CreditorWatch brand banner

Cyber GRC Lead

CreditorWatchSydney, AustraliaPosted 1h ago
via Workable

⭐️⭐️ Newly Create Role!! ⭐️⭐️

Who are we?

So you might ask, who’s CreditorWatch? We are a leading Australian data and technology company that provides businesses with access to unique data and innovative products. By using our platform, our customers can confidently manage their commercial relationships, improve productivity and reduce financial risk.

As a commercial credit reporting bureau, we offer a complete suite of credit reporting products and data insights covering the entire customer lifecycle—from customer onboarding and credit decision automation to credit risk management and automated collections.

We were established in 2010 and have been named one of AFR’s Top 10 Best Places to Work, as well as certified by Great Place to Work consecutively across 2022–2025.

We are scaling at pace, making this an exciting time to join CreditorWatch.

Our Purpose

✅ Empower Australian businesses to trade confidently with their customers.

Our Mission

🏆 We aim to be number one in our industry by delivering unique data insights and innovative products.

Your Role & Team

As CreditorWatch strengthens its core cyber governance, risk and compliance capability, we are establishing a Cyber GRC Lead role to own and mature our information security management and assurance program. 

This is a hands-on leadership role responsible for turning regulatory, certification, customer and business expectations into a practical, sustainable control environment. You will lead cyber risk management, assurance, policy governance, audit readiness, third-party security and resilience activities, while building strong ownership across the business. 

You will work closely with Engineering, Legal, P&C, IT, and business leaders to ensure cyber risk is understood, decisions are evidence-based, and controls operate effectively. The role is accountable for the Cyber GRC program, but succeeds by enabling control owners rather than becoming a central bottleneck. 

You'll report directly to our Head of IT & InfoSec.

Please note, it's a full-time opportunity offering hybrid working conditions out of our Sydney CBD Office.

Some of your responsibilities include and are not limited to:

Cyber GRC Strategy & Operating Model

  • Own and deliver the Cyber GRC roadmap, aligned to business priorities, risk appetite and regulatory requirements.
  • Establish clear governance, accountability, reporting and measures of effectiveness.
  • Lead and develop Cyber GRC capability, including internal and external stakeholders.

Risk, Controls & Policy Governance

  • Own the information security risk management framework and register, including risk assessment, treatment, acceptance and reporting.
  • Oversee the information security policy framework, ensuring policies, standards and procedures remain current and effective.
  • Establish sustainable control ownership, testing and remediation practices.

Assurance, Audits & Certifications

  • Lead ongoing readiness and compliance for ISO 27001 and SOC 2, including audit planning, evidence coordination, control testing and remediation.
  • Develop readiness for additional obligations and certifications, including ISO 42001, CPS 230, CPS 234 and the ASD Essential Eight.
  • Manage audit relationships, findings and customer/partner security assurance requests.

Third-Party Risk, Resilience & Incident Governance

  • Own the cyber components of third-party risk management, including due diligence, reassessments and security requirements.
  • Provide governance oversight across cyber incident readiness, business continuity, disaster recovery and operational resilience.
  • Partner with Engineering, DevOps, IT and Security Engineering to translate risks and control gaps into practical remediation plans.

AI Governance & Business Enablement

  • Lead responsible AI governance, including policy, risk, assurance and accountability.
  • Establish proportionate governance and guardrails for approved AI use cases.
  • Promote security and compliance as business enablers through clear, practical and streamlined requirements.

