Business Risk and Assurance Manager
At DEFEND, we are committed to delivering exceptional cyber resilience by providing strategic, engineered solutions alongside expert advisory services. Our goal is to empower organisations to safeguard their digital assets through innovative technology and best-in-class practices.
The Business Risk & Assurance Manager is responsible for maintaining an effective GRC (Governance, Risk & Compliance) framework internally that ensures DEFEND is accountable, transparent, and responsible to all of its stakeholders, including customers, employees, and the wider community.
Requirements
In this role you'll...
Ensure DEFEND has robust security and privacy controls in place and meets it's regulatory and privacy requirements
Maintain current company certifications like ISO and SOC 2
Maintain and uplift the enterprise risk and compliance framework and policies
Oversee and coordinate enterprise risk management activities
Complete customer, software, project, privacy and vendor/supplier risk assessments as required
Integrate risk management into business processes
Uplift and maintain data governance across DEFEND
Maintain and update DEFEND policies and procedures at least annually
Assist in the creation and delivery of the DEFEND cybersecurity roadmap
Respond to internal cybersecurity and privacy incidents
Regular reporting for ELT, Board and steering committee meetings
Support business to implement policy and risk settings
Deliver annual security and privacy awareness training to all staff
You'll bring..
Good knowledge and experience in implementing of industry standards and regulations (e.g. ISO, NIST, GDPR, COSO)
Strong understanding and experience of risk management framework and processes
Good understanding of business governance functions and processes
Leadership and communication skills to effectively communicate risks, requirements, and recommendations to stakeholders and team members
Project management skills to manage GRC initiatives, prioritise tasks, and meet deadlines
Collaboration skills to work with cross-functional teams and build relationships with internal and external stakeholders
Ideally have experience preparing for and managing regular audits like ISO and SOC 2
Benefits
Our dream at DEFEND is to improve everyday life by creating a cyber resilient world. Over the last few years, we've experienced phenomenal growth, working with a wide variety of customers and winning several industry awards, including Microsoft's Global Partner of the Year for 2025!
Why DEFEND?
We believe in investing in our employees' growth and providing them with opportunities to advance their skills and careers. We offer a collaborative workplace culture, and we are committed to fostering an inclusive environment where innovative thinking is encouraged.
By joining our innovative and creative team you will have the opportunity to contribute a variety of cybersecurity outcomes, from culture & awareness of cyber resilience, through to offensive & defensive security. No matter what your role, everyone at DEFEND contributes towards our dream of creating a cyber resilient world.
The benefits of working at DEFEND
In addition to working for a growing, dynamic NZ company, DEFEND offers the following benefits to all our DEFENDers
- 3.5% Kiwisaver on top of your base salary
- Southern Cross Health Insurance coverage
- Mobile and Broadband discounts for yourself and family
- Flexible, hybrid work environment
- An allowance to contribute to your home office setup
- Access to EAP services to support you across a range of wellbeing needs
Diversity & Inclusion:
At DEFEND, we celebrate a variety of perspectives and experiences. We know from experience that people from underrepresented groups often don't apply for roles they don't feel they meet all the criteria for. We're committed to creating an environment that enables all our team to thrive. If you think you have what it takes, but don't check every single box, please consider applying. We'd love to hear how you might contribute to the team and being our next DEFENDer.