GRC Analyst (Security Compliance & Risk) job at STACK Infrastructure APAC
6 Days Ago
Linkedid Twitter Share on facebook
GRC Analyst (Security Compliance & Risk)
2026-04-04T15:43:41+00:00
STACK Infrastructure APAC
https://www.greataustraliajobs.com/jsjobsdata/data/employer/comp_4988/logo/Stack%20In.jpeg
FULL_TIME
South Yarra, Victoria 3141, Australia
Victoria (VIC)
2000
Australia
Information Technology
Computer & IT, Business Operations, Protective Services
AUD
MONTH
2026-04-14T17:00:00+00:00
8

Summary:

The GRC Analyst (Security Compliance & Risk) plays a crucial role in ensuring that our organisation adheres to security compliance standards and effectively manages risks within the building and construction industry. Based in South Yarra, Victoria, this permanent full-time position is essential for safeguarding our operations and maintaining our reputation in the market. The successful candidate will collaborate with various teams to implement and monitor compliance frameworks, ensuring that we meet both regulatory and internal standards.

Key Responsibilities:

  • Maintain and operate ISO 27001 ISMS and SOC 2 Type II compliance programs
  • Support DISP compliance and ongoing obligations
  • Collect, review, and manage audit evidence across controls
  • Prepare for and coordinate internal and external audits
  • Track and remediate audit findings and control gaps
  • Maintain documentation across personnel, physical, and information security domains
  • Assist with DISP reporting and audit activities
  • Maintain and update security policies, standards, and procedures
  • Ensure controls are implemented and operating effectively
  • Work with teams across engineering, IT, and operations to enforce compliance
  • Maintain risk registers and track risk treatment plans
  • Conduct risk assessments and support business impact analysis
  • Follow up with stakeholders to ensure mitigation actions are completed
  • Perform vendor security assessments and due diligence
  • Maintain third-party risk records and periodic reviews
  • Support security requirements in vendor onboarding and contracts
  • Plan and execute internal audits
  • Monitor control effectiveness and continuous compliance
  • Ensure ongoing audit readiness (not just point-in-time preparation)

Must have Experience:

  • 4–8 years’ experience in GRC, security compliance, or risk roles
  • Hands-on experience with ISO 27001 and/or SOC 2 audits
  • Proven experience collecting audit evidence and working with auditors
  • Strong organisational skills and attention to detail
  • Ability to drive tasks, follow up, and hold stakeholders accountable

Nice to have:

  • Experience with DISP or other government security frameworks
  • Experience in regulated industries (defense, finance, SaaS, etc.)
  • Familiarity with GRC platforms (Drata, Vanta, OneTrust, etc.)
  • Relevant certifications (ISO 27001 Lead Implementer/Auditor, CISA, CISM, etc.)

Equal Opportunity Employer

STACK provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions.

  • Maintain and operate ISO 27001 ISMS and SOC 2 Type II compliance programs
  • Support DISP compliance and ongoing obligations
  • Collect, review, and manage audit evidence across controls
  • Prepare for and coordinate internal and external audits
  • Track and remediate audit findings and control gaps
  • Maintain documentation across personnel, physical, and information security domains
  • Assist with DISP reporting and audit activities
  • Maintain and update security policies, standards, and procedures
  • Ensure controls are implemented and operating effectively
  • Work with teams across engineering, IT, and operations to enforce compliance
  • Maintain risk registers and track risk treatment plans
  • Conduct risk assessments and support business impact analysis
  • Follow up with stakeholders to ensure mitigation actions are completed
  • Perform vendor security assessments and due diligence
  • Maintain third-party risk records and periodic reviews
  • Support security requirements in vendor onboarding and contracts
  • Plan and execute internal audits
  • Monitor control effectiveness and continuous compliance
  • Ensure ongoing audit readiness (not just point-in-time preparation)
  • Strong organisational skills
  • Attention to detail
  • Ability to drive tasks
  • Ability to follow up
  • Ability to hold stakeholders accountable
  • 4–8 years’ experience in GRC, security compliance, or risk roles
  • Hands-on experience with ISO 27001 and/or SOC 2 audits
  • Proven experience collecting audit evidence and working with auditors
  • Experience with DISP or other government security frameworks (Nice to have)
  • Experience in regulated industries (defense, finance, SaaS, etc.) (Nice to have)
  • Familiarity with GRC platforms (Drata, Vanta, OneTrust, etc.) (Nice to have)
  • Relevant certifications (ISO 27001 Lead Implementer/Auditor, CISA, CISM, etc.) (Nice to have)
bachelor degree
24
JOB-69d131adacdd6

