Skip to main content
Posted 25 August, 2026

Security Risk & Assurance Analyst | GRC

FindIT Recruitment
Wellington, WGN, NZ Full Time
Reference: 9ddce5fcd2973c98

Job Description

Jora New Zealand will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey. FindIT Recruitment – Wellington Central, North Island Wellington | Permanent Ready to take the next step in your security, risk, audit or compliance career? This is an excellent opportunity for an early-career professional with 2+ years' experience who wants to build their career in information security risk and assurance. You’ll join a collaborative security team within an established organisation, gaining hands-on exposure across security risk, ISO 27001, assurance, governance, audits and third-party security . You don’t need to have spent your entire career in cyber security. We’re interested in people who have developed a good foundation in information security, risk, compliance, assurance or audit and are ready to broaden their experience and take on more responsibility. What you’ll be doing You’ll support the ongoing development and improvement of the organisation’s Information Security Management System (ISMS) and contribute to a range of security risk and assurance activities. Your responsibilities will include: Maintaining the information security risk register and tracking risk treatment activities Working with stakeholders to review risks, treatment plans and emerging risks Supporting ISO 27001 compliance and continuous improvement Assisting with internal and independent security audits Supporting control assurance and attestation activities Conducting security due diligence and assurance assessments of suppliers and third parties Tracking findings, non-conformities and corrective actions Preparing security metrics and reporting for governance and management Supporting security awareness and broader governance initiatives What we’re looking for You’ll ideally have 2+ years' experience within information security, technology risk, compliance, assurance, audit or a related area. We’re particularly interested in candidates who bring: Exposure to ISO 27001, ISO 9001 or similar standards An understanding of security frameworks such as ISO 27001, NIST or CIS Strong analytical and organisational skills Excellent attention to detail Confidence working with a range of stakeholders Strong written and verbal communication skills A genuine interest in developing your career within security risk and assurance You might currently be working as a GRC Analyst, Risk Analyst, Technology Risk Analyst, Assurance Analyst, Compliance Analyst, IT Auditor or Security Analyst and looking for your next step. Why consider this opportunity? This is a role where you’ll get exposure to much more than one area of security risk and compliance. You’ll have the opportunity to work across risk, governance, assurance, audits, controls, third-party security and ISO 27001 , while learning from experienced security professionals and gradually taking on greater responsibility. It’s an excellent next move for someone who has built their foundations and now wants a role that will broaden the experience and accelerate development within GRC and information security . If you’ve started your career in security, technology risk, audit, assurance or compliance and are looking for an opportunity where you can learn, contribute and grow , we’d love to hear from you. #J-18808-Ljbffr

Sign up for Job Alerts