Our ideal candidate

  • Proven experience leading or owning Cyber Security GRC programs within SaaS, technology, financial services or regulated environments.
  • Strong experience with ISMS, ISO 27001 and/or SOC 2, including audit readiness, evidence management, findings and continuous improvement.
  • Strong knowledge of cyber risk, controls, policy governance, third-party risk and customer assurance.
  • Ability to translate regulatory, contractual and framework requirements into practical, business-owned controls.
  • Strong understanding of incident management, business continuity, disaster recovery and operational resilience.
  • Exposure to CPS 230, CPS 234 and the ASD Essential Eight is highly regarded; AI governance/ISO 42001 experience is desirable.
  • Experience with GRC and workflow tools, such as Drata, Jira, Confluence or equivalent.
  • Strong communication and stakeholder management skills, with the ability to challenge constructively and make complex risk easy to understand.
  • Hands-on and commercially minded, comfortable balancing strategy, stakeholder leadership and day-to-day program execution.

More than just work

🏃🏽‍♀️ Keep Active – All employees get a Fitness First Platinum gym membership.

☕️ Daily Fuel – Barista-made coffee, breakfast, snacks, lunches and drinks on us – we got you!

📲 Phone Credits - We pay you $50 per month to put towards your plans - how good.

❤️‍🩹 Wellness Days – Receive an additional day off each month. Whether you’re pursuing physical activities, cultivating your mental wellbeing or supporting your community… this is your time to switch off from work.

💆🏽‍♂️ Monthly Massages – We offer monthly in-house massages to soothe those sore spots and tight knots. Poor posture? Stressful week? We get it.

💰 Bonus Shares – We offer our dedicated employees’ performance-based bonuses. Our employees are also permitted to gain access to our bespoke Employee Share Scheme, giving you the rare opportunity to invest in a growing technology company.

🤩 Fun Activities – We love escaping the workplace to do fun stuff. Whether its pasta-making, sailing classes, touch footy, winery tours, go karting or relaxing on the company boat (yeah… we own a boat) – these monthly team building activities will keep you feeling valued and connected.

👩🏻‍⚖️ Legal Services – Our employees get access to free legal services – from conveyancing and property advice to legal assistance around wills, trusts, powers of attorney and more. We make life easier for you, saving you time, money and unnecessary headaches.

Our Values

⚡️ The 1%’ers add up – Our commitment to going that one step further sets us apart, as we believe that small efforts or improvements in any aspect of our work collectively lead to significant success.

👊🏼 We are dependable and trustworthy – Our clients are everything to us and we are passionate about maintaining and delivering reliable and trusted services to them.

📈 We are committed to growth – Our success comes from our ability to grow and adapt; both collectively and individually. We set the bar high to ensure we continue to innovate and exceed expectations. We are dedicated to the development of our business and our people.

🫶🏾 Our people make the difference – Just as we help small businesses think big, we help our employees achieve their aspirations. We provide our people with challenges and opportunities, supporting them to live their best lives.

Recruitment Process – We like to keep it simple!

  1. Phone Screening – A deep dive into the company, role and experience required, including a thorough review of your match to the role – let’s get to know each other and ensure the opportunity is a match!
  2. Hiring Manager Meeting – This is an opportunity to showcase why your background and skill set aligns to the role and ask questions – be as curious as you want!
  3. Functional Meeting – Here you’ll be set up with a take home case-challenge that is designed to look into the way you think and approach certain situations.
  4. Values Meeting – We’d love to hear why CreditorWatch and see how you’d fit into our world.

We are committed to you

We offer a fantastic culture with open communication and rewards and recognition that include probation celebrations, all-staff birthday and service anniversary celebrations.

We are an equal opportunity employer and committed to excellence through diversity. We do not discriminate on race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Similar roles

  • Right Hook Digital logo

    Creative Production Specialist (Part-time)

    Right Hook Digital·Australia

    Location: Remote (AU/NZ or US based) Type: Part-time (8 hours per week - either 1x full day or 2x half days per week) Salary: USD $2,500 - USD $3,000 per month (USD $30,000 - USD $36,000 per annum) Start: September 2026 Want to raise the bar on performance creative? At Right Hook, we make ads that stop the scroll, earn…

    • Remote
    • Part-time
    • Skilled Independent 189PR, no sponsor
  • Altius Group logo

