Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
DEFEND

Business Risk and Assurance Manager

DEFEND

Business Risk and Assurance Manager strengthening DEFEND’s internal GRC, risk, compliance, and data governance frameworks. Supporting cyber resilience, audits, incident response, reporting, and security awareness across New Zealand operations.

Posted 8/12/2026full-timeAuckland • 🇳🇿 New ZealandMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in maintaining and uplifting enterprise risk and compliance frameworks, ensuring adherence to regulatory standards such as ISO and SOC 2. Proficient in risk management processes, data governance, and delivering cybersecurity training while effectively communicating with stakeholders.

Highest-signal resume keywords
ISO Certification ManagementSOC 2 ComplianceRisk Management FrameworksProject Management SkillsCybersecurity Incident Response

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentData GovernanceRegulatory ComplianceCybersecurity Roadmap DevelopmentPolicy and Procedure Maintenance
Soft Skills
Leadership SkillsCommunication SkillsCollaboration Skills
Certifications & Qualifications
ISO CertificationSOC 2 Certification
Industry Keywords
GRC FrameworkNISTGDPRCOSOEnterprise Risk Management

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Maintain an effective internal GRC framework ensuring accountability, transparency, and responsibility to stakeholders
  • Ensure robust security and privacy controls and compliance with regulatory and privacy requirements
  • Maintain current company certifications, including ISO and SOC 2
  • Maintain and uplift the enterprise risk and compliance framework and policies
  • Oversee and coordinate enterprise risk management activities
  • Complete customer, software, project, privacy, and vendor/supplier risk assessments
  • Integrate risk management into business processes
  • Uplift and maintain data governance across DEFEND
  • Maintain and update company policies and procedures at least annually
  • Assist in creating and delivering the cybersecurity roadmap
  • Respond to internal cybersecurity and privacy incidents
  • Provide regular reporting for ELT, Board, and steering committee meetings
  • Support the business in implementing policy and risk settings
  • Deliver annual security and privacy awareness training to all staff

Requirements

What you’ll need
  • Knowledge and experience implementing industry standards and regulations such as ISO, NIST, GDPR, and COSO
  • Strong understanding and experience of risk management frameworks and processes
  • Understanding of business governance functions and processes
  • Leadership and communication skills for communicating risks, requirements, and recommendations
  • Project management skills to manage GRC initiatives, prioritize tasks, and meet deadlines
  • Collaboration skills for working with cross-functional teams and internal and external stakeholders
  • Ideally, experience preparing for and managing regular ISO and SOC 2 audits

Benefits

Comp & perks
  • 3.5% KiwiSaver on top of your base salary
  • Southern Cross Health Insurance coverage
  • Mobile and Broadband discounts for yourself and family
  • Flexible, hybrid work environment
  • An allowance to contribute to your home office setup
  • Access to EAP services to support you across a range of wellbeing needs
  • Opportunities to advance skills and careers
  • Collaborative workplace culture
  • Inclusive environment where innovative thinking is encouraged
  • Opportunity to contribute to a variety of cybersecurity outcomes