27001, ASD Essential 8, ISM, and NIST.
  • Assist in developing and revising information security policies and procedures for SOC operations to align with ISO 27001 standards.
  • Continuously monitor the effectiveness of security controls in the SOC environment, collect feedback, and recommend improvements to ensure compliance and enhance security.
  • Experience with security risk management frameworks and processes like ISO31000, ISO27001, ISM, ASD8, and NIST, including developing documentation.

Requirements

  • Strong problem-solving skills, especially around process improvement and control implementation.
  • Ability to promote collaboration between teams by removing roadblocks and fostering communication.
  • Excellent communication skills, able to present ideas and outcomes to both technical and non-technical audiences.
  • Proficiency in technical and non-technical writing, including policies, standards, procedural documentation, process flow diagrams, and reporting.

Ready to apply? Get in touch.

Apply now ⟶