GRC Manager - Cybersecurity

DEFEND Limited, Wellington, New Zealand

What our tracking knows about this posting

Published on 30 September 2026 · first appeared in our records on 1 October 2026.

Stable posting: first seen on 1 October 2026, with no abnormal reposting.

This posting shows no salary, while 22% of open postings in the same sector in this country (New Zealand) do.

View the posting at the employer Have my resume reviewed for this job
At DEFEND, our dream is to improve everyday life by creating a cyber resilient world. We're looking for a GRC Manager to help protect and strengthen our business by managing our governance, risk, compliance, security and privacy capability. This is a unique opportunity to influence business strategy and work closely with the senior stakeholders, to ensure DEFEND continues to operate with the highest standards of trust, resilience and assurance. What you will do • Manage DEFEND's GRC capability by leading and continuously improving our governance, risk, compliance, security and privacy frameworks. •   Maintain trust and assurance through the successful renewal of DEFEND’s ISO certifications and SOC 2 attestations, plus other security, privacy and compliance obligations. • Embed risk into decision making partner with leaders across the business by integrating risk management into everyday operations. • L ead enterprise risk activities including customer, supplier, project, software and privacy risk assessments. • Strengthen DEFEND's security posture through policy development, control uplift, data governance and security awareness initiatives. • Support strategic outcomes contribute to DEFEND's cybersecurity roadmap and advise on key security, privacy and risk decisions. • Provide trusted executive reporting to the ELT, Board and governance forums on risk, compliance, privacy and security matters. The skills & experience you will bring to DEFEND • Proven experience in Governance, Risk and Compliance (GRC), information security, privacy, risk management or related disciplines. • Strong working knowledge of recognised frameworks and standards such as ISO 27001, SOC 2, NIST, COSO, GDPR and other relevant regulatory requirements. • Demonstrated experience developing, implementing and continuously improving risk management and compliance frameworks. • Experience leading or coordinating external audits, certifications and assurance activities. • Strong understanding of governance practices, risk management methodologies and compliance obligations. • Excellent communication skills, with the ability to influence and engage stakeholders from operational teams through to Executive and Board level. • Proven ability to translate complex risk and compliance requirements into practical business solutions. • Strong project management and organisational skills, with the ability to juggle competing priorities and deliver outcomes in a dynamic environment. • A highly collaborative approach and the ability to build trusted relationships across a diverse range of stakeholders. • Experience responding to security, privacy or compliance incidents would be highly regarded. • A continuous improvement mindset and a genuine passion for creating secure, resilient organisations. • Comfortable rolling up your sleeves, adapting to change and contributing wherever needed to support the wider DEFEND business.

Other recent postings in the same sector