Vacancy title:
GRC Analyst (Security Compliance & Risk)

[Type: FULL_TIME, Industry: Information Technology, Category: Computer & IT, Business Operations, Protective Services]

Jobs at:
STACK Infrastructure APAC

Deadline of this Job:
Tuesday, April 14 2026

Duty Station:
South Yarra, Victoria 3141, Australia | Victoria (VIC)

Summary
Date Posted: Saturday, April 4 2026, Base Salary: Not Disclosed

Similar Jobs in Australia
Learn more about STACK Infrastructure APAC
STACK Infrastructure APAC jobs in Australia

JOB DETAILS:

Summary:

The GRC Analyst (Security Compliance & Risk) plays a crucial role in ensuring that our organisation adheres to security compliance standards and effectively manages risks within the building and construction industry. Based in South Yarra, Victoria, this permanent full-time position is essential for safeguarding our operations and maintaining our reputation in the market. The successful candidate will collaborate with various teams to implement and monitor compliance frameworks, ensuring that we meet both regulatory and internal standards.

Key Responsibilities:

  • Maintain and operate ISO 27001 ISMS and SOC 2 Type II compliance programs
  • Support DISP compliance and ongoing obligations
  • Collect, review, and manage audit evidence across controls
  • Prepare for and coordinate internal and external audits
  • Track and remediate audit findings and control gaps
  • Maintain documentation across personnel, physical, and information security domains
  • Assist with DISP reporting and audit activities
  • Maintain and update security policies, standards, and procedures
  • Ensure controls are implemented and operating effectively
  • Work with teams across engineering, IT, and operations to enforce compliance
  • Maintain risk registers and track risk treatment plans
  • Conduct risk assessments and support business impact analysis
  • Follow up with stakeholders to ensure mitigation actions are completed
  • Perform vendor security assessments and due diligence
  • Maintain third-party risk records and periodic reviews
  • Support security requirements in vendor onboarding and contracts
  • Plan and execute internal audits
  • Monitor control effectiveness and continuous compliance
  • Ensure ongoing audit readiness (not just point-in-time preparation)

Must have Experience:

  • 4–8 years’ experience in GRC, security compliance, or risk roles
  • Hands-on experience with ISO 27001 and/or SOC 2 audits
  • Proven experience collecting audit evidence and working with auditors
  • Strong organisational skills and attention to detail
  • Ability to drive tasks, follow up, and hold stakeholders accountable

Nice to have:

  • Experience with DISP or other government security frameworks
  • Experience in regulated industries (defense, finance, SaaS, etc.)
  • Familiarity with GRC platforms (Drata, Vanta, OneTrust, etc.)
  • Relevant certifications (ISO 27001 Lead Implementer/Auditor, CISA, CISM, etc.)

Equal Opportunity Employer

STACK provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions.

Work Hours: 8

Experience in Months: 24

Level of Education: bachelor degree

Job application procedure

To apply for this position, please visit the following link:

Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Australia
Job Type: Full-time
Deadline of this Job: Tuesday, April 14 2026
Duty Station: South Yarra, Victoria 3141, Australia | Victoria (VIC)
Posted: 04-04-2026
No of Jobs: 1
Start Publishing: 04-04-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.