EVT logo
EVTPosted 2 weeks ago

Cyber Risk and Governance Analyst - EVT Head Office

HybridSydney, New South Wales, Australia

Full TimeLarge

Job Summary

Build and maintain EVT's security governance framework, policies, and risk registers using Vanta to automate control evidence and reporting. Lead PCI-DSS compliance certification cycles, manage penetration testing vendors, and coordinate configuration reviews for critical systems. Assess third-party and supplier security risks while enforcing contractual requirements and maintaining the vendor risk register. Collaborate with technology and business teams to deliver information security outcomes and drive continuous improvement across the function. This hands-on role supports the development of risk frameworks aligned with NIST 2.0 and PCI DSS standards.

Required Qualifications

  • Significant experience in cyber security governance, risk, compliance, or technology risk management
  • Strong working knowledge of recognised frameworks and standards: NIST CSF, PCI-DSS, ISO, and SOC2
  • Demonstrated experience managing third-party and supplier cyber security risk in a corporate environment
  • Experience supporting audits, regulatory engagements, and executive-level reporting
  • Excellent stakeholder engagement, communication, and influencing skills
  • Ability to operate independently and provide strategic guidance in a complex organisational environment
  • Tertiary qualification in information security, IT, risk, law, or a related discipline, or equivalent professional experience

Desired Qualifications

  • Experience in a regulated or highly governed industry is desirable, for example financial services, critical infrastructure, utilities, government, or healthcare
  • Exposure to cloud and outsourced service risk management (AWS, Azure, SaaS providers) is desirable
  • Experience implementing or uplifting third-party risk management frameworks or GRC tooling is desirable
  • Relevant certifications are highly regarded, for example CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Implementer or Auditor

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce