Posted 15 August, 2026
Business Risk and Assurance Manager
Jobtailor
Auckland, AUK, NZ
Full Time
Reference: 01be0ab3b2e1654a
Job Description
\n
#J-18808-Ljbffr- \n
- Maintain an effective internal GRC framework ensuring accountability, transparency, and responsibility to stakeholders \n
- Ensure robust security and privacy controls and compliance with regulatory and privacy requirements \n
- Maintain current company certifications, including ISO and SOC 2 \n
- Maintain and uplift the enterprise risk and compliance framework and policies \n
- Oversee and coordinate enterprise risk management activities \n
- Complete customer, software, project, privacy, and vendor/supplier risk assessments \n
- Integrate risk management into business processes \n
- Uplift and maintain data governance across DEFEND \n
- Maintain and update company policies and procedures at least annually \n
- Assist in creating and delivering the cybersecurity roadmap \n
- Respond to internal cybersecurity and privacy incidents \n
- Provide regular reporting for ELT, Board, and steering committee meetings \n
- Support the business in implementing policy and risk settings \n
- Deliver annual security and privacy awareness training to all staff \n
- \n
- Knowledge and experience implementing industry standards and regulations such as ISO, NIST, GDPR, and COSO \n
- Strong understanding and experience of risk management frameworks and processes \n
- Understanding of business governance functions and processes \n
- Leadership and communication skills for communicating risks, requirements, and recommendations \n
- Project management skills to manage GRC initiatives, prioritize tasks, and meet deadlines \n
- Collaboration skills for working with cross-functional teams and internal and external stakeholders \n
- Ideally, experience preparing for and managing regular ISO and SOC 2 audits \n
Demonstrates expertise in maintaining and uplifting enterprise risk and compliance frameworks, ensuring adherence to regulatory standards such as ISO and SOC 2. Proficient in risk management processes, data governance, and delivering cybersecurity training while effectively communicating with stakeholders.
Highest-signal resume keywords\n- \n
- ISO Certification Management \n
- SOC 2 Compliance \n
- Risk Management Frameworks \n
- Project Management Skills \n
- Cybersecurity Incident Response \n
- \n
- Risk Assessment \n
- Data Governance \n
- Regulatory Compliance \n
- Cybersecurity Roadmap Development \n
- Policy and Procedure Maintenance \n
- \n
- Leadership Skills \n
- Communication Skills \n
- Collaboration Skills \n
- \n
- ISO Certification \n
- SOC 2 Certification \n
- \n
- GRC Framework \n
- NIST \n
- GDPR \n
- COSO \n
- Enterprise Risk Management \n