Cyber Governance, Risk and Compliance (GRC) Analyst

Apply now Job no: 493772
Work type: Permanent - Full Time
Location: Brisbane CBD
Categories: Digital and Technology Group

About the Opportunity – Cyber GRC Analyst 

As a Cyber Governance, Risk and Compliance (GRC) Analyst, you’ll support the ongoing maturity and assurance of WorkCover’s Information Security Management System (ISMS), working across cyber control assessments, risk reviews, and internal/external audit activities. You’ll play a hands-on role in uplifting our compliance posture and embedding security governance across the enterprise. 

Reporting to the Cyber Security Governance and Compliance Manager, you’ll collaborate with internal stakeholders across cyber, IT, and business to deliver operational GRC outcomes - from control testing and policy development to risk-based reporting and third-party assurance. You’ll contribute to risk-informed decision-making and help ensure WorkCover remains secure and resilient in a dynamic regulatory and threat landscape.  

You’ll also contribute to: 

  • Lead control assessments, internal assurance and evidence collection activities across WorkCover’s ISMS 

  • Support internal and external audits, ensuring evidence readiness and cyber GRC alignment 

  • Collaborate with technical and business stakeholders to perform cyber risk assessments and uplift control maturity 

  • Monitor and report on cyber risks, control gaps and assurance outcomes to enable effective remediation 

  • Track emerging risks and contribute to improving cyber policies, standards and frameworks 

A bit about you: 

You’re a capable and proactive cyber security professional with experience across GRC, compliance, or risk. You’re detail-oriented and able to manage complexity without losing sight of the big picture. Whether coordinating a control review or supporting audit prep, you’re organised, collaborative and always looking for ways to improve. 

You bring: 

  • Minimum 5+ years’ experience in cyber GRC, information security, or technology risk roles 

  • Familiarity with ISMS practices and frameworks such as ISO27001, NIST CSF and or Essential 8 

  • Experience in testing or reviewing cyber controls, assessing risk, and supporting assurance activities 

  • Strong communication skills with the ability to engage technical and non-technical stakeholders 

  • Working knowledge of GRC platforms (e.g. Protecht), Microsoft security stack, and cloud governance concepts 

  • Relevant certifications such as ISO27001, CRISC, or CISA are desirable but not essential 

You’re someone who enjoys solving problems, engaging across teams, and contributing to cyber security outcomes that matter. You take pride in your work and thrive in a fast-paced, collaborative environment where your input makes a difference. 

The Cyber GRC Analyst position description is available on the intranet. 

How do I apply? 

Please submit your resume and a covering letter of no more than two pages, outlining your suitability for the role, your motivations, and alignment with our values and vision. Applications close at 5PM, Tuesday 29th of July.  

Prior to applying, please discuss your intent to apply with your leader and take a look at our expression of interest tips. 

This role is graded at Individual Contract. If you have any questions about this opportunity, please contact Chris Yeoh or Angela Ng.  

We are committed to ensuring WorkCover reflects the diversity of the Queensland community. We welcome applications from First Nations peoples, members of the LGBTQIA+SB community, people of all ages, people who are neurodivergent, people with disability, and people from culturally and linguistically diverse backgrounds. To provide you the best experience, we can support with accommodations or adjustments at any stage of the recruitment process. Simply inform our recruitment team during your conversation with them. 

Advertised: E. Australia Standard Time
Applications close: E. Australia Standard Time

Back to search results

Apply Now