Skip to main content
Posted 15 August, 2026

Business Risk and Assurance Manager

Jobtailor
Auckland, AUK, NZ Full Time
Reference: 01be0ab3b2e1654a

Job Description

\n
    \n
  • Maintain an effective internal GRC framework ensuring accountability, transparency, and responsibility to stakeholders
  • \n
  • Ensure robust security and privacy controls and compliance with regulatory and privacy requirements
  • \n
  • Maintain current company certifications, including ISO and SOC 2
  • \n
  • Maintain and uplift the enterprise risk and compliance framework and policies
  • \n
  • Oversee and coordinate enterprise risk management activities
  • \n
  • Complete customer, software, project, privacy, and vendor/supplier risk assessments
  • \n
  • Integrate risk management into business processes
  • \n
  • Uplift and maintain data governance across DEFEND
  • \n
  • Maintain and update company policies and procedures at least annually
  • \n
  • Assist in creating and delivering the cybersecurity roadmap
  • \n
  • Respond to internal cybersecurity and privacy incidents
  • \n
  • Provide regular reporting for ELT, Board, and steering committee meetings
  • \n
  • Support the business in implementing policy and risk settings
  • \n
  • Deliver annual security and privacy awareness training to all staff
  • \n
Requirements\n
    \n
  • Knowledge and experience implementing industry standards and regulations such as ISO, NIST, GDPR, and COSO
  • \n
  • Strong understanding and experience of risk management frameworks and processes
  • \n
  • Understanding of business governance functions and processes
  • \n
  • Leadership and communication skills for communicating risks, requirements, and recommendations
  • \n
  • Project management skills to manage GRC initiatives, prioritize tasks, and meet deadlines
  • \n
  • Collaboration skills for working with cross-functional teams and internal and external stakeholders
  • \n
  • Ideally, experience preparing for and managing regular ISO and SOC 2 audits
  • \n
Core Competencies\n

Demonstrates expertise in maintaining and uplifting enterprise risk and compliance frameworks, ensuring adherence to regulatory standards such as ISO and SOC 2. Proficient in risk management processes, data governance, and delivering cybersecurity training while effectively communicating with stakeholders.

Highest-signal resume keywords\n
    \n
  • ISO Certification Management
  • \n
  • SOC 2 Compliance
  • \n
  • Risk Management Frameworks
  • \n
  • Project Management Skills
  • \n
  • Cybersecurity Incident Response
  • \n
ATS Optimization Keywords Hard Skills\n
    \n
  • Risk Assessment
  • \n
  • Data Governance
  • \n
  • Regulatory Compliance
  • \n
  • Cybersecurity Roadmap Development
  • \n
  • Policy and Procedure Maintenance
  • \n
Soft Skills\n
    \n
  • Leadership Skills
  • \n
  • Communication Skills
  • \n
  • Collaboration Skills
  • \n
Certifications & Qualifications\n
    \n
  • ISO Certification
  • \n
  • SOC 2 Certification
  • \n
Industry Keywords\n
    \n
  • GRC Framework
  • \n
  • NIST
  • \n
  • GDPR
  • \n
  • COSO
  • \n
  • Enterprise Risk Management
  • \n
\n
#J-18808-Ljbffr

Sign up for Job Alerts