Employment Hero is looking for a Security GRC Manager to lead our Global Security GRC Team and shape the overarching information security management strategy. In this role, you will be responsible for ensuring the company is at the forefront of information security excellence.
What You'll Do
- Lead and manage a team of Security GRC professionals, providing guidance, mentorship, and support.
- Develop and drive the organisation's overarching information security and GRC strategy.
- Oversee the design, implementation, and continuous improvement of security governance processes, risk management frameworks, and compliance programs.
- Lead internal and external security audits, ensuring the organisation meets compliance requirements and deadlines.
- Establish and maintain high-level information security policies, procedures, and standards.
- Serve as the primary liaison between internal stakeholders to ensure effective implementation of security and risk initiatives.
- Lead regular risk assessments, audits, and vulnerability assessments and provide strategic recommendations to senior leadership.
- Oversee and guide the response to security incidents, ensuring rapid remediation and root cause analysis.
- Foster a security-conscious culture by developing and delivering security training programs.
- Stay current with emerging trends in information security, governance, and compliance and implement continuous improvements.
What We're Looking For
- A degree in information technology, information security, risk management, or equivalent work experience.
- Proven ability to lead and manage a team, with strong consultative, written, and verbal communication skills.
- Demonstrated knowledge and understanding of contemporary frameworks and methodologies, such as ISO 27001, NIST 800-53, SOC2.
- Excellent written, oral, and influencing skills with the ability to work autonomously.
- A strong focus on continuous improvement, with a proven ability to challenge the status quo constructively.
- Broad knowledge of current Governance, Risk and Compliance (GRC) technological tools and methodologies.
- Strong consultative skills, enabling effective communication of complex concepts to both technical and non-technical audiences.
- Meticulous attention to detail.
- A strong desire to learn and expand knowledge in the field of information security.
Nice to Have
- Industry certifications such as CISSP, CISM or CISA are highly desirable.
Team & Environment
You will lead and manage our Global Security GRC Team.
Benefits & Compensation
- Work remotely with flexibility to own your time.
- Access cutting-edge tools to amplify your work, knowledge and outputs.
- Own ESOP (employee share options) in one of the world’s fastest-growing tech companies.
- Generous paternity leave policy.
- Subsidised egg freezing.
- WFH office expense budget.
- Outstanding learning & development opportunities.
Work Mode
This is a remote position open to candidates based in Australia.
Employment Hero celebrates diverse perspectives and experiences, we invite people of all backgrounds and identities to apply for this position.
