Cybersecurity Risk Analyst
Aristocrat TechnologiesAt Aristocrat, we believe in bringing happiness to life through the power of play. We are a world leader in gaming content and technology. We are committed to crafting a vibrant and inclusive environment where innovation thrives. Our culture focuses on collaboration, excellence, and positively impacting the gaming industry. The Application Risk Analyst role in our Cyber Governance, Risk, and Compliance (GRC) team is key to meeting cybersecurity goals and ensuring regulatory compliance across all units. This is an outstanding opportunity to join a dynamic team and help maintain a secure and resilient IT infrastructure!
What You'll Do
- Conduct technical application and third-party risk assessments to identify cyber vulnerabilities and operational and regulatory threats.
- Collaborate with agile Product teams and GIS to implement mitigating technical controls aligned with GIS policies and regulatory standards.
- Prepare detailed assessment reports for Business Unit owners, highlighting key risks and policy exceptions through threat modeling.
- Partner with GIS and Business Units to develop and implement risk exception plans and strategies.
- Support the development of automated quantitative and qualitative risk analyses and reporting processes.
- Liaise with internal and external auditors to provide documentation and evidence for compliance with international security standards (SOC-2, ISO 27001, PCI DSS, NIST CSF 2.0).
- Provide mentorship on changes in product security and regulatory landscapes, updating Aristocrat’s Security Policies, Standards, and Technical Security Requirements as needed.
- Support the delivery of the wider GIS Security program in line with Aristocrat’s strategy and important metrics.
What We're Looking For
- Self-motivated and adaptable to an ever-changing cybersecurity environment.
- Excellent collaboration skills, eager to work as part of a cohesive, distributed team.
- Outstanding analytical and critical thinking skills.
- Comprehensive communication skills, including effective listening, data gathering, and idea articulation.
- 5+ years of experience in information security with a relevant degree.
- IT Audit, Internal Audit, and/or cyber advisory experience are a plus.
- Familiarity with cybersecurity industry standards and frameworks such as NIST CSF, NIST 800-53, ISO 27001, and PCI DSS.
- Preferred certifications: CISSP, CCSP, CISM, CISA, CompTIA Security+, GIAC.
Compensation Philosophy
We offer a comprehensive pay and benefits package designed to stay competitive in the market, support your wellbeing, and recognise your contribution to our success. Our approach is underpinned by a pay-for-performance belief in rewarding individual impact. Your specific compensation package will be determined by factors such as your skills, experience, qualifications, and location.
Depending on your role and location, you may be eligible for annual bonuses and incentives, health and wellbeing benefits, paid time off, retirement plans, insurance coverage, and other local or statutory benefits.
Specific details about compensation and benefits for this position will be discussed during the recruitment process.