IT Risk and Governance Analyst

Summary

IT Risk and Governance Analyst driving GRC, IT risk lifecycle management, audits and compliance for Asahi Beverages' security program. Works with NIST, Essential Eight, SOX/JSOX, cloud security and AI governance in a hybrid (3 days office) Melbourne-based role.

Salary: Laptop + phone + hybrid working 3 days in office

Your Impact

We are seeking an IT Risk and Governance Analyst to play a key role in driving our governance, risk, and compliance (GRC) framework across Asahi Beverages. You will play a critical role in ensuring our IT security practices align with regulatory requirements, industry standards, and internal policies, while proactively managing risk across its full lifecycle. You will help embed strong risk management practices, support audit and compliance activities, and provide meaningful insights into our risk posture.

With exposure to emerging areas such as cloud security and AI governance, this is an exciting opportunity to contribute to forward-looking security initiatives while strengthening foundational controls and processes in a collaborative and high-impact environment.

Key Responsibilities

  • Manage and maintain the IT risk lifecycle, including identification, remediation, and reporting

  • Support internal and external audit activities and compliance processes

  • Maintain risk registers and track remediation plans

  • Ensure alignment with frameworks such as NIST, Essential Eight, SOX/JSOX

  • Assist in developing and maintaining security policies, standards, and procedures

  • Monitor and report vulnerabilities and patch management status

  • Collaborate with IT teams to ensure timely risk remediation

  • Support access management processes including RBAC, PAM, and User Access Reviews (UAR)

  • Work within ITSM frameworks (Change, Incident, Problem, Request)

  • Provide regular reporting and insights to senior stakeholders, including executive-level reporting

  • Contribute to governance of AI and cloud environments

About You

  • Experience as a consultant or senior consultant within IT risk management, GRC, cybersecurity, or IT audit within professional services firms

  • Strong understanding of IT risk management, compliance and audit practices

  • Relevant certifications such as CISA, CRISC, ISO 27001, or Security+ highly desired

  • Proven experience working with security frameworks such as SOX/JSOX, NIST and Essential Eight highly regarded

  • Excellent stakeholder engagement and communication skills

  • Exposure to cloud security and AI governance highly desirable

Why Asahi Beverages?

At Asahi Beverages, we're passionate about crafting more than just drinks - we craft moments of connection, celebration, and shared enjoyment. We bring together a diverse portfolio of iconic beverage brands, a commitment to quality, and a drive to constantly innovate. Headquartered in Melbourne and with facilities right across Australia and New Zealand, you’ll find Asahi is a place where talent is nurtured, and ambition is rewarded. If you’re ready to toast your future, we’re ready to meet you.

We are a Circle Back Initiative employer and commit to responding to all applicants.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available