高级合规分析师
Senior Compliance Analyst
职位描述
我们正在寻找一位经验丰富且积极主动的高级合规分析师加入我们不断壮大的合规团队。
在此职位上,您将负责确保我们的数字系统、安全控制和业务流程符合监管、合同及行业合规要求。您将在维护和改进我们的合规框架、支持认证和认可、开展评估以及为组织内各相关部门提供专业指导方面发挥关键作用。
这是一个绝佳的机会,适合一位喜欢在技术、风险管理、治理和监管合规交叉领域工作的合规专业人士。
主要职责
· 根据ISO 27001、ISM、PSPF、RFFR、合同义务及其他相关监管要求进行合规评估。
· 向业务部门的相关方提供关于合规义务、风险管理及控制措施的专业指导。
· 维护适用的法律、监管、合同及政策义务清单。
- 监控安全、监管和政府框架的变化,评估影响,并推动新要求的实施。
- 与业务和技术团队合作,实施、审查和增强安全控制和合规措施。
- 领导保证审查、审计和控制有效性评估,识别合规差距并协调补救活动。
- 计划并执行保证审查,以评估控制有效性和合规成熟度
- 准备合规报告、仪表盘、指标和治理委员会更新。
- 支持客户安全审查、合规问卷调查、审计和监管报告工作。
- 制定和维护合规政策、标准、程序和治理文档。
- 分析合规数据,识别新兴风险和趋势,并为组织内的持续改进计划做出贡献。
我们希望您是一位高度分析能力和注重细节的合规专业人士,对信息安全、合规和风险管理框架有深刻理解。您能在复杂环境中茁壮成长,具备出色的干系人管理能力,并热衷于帮助组织应对合规要求,同时推动实际的业务成果。
经验要求
- 至少7年IT合规、信息安全、风险管理或相关领域的经验。
- 对信息安全管理有深入的理解,熟悉各类合规框架。
查看英文原文
About the Role
We are seeking an experienced and proactive Senior Compliance Analyst to join our growing Compliance team.
In this role, you will be responsible for ensuring our digital systems, security controls, and business processes meet regulatory, contractual, and industry compliance obligations. You will play a key role in maintaining and improving our compliance framework, supporting certifications and accreditations, conducting assessments, and providing expert guidance across the organisation.
This is an excellent opportunity for a compliance professional who enjoys working at the intersection of technology, risk management, governance, and regulatory compliance.
Key Responsibilities
· Conduct compliance assessments against ISO 27001, ISM, PSPF, RFFR, contractual obligations, and other relevant regulatory requirements.
· Provide expert guidance on compliance obligations, risk management, and controls to stakeholders across the business.
· Maintain a register of applicable legal, regulatory, contractual, and policy obligations.
- Monitor changes to security, regulatory, and government frameworks, assess impacts, and drive implementation of new requirements.
- Partner with business and technology teams to implement, review, and enhance security controls and compliance measures.
- Lead assurance reviews, audits, and control effectiveness assessments, identifying compliance gaps and coordinating remediation activities.
- Plan and perform assurance reviews to evaluate control effectiveness and compliance maturity
- Prepare compliance reports, dashboards, metrics, and governance committee updates.
- Support customer security reviews, compliance questionnaires, audits and regulatory reporting activities.
- Develop and maintain compliance policies, standards, procedures, and governance documentation.
- Analyse compliance data, identify emerging risks and trends, and contribute to continuous improvement initiatives across the organisation.
About You
You are a highly analytical and detail-oriented compliance professional with a strong understanding of information security, compliance, and risk management frameworks. You thrive in complex environments, have excellent stakeholder management skills, and are passionate about helping organisations navigate compliance requirements while driving practical business outcomes.
Experience
- Minimum 7 years' experience in IT compliance, information security, risk management, or a related field.
- Strong understanding of risk management frameworks, methodologies, and governance principles.
- Demonstrated experience working with compliance frameworks such as:
- ISO/IEC 27001
- Information Security Manual (ISM)
- Protective Security Policy Framework (PSPF)
- Other government, regulatory, or industry security frameworks
- Experience conducting security assessments, audits, certification programs, and assurance activities.
- Ability to interpret legal agreements, contractual requirements, and compliance obligations.
- Strong analytical, reporting, documentation, and problem-solving skills.
- Excellent communication and stakeholder engagement capabilities.
- Strong organisational and project management skills.
- High level of integrity, professionalism, and accountability.
- A proactive, collaborative, and solution-focused approach.
Highly Desirable
- Experience in highly regulated environments such as government, financial services, healthcare, or critical infrastructure.
- Experience with AI governance, emerging technology risks, and related compliance considerations.
- Experience managing ISO 27001 certification and security accreditation activities.
Desirable qualifications include:
- Tertiary qualifications in Information Security, Cyber Security, Computer Science, Technology, Risk Management, or a related discipline.
- CRISC, CISM, or CISA certification.
- ISO 31000 Risk Management certification.
- ISO 27001 Lead Auditor certification.
Why Join APM?
At APM, you'll have the opportunity to build a rewarding career while making a genuine difference in people's lives.
Our Benefits
- Work-life balance with no weekend work
- Opportunity to purchase additional annual leave
- Discounted health insurance
- Novated car leasing options
- Paid parental leave
- Service recognition programs
- Career growth opportunities across APM's diverse health and human services brands
- Ongoing learning and professional development
- Access to a supportive, collaborative, and inclusive workplace culture
Our Commitment to Diversity
At APM, we are strengthened by diversity and committed to creating a workplace where everyone feels included, respected, and valued. We welcome applications from people of all ages, nationalities, abilities, and cultures, including Aboriginal and Torres Strait Islander peoples, members of the LGBTQIA+ community, and people living with disability.
Ready to make an impact?
Apply now and join a purpose-driven organisation where your expertise will help strengthen compliance, protect our business, and contribute to enabling better lives.
Apply Now
If you are a compliance professional looking to take the next step in your career and contribute to a strong culture of governance and integrity, we would love to hear from you.
Originally posted on Himalayas