Cyber Governance, Risk and Compliance Analyst
Group Overview
Metrea is actively building its presence in Australia as part of a deliberate, globally coordinated expansion into the Asia-Pacific region. Our Asia-Pacific Market Group, headquartered in Brisbane with an additional office in Perth, is the enterprise's dedicated regional interface — connecting Australia's national security community with Metrea's full suite of capabilities across three core domains: Aerospace, Electromagnetic & Cyber, and Digital & Synthetic. Metrea is now bringing that same depth of mission expertise and proven operating model to Australia.
Underpinning these capabilities is a global network of Support Groups spanning people, finance, platform, operations, legal, and engagement — ensuring that as we grow in Australia, we do so with the full weight of an established global enterprise behind us.
Metrea's solutions are built for elegance: effective, efficient, and evolving — enabling our partners to scale capacity and achieve asymmetric advantage against rapidly evolving threats.
Position Summary
We are seeking a motivated and detail-oriented Cybersecurity Governance, Risk and Compliance (GRC) Analyst to support and maintain cybersecurity governance and assurance activities within a classified Microsoft Azure environment.
This role is responsible for ensuring the ongoing security compliance of critical classified systems and services through the development, maintenance, and review of security accreditation and risk management documentation. The Cybersecurity GRC Analyst will work closely with technical teams, program stakeholders, security practitioners, and governance bodies to support the protection of classified information and systems in accordance with the Australian Government Information Security Manual (ISM), Protective Security Policy Framework (PSPF), and organisational security requirements.
The successful candidate will lead and contribute to security documentation activities, security audits, risk assessments, compliance reporting, accreditation processes, and governance forums. They will provide cybersecurity advice to project and operational teams, support investigations relating to security incidents and compliance concerns, and help ensure security controls remain effective and aligned to regulatory and contractual obligations.
This position requires strong knowledge of Australian Government cybersecurity frameworks, risk management principles, security accreditation processes, and cloud security concepts within Azure-based environments.
What You'll Do
As a GRC Analyst you will be responsible for maintaining the security compliance of classified mission critical networks with ISM and PSPF controls. You will also be responsible for assessing and communicating system risk to senior stakeholders. Responsibilities fall into the following main areas:
Develop, review, maintain, and update cybersecurity governance and accreditation documentation, including System Security Plans (SSP), Security Risk Management Plans (SRMP), security procedures, Plans of Action and Milestones (POA&Ms) and risk assessments
Support system accreditation and re-accreditation activities within classified environments
Ensure ongoing compliance with the ISM, PSPF, Essential Eight, and organisational security requirements
Conduct security compliance reviews, audits, and assurance assessments
Identify, assess, document, and manage cybersecurity risks and control gaps
Monitor remediation activities and ensure audit findings are addressed appropriately
Contribute cybersecurity advice and guidance to program security meetings, governance forums, project reviews, and change activities
Participate in the investigation of cybersecurity incidents, compliance breaches, and security concerns
Provide compliance reporting and risk status updates to management and stakeholders
Work closely with technical teams to validate security controls and ensure effective implementation
Assist with the development and continuous improvement of cybersecurity policies, standards, procedures, and governance processes
Maintain evidence repositories and compliance artefacts supporting audits and accreditation activities
Deliver cybersecurity training and awareness to system users
Interface with client cybersecurity stakeholders to ensure alignment across system boundaries
What You Bring
The successful candidate will ideally have the following key qualifications, skills, and experiences:
Extensive experience in cybersecurity governance, risk and compliance, security assurance, risk management, or information security roles
Experience working in government, Defence, critical infrastructure, or highly regulated environments
Experience supporting and authorising systems operating at PROTECTED, or higher security classifications is highly desirable
Demonstrated experience applying ISM and PSPF requirements within operational environments
Experience developing, maintaining, and reviewing cybersecurity documentation aligned to ISM and IRAP assessments such as System Security Plans (SSP), Security Risk Management Plans (SRPM), and Plans of Action and Milestones (POA&M)
IRAP assessment exposure or formal IRAP training
Strong analytical and critical thinking skills
Ability to work independently and manage competing priorities
High level of integrity, professionalism, and discretion
Commitment to continuous improvement and security best practices
Clear and effective written and verbal communication
Strong organisational and documentation management capabilities
Additional Eligibility Qualifications
Preferred: Bachelor's degree or higher in Cyber Security, Information Security, Information Technology, Computer Science, Risk Management, Governance, or a related discipline. Relevant industry experience may be considered in lieu of formal qualifications.
The below certifications are highly desirable.
CRISC, CISA, CGRC or working towards certification
ISO 27001 Lead Auditor.
ITIL 4 Foundations
Microsoft Certified: Azure Fundamentals (AZ-900).
Microsoft Certified: Security Fundamentals (SC-900)
Microsoft Certified: Information Protection and Compliance Administrator (SC-400)
Microsoft Certified: Cyber Security Architect (SC-100)
Benefits
Private Health Insurance
Generous Annual Leave
Annual incentive plan
Paid parental leave
Life and disability insurance
Income Protection Insurance
Employee Assistance Program
Novated Car Leasing
Work Authorisation / Security Clearance
Ability to obtain and maintain an AGSVA Security Clearance.
Inclusion Statement
We are committed to building a team that reflects a broad range of backgrounds, experiences and perspectives. We welcome applications from all qualified candidates and make hiring decisions based on capability, potential and alignment with our values. If you require any adjustments throughout the recruitment process, please let us know.