Business Risk and Assurance Manager
Wellington, Wellington Region, New Zealand · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 ಗಂಟೆ ಹಿಂದೆ
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About DEFEND and Role Overview
DEFEND is dedicated to enhancing cyber resilience by delivering strategic, engineered solutions and specialized advisory services. Our mission is to help organisations protect their digital assets through cutting-edge technology and leading practices. The Business Risk and Assurance Manager will be pivotal in sustaining an effective Governance, Risk, and Compliance (GRC) framework internally, ensuring DEFEND remains accountable, transparent, and responsible to its stakeholders including customers, employees, and the broader community.
Key Responsibilities
- Ensure that DEFEND has strong security and privacy safeguards complying with regulatory and privacy mandates.
- Oversee maintenance of company certifications such as ISO and SOC 2.
- Enhance and sustain the enterprise risk and compliance frameworks and associated policies.
- Coordinate and supervise enterprise risk management activities function-wide.
- Conduct risk assessments related to customers, software, projects, privacy, and vendors/suppliers as necessary.
- Embed risk management principles into business operations.
- Improve and uphold data governance throughout the organisation.
- Review and refresh DEFEND policies and procedures annually at minimum.
- Support the formulation and implementation of the DEFEND cybersecurity roadmap.
- Respond effectively to internal cybersecurity and privacy incidents.
- Provide regular progress and status reports to the Executive Leadership Team, Board, and steering committees.
- Assist business units in implementing policy and managing risk parameters.
- Coordinate and deliver annual training on security and privacy awareness to all employees.
Required Experience and Skills
- Solid experience and knowledge in applying industry standards and regulations such as ISO, NIST, GDPR, and COSO.
- Comprehensive understanding and hands-on experience with risk management frameworks and processes.
- Awareness of business governance roles and procedures.
- Strong leadership abilities with effective communication skills to relay risks, compliance requirements, and recommendations clearly to stakeholders and teams.
- Project management capabilities to oversee GRC initiatives, prioritize activities, and adhere to deadlines.
- Ability to collaborate with cross-functional groups and maintain productive relationships internally and externally.
- Preferred prior exposure to managing audits like ISO and SOC 2.
Benefits and Company Culture
At DEFEND, we strive to improve daily life by fostering a cyber resilient environment. Recognized through multiple industry accolades, including Microsoft's Global Partner of the Year for 2025, we are growing rapidly and value employee development. Joining DEFEND means working in a culture that encourages innovation, inclusivity, and professional growth.
- Employer contribution of 3.5% to Kiwisaver in addition to base salary.
- Comprehensive Southern Cross Health Insurance coverage.
- Discounts on mobile and broadband services for employees and their families.
- Flexible hybrid working arrangements.
- An allowance for home office equipment setup.
- Access to Employee Assistance Program services supporting a variety of wellbeing needs.
Diversity & Inclusion
DEFEND champions diverse perspectives and experiences. We encourage candidates from underrepresented backgrounds, even if they do not meet every requirement, to apply and share how they can contribute to our mission as valued team members.
Industry
Cybersecurity