GRC Lead
Adelaide, South Australia, Australia
Full Time
Experienced
About the role:
The GRC Lead is responsible for maintaining and strengthening Fivecast's governance, risk, compliance, and assurance capabilities. You will lead the delivery of the Governance, Risk and Compliance (GRC) stream, ensuring Fivecast can demonstrate its security posture to customers, auditors, regulators, certifying bodies, and government stakeholders.
Responsibilities:
- Lead the day-to-day delivery of the GRC function, mentoring team members and reviewing work to ensure high-quality outcomes across compliance, risk management, assurance, and governance activities.
- Maintain and continuously improve Fivecast's Information Security Management System (ISMS), ensuring compliance obligations are embedded into business operations and remain effective as the company scales.
- Own the preparation, coordination and successful execution of external audits and certifications, ensuring evidence is current, stakeholders are prepared, and remediation activities are tracked through to completion.
- Act as the owner of GRC platforms and tooling, ensuring compliance evidence, policies, controls and risk records remain accurate, accessible and audit-ready.
- Lead organisational risk management activities, facilitating risk assessments, documenting risk decisions, and ensuring critical risks are communicated appropriately to stakeholders and leadership.
- Support commercial activities by leading responses to customer security questionnaires, participating in customer assurance discussions, and contributing to Trust Centre content that supports sales and customer confidence.
- Monitor regulatory, contractual and industry changes relevant to Fivecast and translate emerging requirements into actionable controls, policies and business processes.
- Oversee business continuity, disaster recovery and personnel clearance programs, ensuring obligations are met and operational readiness is maintained.
- Provide leadership through regular coaching, objective setting, performance feedback, career development discussions and participation in recruitment activities for the GRC stream.
- Uses AI tooling as part of normal delivery - drafting, summarising evidence, mapping controls between frameworks - and reviews the output before it carries Fivecast's name. Knows what cannot be put into a tool and why.
Skills and Experience
- Must be an Australian Citizen and eligible to obtain an Australian Government Security Clearance (NV1/NV2).
- 5+ years of experience in Information Security, Governance Risk & Compliance (GRC), IT Audit, or related security disciplines.
- Experience maintaining and improving security compliance programs aligned with frameworks such as ISO 27001, NIST 800-171, CMMC, Essential 8, DISP, Cyber Essentials Plus, or SOC 2.
- Experience coordinating and leading external audits, certification activities, and/or compliance assessments.
- Experience utilising GRC automation platforms (e.g. Vanta, Drata) and work management tools (e.g. Jira, Confluence).
- Exposure to privacy, third-party risk, business continuity, or assurance programs within a technology or SaaS environment is highly desirable.
- Ability to mentor others and improve team capability through coaching, feedback and knowledge sharing.
- Strong written and verbal communication skills, capable of translating complex security and compliance requirements for technical, business and executive audiences.
- Highly motivated and comfortable operating in ambiguous environments, able to transform business outcomes into clear plans, priorities and deliverables.
- High attention to detail with a strong focus on documentation quality, evidence management, audit readiness and continual improvement.
- Strong judgement and a pragmatic approach to security, applying right-sized controls that effectively manage risk while supporting business outcomes.
- Able to influence stakeholders across the organisation and drive accountability without relying on formal authority.
- Comfortable working in a fast-paced, high-growth environment with competing priorities and changing business needs.
Qualifications (nice to have not required)
- CISSP, CISA, ISO 27001 Lead Implementer/Auditor, or equivalent experience.
- CompTIA Security+ or other relevant industry certifications.
- Tertiary qualifications in Information Security, Business, IT, Risk Management, or a related discipline are desirable.
Apply for this position
Required*