Business Risk and Assurance Manager

Posted 9 Days Ago
Be an Early Applicant
2 Locations
In-Office
Senior level
Information Technology • Software • Consulting • Cybersecurity
The Role
Lead and maintain DEFEND's Governance, Risk & Compliance (GRC) framework, manage enterprise risk and compliance activities, maintain certifications (ISO, SOC 2), perform risk assessments (customer, software, project, privacy, vendors), uplift data governance, update policies, support audits, respond to cybersecurity/privacy incidents, deliver training, and report to ELT/Board while supporting implementation of security and privacy controls across the business.
Summary Generated by Built In

At DEFEND, we are committed to delivering exceptional cyber resilience by providing strategic, engineered solutions alongside expert advisory services. Our goal is to empower organisations to safeguard their digital assets through innovative technology and best-in-class practices.

The Business Risk & Assurance Manager is responsible for maintaining an effective GRC (Governance, Risk & Compliance) framework internally that ensures DEFEND is accountable, transparent, and responsible to all of its stakeholders, including customers, employees, and the wider community.


Requirements

In this role you’ll...

• Ensure DEFEND has robust security and privacy controls in place and meets it’s regulatory and privacy requirements

• Maintain current company certifications like ISO and SOC 2

• Maintain and uplift the enterprise risk and compliance framework and policies

• Oversee and coordinate enterprise risk management activities  

• Complete customer, software, project, privacy and vendor/supplier risk assessments as required

• Integrate risk management into business processes

• Uplift and maintain data governance  across DEFEND

• Maintain and update DEFEND policies and procedures at least annually

• Assist in the creation and delivery of the DEFEND cybersecurity roadmap

• Respond to internal cybersecurity and privacy incidents

• Regular reporting for ELT, Board and steering committee meetings

• Support business to implement policy and risk settings

• Deliver annual security and privacy awareness training to all staff

You’ll bring..

• Good knowledge and experience in implementing of industry standards and regulations (e.g. ISO, NIST, GDPR, COSO)  

• Strong understanding and experience of risk management framework and processes

• Good understanding of business governance functions and processes 

• Leadership and communication skills to effectively communicate risks, requirements, and recommendations to stakeholders and team members

• Project management skills to manage GRC initiatives, prioritise tasks, and meet deadlines

• Collaboration skills to work with cross-functional teams and build relationships with internal and external stakeholders

• Ideally have experience preparing for and managing regular audits like ISO and SOC 2


Benefits

Our dream at DEFEND is to improve everyday life by creating a cyber resilient world. Over the last few years, we've experienced phenomenal growth, working with a wide variety of customers and winning several industry awards, including Microsoft's Global Partner of the Year for 2025! 


Why DEFEND? 

We believe in investing in our employees’ growth and providing them with opportunities to advance their skills and careers. We offer a collaborative workplace culture, and we are committed to fostering an inclusive environment where innovative thinking is encouraged.  


By joining our innovative and creative team you will have the opportunity to contribute a variety of cybersecurity outcomes, from culture & awareness of cyber resilience, through to offensive & defensive security. No matter what your role, everyone at DEFEND contributes towards our dream of creating a cyber resilient world. 


The benefits of working at DEFEND 

In addition to working for a growing, dynamic NZ company, DEFEND offers the following benefits to all our DEFENDers 

  • 3.5% Kiwisaver on top of your base salary 
  • Southern Cross Health Insurance coverage 
  • Mobile and Broadband discounts for yourself and family  
  • Flexible, hybrid work environment 
  • An allowance to contribute to your home office setup 
  • Access to EAP services to support you across a range of wellbeing needs 

Diversity & Inclusion: 

At DEFEND, we celebrate a variety of perspectives and experiences. We know from experience that people from underrepresented groups often don’t apply for roles they don’t feel they meet all the criteria for. We’re committed to creating an environment that enables all our team to thrive. If you think you have what it takes, but don’t check every single box, please consider applying. We’d love to hear how you might contribute to the team and being our next DEFENDer. 

Skills Required

  • Experience implementing industry standards and regulations (ISO, NIST, GDPR, COSO)
  • Experience maintaining company certifications such as ISO and SOC 2
  • Strong understanding and experience of risk management frameworks and processes
  • Experience with data governance and maintaining data governance programs
  • Experience conducting customer, software, project, privacy, and vendor/supplier risk assessments
  • Experience updating and maintaining policies and procedures
  • Leadership and communication skills to convey risks and recommendations to stakeholders
  • Project management skills to manage GRC initiatives and meet deadlines
  • Collaboration skills to work with cross-functional teams and stakeholders
  • Experience preparing for and managing regular audits like ISO and SOC 2
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Albany
121 Employees
Year Founded: 2015

What We Do

DEFEND are an independent agnostic cyber security partner. Security practice leading capability in: - Auditing and Compliance (NIST Framework) - Business C-Level/Board consultancy (Virtual CISO) - Cloud/Data Centre Connect - Service Provider independent compliance - Network (WAN/LAN/Wi-Fi/Telco) - Application performance & secure coding - End point and End User protection - Threat Education & Intelligence - BCP & DR DEFEND develop and provide managed cyber security outsourcing & consulting services across industry verticals. DEFEND support and assist customers to ensure they have access to the best people, process and technology to mitigate and reduce business risk from Cyber-attacks. DEFEND are a specialist threat protection, intelligence and detection company providing services across ANZ . DEFEND are heavily focus on end user centric threat management solutions. DEFEND provide guidance and leadership within your disaster recovery (DR) and business continuity planning (BCP). We provide an aggregated security procurement management service to ensure our customer obtain the most effective access to services, solutions and pricing. Our objective is to attract only the most credible and capable people to join our team. We ensure our customers have a safe pair hands to call upon proactively and reactively in their time of need. If you want to join DEFEND or would allow us the privilege to become your partner then please contact us.

Similar Jobs

Cin7 Logo Cin7

Onboarding Specialist

Cloud • eCommerce • Logistics • Software
Easy Apply
Hybrid
Auckland, NZL
276 Employees
65K-75K Annually

Halter Logo Halter

Data Analyst

Greentech • Hardware • Internet of Things • Machine Learning • Software • Business Intelligence • Agriculture
In-Office or Remote
2 Locations
350 Employees

Xero Logo Xero

Engineering Manager

Cloud • Fintech • Information Technology • Machine Learning • Software
Hybrid
3 Locations
4500 Employees

Xero Logo Xero

Senior Account Executive

Cloud • Fintech • Information Technology • Machine Learning • Software
Hybrid
Auckland, NZL
4500 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account