Security Risk & Assurance Analyst | GRC
Wellington | Permanent
Ready to take the next step in your security, risk, audit or compliance career?
This is an excellent opportunity for an early-career professional with 2+ years' experience who wants to build their career in information security risk and assurance.
You'll join a collaborative security team within an established organisation, gaining hands-on exposure across security risk, ISO 27001, assurance, governance, audits and third-party security.
You don't need to have spent your entire career in cyber security. We're interested in people who have developed a good foundation in information security, risk, compliance, assurance or audit and are ready to broaden their experience and take on more responsibility.
What you'll be doing
You'll support the ongoing development and improvement of the organisation's Information Security Management System (ISMS) and contribute to a range of security risk and assurance activities.
Your responsibilities will include:
You'll ideally have 2+ years' experience within information security, technology risk, compliance, assurance, audit or a related area.
We're particularly interested in candidates who bring:
Why consider this opportunity?
This is a role where you'll get exposure to much more than one area of security risk and compliance.
You'll have the opportunity to work across risk, governance, assurance, audits, controls, third-party security and ISO 27001, while learning from experienced security professionals and gradually taking on greater responsibility.
It's an excellent next move for someone who has built their foundations and now wants a role that will broaden their experience and accelerate their development within GRC and information security.
Interested?
If you've started your career in security, technology risk, audit, assurance or compliance and are looking for an opportunity where you can learn, contribute and grow, we'd love to hear from you.
Apply now or get in touch for a confidential conversation.
Ready to take the next step in your security, risk, audit or compliance career?
This is an excellent opportunity for an early-career professional with 2+ years' experience who wants to build their career in information security risk and assurance.
You'll join a collaborative security team within an established organisation, gaining hands-on exposure across security risk, ISO 27001, assurance, governance, audits and third-party security.
You don't need to have spent your entire career in cyber security. We're interested in people who have developed a good foundation in information security, risk, compliance, assurance or audit and are ready to broaden their experience and take on more responsibility.
What you'll be doing
You'll support the ongoing development and improvement of the organisation's Information Security Management System (ISMS) and contribute to a range of security risk and assurance activities.
Your responsibilities will include:
- Maintaining the information security risk register and tracking risk treatment activities
- Working with stakeholders to review risks, treatment plans and emerging risks
- Supporting ISO 27001 compliance and continuous improvement
- Assisting with internal and independent security audits
- Supporting control assurance and attestation activities
- Conducting security due diligence and assurance assessments of suppliers and third parties
- Tracking findings, non-conformities and corrective actions
- Preparing security metrics and reporting for governance and management
- Supporting security awareness and broader governance initiatives
You'll ideally have 2+ years' experience within information security, technology risk, compliance, assurance, audit or a related area.
We're particularly interested in candidates who bring:
- Exposure to ISO 27001, ISO 9001 or similar standards
- An understanding of security frameworks such as ISO 27001, NIST or CIS
- Strong analytical and organisational skills
- Excellent attention to detail
- Confidence working with a range of stakeholders
- Strong written and verbal communication skills
- A genuine interest in developing your career within security risk and assurance
Why consider this opportunity?
This is a role where you'll get exposure to much more than one area of security risk and compliance.
You'll have the opportunity to work across risk, governance, assurance, audits, controls, third-party security and ISO 27001, while learning from experienced security professionals and gradually taking on greater responsibility.
It's an excellent next move for someone who has built their foundations and now wants a role that will broaden their experience and accelerate their development within GRC and information security.
Interested?
If you've started your career in security, technology risk, audit, assurance or compliance and are looking for an opportunity where you can learn, contribute and grow, we'd love to hear from you.
Apply now or get in touch for a confidential conversation.