    Client Service Liaison

    Altius Group·Sydney, Australia

    Executive Health Solutions (EHS), part of the Altius Group, is Australia’s leading provider of corporate and executive health programs. We partner with organisations nationwide to deliver premium health assessments led by some of Australia’s top doctors and allied health professionals. We are seeking a motivated Client Service Liaison / Receptionist to join our VIP Health Assessment Centre in the Sydney…

    • Full-time
    • Skilled Independent 189PR, no sponsor
  • Rubrik Job Board logo

    Global Solutions Architect

    Rubrik Job Board·Australia

    Global Solutions Architect, Cloud PROFESSIONAL SERVICES • TECHNICAL DIRECTOR • INDIVIDUAL CONTRIBUTOR, APAC About the role Rubrik Professional Services is hiring a Global Solutions Architect to serve as our most senior technical authority for public cloud. This is a global, individual-contributor role at Technical Director level. You will set the architectural direction for how Rubrik is designed, deployed, and operated…

    • Full-time
    • Skilled Independent 189PR, no sponsor
  • CreditorWatch logo

    Security Engineer (SaaS)

    CreditorWatch·Sydney, Australia

    ⭐️⭐️ New Headcount!! ⭐️⭐️ Who are we? So you might ask, who’s CreditorWatch? We are a leading Australian data and technology company that provides businesses with access to unique data and innovative products. By using our platform, our customers can confidently manage their commercial relationships, improve productivity and reduce financial risk. As a commercial credit reporting bureau, we offer a…

    • Hybrid
    • Full-time
    • Skilled Independent 189PR, no sponsor
  • dpa Deutsche Presse-Agentur GmbH logo

    Werkstudent (m/w/d) - Information Security

    dpa Deutsche Presse-Agentur GmbH·Hamburg, Germany

    Unternehmensbeschreibung Die dpa-IT Services GmbH ist das IT-Rückgrat der Deutschen Presse-Agentur (dpa) - einer der führenden unabhängigen Nachrichtenagenturen weltweit. Als Tochterunternehmen der dpa verantworten wir IT-Infrastruktur, geschäftskritische Anwendungen, moderne Cloud- und Rechenzentrumsinfrastrukturen sowie digitale Arbeitsplätze für die gesamte dpa-Gruppe. Du möchtest praktische Erfahrungen sammeln und aktiv an IT- und Informationssicherheitsthemen mitarbeiten? Dann bist du bei uns genau richtig. Zur Verstärkung…

    • On-site
    • Full-time
    • Blue Cardtied; settle 21–33mo
  • Compass Education logo

    Sales Development Representative

    Compass Education·Hawthorn, Australia

    Come shape the future of education with us. At Compass, we're on a mission to transform the school day for everyone - from staff and students to families and administrators. We build smart, seamless technology that empowers schools to focus on what really matters: learning, growing and thriving. That mission has fuelled our growth into a global scale-up, now supporting…

    • Hybrid
    • Full-time
    • Skilled Independent 189PR, no sponsor
  • Journey Beyond logo

    Chef | Rail

    Journey Beyond·Sydney, Australia

    Be a part of sharing special places and shaping lasting memories with Australia’s leading experiential tourism business. About Us Our Rail Division, previously known as Great Southern Rail (“GSR”) operates Australia’s iconic rail journeys, The Ghan, Indian Pacific, The Overland and Great Southern. There are very few global journeys considered national treasures, but our trains are, without question, iconic Australian…

    • Part-time
    • Skilled Independent 189PR, no sponsor
  • ClickView logo

    People Operations Manager

    ClickView·Sydney, Australia

    * Lead our global People Operations function, driving strategy and execution across Australia, the UK and the US * Join a company where people experience and culture are genuinely at the heart of what we do * Full-time, 14-month fixed-term contract, from early November 2026 to mid-December 2027 WHY JOIN US? Do you want to shape the future of education?…

    • Hybrid
    • Contract
    • Skilled Independent 189PR, no sponsor