freehire launches on Product Hunt on 26 August.

Follow →

Security Risk & Assurance Analyst | GRC

Wellington | Permanent

Ready to take the next step in your security, risk, audit or compliance career?

This is an excellent opportunity for an early-career professional with 2+ years' experience who wants to build their career in information security risk and assurance.

You'll join a collaborative security team within an established organisation, gaining hands-on exposure across security risk, ISO 27001, assurance, governance, audits and third-party security.

You don't need to have spent your entire career in cyber security. We're interested in people who have developed a good foundation in information security, risk, compliance, assurance or audit and are ready to broaden their experience and take on more responsibility.

What you'll be doing
You'll support the ongoing development and improvement of the organisation's Information Security Management System (ISMS) and contribute to a range of security risk and assurance activities.

Your responsibilities will include:
  • Maintaining the information security risk register and tracking risk treatment activities
  • Working with stakeholders to review risks, treatment plans and emerging risks
  • Supporting ISO 27001 compliance and continuous improvement
  • Assisting with internal and independent security audits
  • Supporting control assurance and attestation activities
  • Conducting security due diligence and assurance assessments of suppliers and third parties
  • Tracking findings, non-conformities and corrective actions
  • Preparing security metrics and reporting for governance and management
  • Supporting security awareness and broader governance initiatives
What we're looking for
You'll ideally have 2+ years' experience within information security, technology risk, compliance, assurance, audit or a related area.

We're particularly interested in candidates who bring:
  • Exposure to ISO 27001, ISO 9001 or similar standards
  • An understanding of security frameworks such as ISO 27001, NIST or CIS
  • Strong analytical and organisational skills
  • Excellent attention to detail
  • Confidence working with a range of stakeholders
  • Strong written and verbal communication skills
  • A genuine interest in developing your career within security risk and assurance
You might currently be working as a GRC Analyst, Risk Analyst, Technology Risk Analyst, Assurance Analyst, Compliance Analyst, IT Auditor or Security Analyst and looking for your next step.

Why consider this opportunity?
This is a role where you'll get exposure to much more than one area of security risk and compliance.

You'll have the opportunity to work across risk, governance, assurance, audits, controls, third-party security and ISO 27001, while learning from experienced security professionals and gradually taking on greater responsibility.

It's an excellent next move for someone who has built their foundations and now wants a role that will broaden their experience and accelerate their development within GRC and information security.
Interested?

If you've started your career in security, technology risk, audit, assurance or compliance and are looking for an opportunity where you can learn, contribute and grow, we'd love to hear from you.
Apply now or get in touch for a confidential conversation.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available