أبلاي إيدج ابدأ البحث عن عمل

Cyber Governance, Risk and Compliance Specialist

Metrea · Brisbane, Queensland, Australia

قدّم وتابع مع أبلاي إيدج
Company OverviewMetrea delivers effects-as-a-service to national security partners across five domains and more than a dozen mission areas. These include airborne ISR, electronic warfare, secure communications, aerial refueling, special air missions, aerial firefighting, and advanced simulation. We own the whole stack: designing, building, and operating turnkey capabilities that give our partners decisive, asymmetric advantage against rapidly evolving threats.Our operating model is built around three interlocking pillars. The Support Groups provide a global shared-service – spanning people, finance, platform, operations, legal, and engagement. This frees up our Core Groups, who develop and own mission capabilities end-to-end, to focus entirely on delivery. The Market Groups apply a regional lens, ensuring that our agile and adaptable capabilities remain aligned to the wicked problems that matter most to our partners across the Americas, EMEA, and Asia-Pacific.At the heart of our model is a simple but powerful idea: be a true partner with skin in the game. Our partners need effects, not just equipment. By owning the full stack – from the lab to the field – we are able to drive a continuous cycle of innovation that keeps our partners ahead. It's a fast-moving, intellectually demanding environment where talented people are given real responsibility, work on problems that matter, and contribute to an enterprise that is growing quickly and deliberately.Headquartered in Washington, DC, with facilities across the United States, the United Kingdom, as well as Continental Europe and Asia-Pacific.Group OverviewMetrea is actively building its presence in Australia as part of a deliberate, globally coordinated expansion into the Asia-Pacific region. Our Asia-Pacific Market Group, headquartered in Brisbane with an additional office in Perth, is the enterprise's dedicated regional interface — connecting Australia's national security community with Metrea's full suite of capabilities across three core domains: Aerospace, Electromagnetic & Cyber, and Digital & Synthetic. Metrea is now bringing that same depth of mission expertise and proven operating model to Australia.Underpinning these capabilities is a global network of Support Groups spanning people, finance, platform, operations, legal, and engagement — ensuring that as we grow in Australia, we do so with the full weight of an established global enterprise behind us.Metrea's solutions are built for elegance: effective, efficient, and evolving — enabling our partners to scale capacity and achieve asymmetric advantage against rapidly evolving threats.Position SummaryWe are seeking a motivated and detail-oriented Cybersecurity Governance, Risk and Compliance (GRC) Analyst to support and maintain cybersecurity governance and assurance activities within a classified Microsoft Azure environment.This role is responsible for ensuring the ongoing security compliance of critical classified systems and services through the development, maintenance, and review of security accreditation and risk management documentation. The Cybersecurity GRC Analyst will work closely with technical teams, program stakeholders, security practitioners, and governance bodies to support the protection of classified information and systems in accordance with the Australian Government Information Security Manual (ISM), Protective Security Policy Framework (PSPF), and organisational security requirements.The successful candidate will lead and contribute to security documentation activities, security audits, risk assessments, compliance reporting, accreditation processes, and governance forums. They will provide cybersecurity advice to project and operational teams, support investigations relating to security incidents and compliance concerns, and help ensure security controls remain effective and aligned to regulatory and contractual obligations.This position requires strong knowledge of Australian Government cybersecurity frameworks, risk management principles, security accreditation processes, and cloud security concepts within Azure-based environments.What You'll DoAs a GRC Analyst you will be responsible for maintaining the security compliance of classified mission critical networks with ISM and PSPF controls. You will also be responsible for assessing and communicating system risk to senior stakeholders. Responsibilities fall into the following main areas:Develop, review, maintain, and update cybersecurity governance and accreditation documentation, including System Security Plans (SSP), Security Risk Management Plans (SRMP), security procedures, Plans of Action and Milestones (POA&Ms) and risk assessments.Support system accreditation and re-accreditation activities within classified environments.Ensure ongoing compliance with the ISM, PSPF, Essential Eight, and organisational security requirements.Conduct security compliance reviews, audits, and assurance assessments.Identify, assess, document, and manage cybersecurity risks and control gaps.Monitor remediation activities and ensure audit findings are addressed appropriately.Contribute cybersecurity advice and guidance to program security meetings, governance forums, project reviews, and change activities.Participate in the investigation of cybersecurity incidents, compliance breaches, and security concerns.Provide compliance reporting and risk status updates to management and stakeholders.Work closely with technical teams to validate security controls and ensure effective implementation.Assist with the development and continuous improvement of cybersecurity policies, standards, procedures, and governance processes.Maintain evidence repositories and compliance artefacts supporting audits and accreditation activities.Deliver cybersecurity training and awareness to system users.Interface with client cybersecurity stakeholders to ensure alignment across system boundaries.What You BringThe successful candidate will ideally have the following key qualifications, skills, and experiences:Extensive experience in cybersecurity governance, risk and compliance, security assurance, risk management, or information security roles.Experience working in government, Defence, critical infrastructure, or highly regulated environments.Experience supporting and authorising systems operating at PROTECTED, or higher security classifications is highly desirable.Demonstrated experience applying ISM and PSPF requirements within operational environments.Experience developing, maintaining, and reviewing cybersecurity documentation aligned to ISM and IRAP assessments such as System Security Plans (SSP), Security Risk Management Plans (SRPM), and Plans of Action and Milestones (POA&M).IRAP assessment exposure or formal IRAP training.Strong analytical and critical thinking skills.Ability to work independently and manage competing priorities.High level of integrity, professionalism, and discretion.Commitment to continuous improvement and security best practices.Clear and effective written and verbal communication.Strong organisational and documentation management capabilitiesAdditional Eligibility QualificationsPreferred: Bachelor's degree or higher in Cyber Security, Information Security, Information Technology, Computer Science, Risk Management, Governance, or a related discipline. Relevant industry experience may be considered in lieu of formal qualifications.The below certifications are highly desirable.CRISC, CISA, CGRC or working towards certification.ISO 27001 Lead Auditor.ITIL 4 FoundationsMicrosoft Certified: Azure Fundamentals (AZ-900).Microsoft Certified: Security Fundamentals (SC-900)Microsoft Certified: Information Protection and Compliance Administrator (SC-400)Microsoft Certified: Cyber Security Architect (SC-100)BenefitsPrivate Health InsuranceGenerous Annual LeaveAnnual incentive planPaid parental leaveLife and disability insuranceIncome Protection InsuranceEmployee Assistance ProgramNovated Car LeasingWork Authorisation / Security ClearanceAbility to obtain and maintain an AGSVA Security Clearance.Inclusion StatementWe are committed to building a team that reflects a broad range of backgrounds, experiences and perspectives. We welcome applications from all qualified candidates and make hiring decisions based on capability, potential and alignment with our values. If you require any adjustments throughout the recruitment process, please let us know.Our FirmwareAt Metrea, our single core value is Rooted in Humility, and our four cornerstone attributes are Entrepreneurial, Systematic, Discerning, and Over-Deliver. These form what we call our Teammate Firmware. Just like technical firmware connects software and hardware, our Firmware is the constant interface between our mission and our people. It defines how we show up, how we work together, and how we solve complex problems.Our team Firmware creates a web-like, hyper-collaborative, dynamically hierarchical way of working that helps us adapt quickly, communicate openly, and distribute decision-making to where expertise actually lives. It enables groups to self-organize around hard problems, shift fluidly as priorities evolve, and operate with the trust, curiosity, and discipline required in a complex mission space. This foundation allows us to deliver elegant, effective solutions and uphold our purpose: protecting our precious inheritance.