Posted 31 July, 2026
Senior Cyber GRC Engineer
Wesfarmers Corporate Office
Melbourne VIC,Australia,Australia
Full Time
Reference: 388_546192_KBN3Y
Apply Job no: KBN3Y Drive cyber and technology GRC uplift across Corporate Office including OneDigital, making risk visible and actionable Embed practical frameworks, tools and ways of working to strengthen governance and assurance Operate with autonomy, translating complex cyber, technology and AI risk into clear business decisions About the team Wesfarmers' Technology team plays a key role in enabling secure, reliable and high-performing technology services across the Corporate Office, including OneDigital. Through innovation, automation and data-led insights, we deliver solutions that support long-term business objectives and protect our digital assets. Within Technology, the Cyber Security team focuses on strengthening the resilience of our digital environment. The team spans three core areas: Engineering and Architecture, Cyber Governance, Risk and Compliance, and Defensive Cyber Operations. We foster a collaborative environment where team members can do meaningful work, build capability and contribute to outcomes that matter across the Corporate Office. About you To be successful in this role, you will arrive with depth to your technical capability in cyber and technology GRC, including risk assessment, control effectiveness, compliance frameworks, automated control monitoring and remediation oversight. You will be a proactive and practical GRC specialist who can communicate risk clearly, and partner confidently with technical and non-technical stakeholders to ensure controls and risk management decisions are proportionate and sensible. You will also bring a working understanding of emerging AI cyber and technology risks, including risks linked to approved and unapproved AI tools. Just as importantly, you will know how to establish risk practices through people - building awareness, supporting consistent ways of working, and reinforcing pragmatic decision-making. What you'll do As a hands-on expert, you'll embed strong cyber and technology risk management across Wesfarmers Corporate Office, including OneDigital. You will deepen capability, strengthen reporting and metrics, and support a risk-aware culture that enables secure innovation. There are sound practices in place, and a genuine maturity journey ahead for you to drive with the team. Reporting to our Cyber Security Manager, you will take responsibility for the following deliverables: Clarifying risk: identify, assess and prioritise cyber and technology risk across Corporate Office, including OneDigital, translating risk clearly for different audiences so decisions are informed, proportionate and aligned to business priorities Leading remediation and assurance: close control gaps with clear guidance and reporting, and drive controls testing across Line 1 and Line 2 risk, risk assessments and risk forums Managing third-party and supplier risk: conduct vendor assessments and due diligence, ensuring insights are shared and acted on across relevant teams Assessing AI cyber risk: manage the risks introduced by approved and unapproved AI tools including data leakage, model misuse and prompt injection, partnering with the teams that own AI governance Strengthening governance frameworks: develop, embed and maintain frameworks, policies and consistent practices that align with business objectives and adapt to emerging threats Automating monitoring and reporting: build dashboards and metrics that give continuous oversight of controls and enable insight-driven decision-making Partnering across the Group: collaborate with OneDigital and Corporate leaders, Group Cyber Security and Group Risk to integrate controls, manage expectations and drive capability uplift, and share knowledge with GRC functions across Wesfarmers divisions What you'll need Tertiary qualifications in Computer Science, Software Engineering, Information Technology, Cyber Security or a related discipline, or equivalent experience Relevant industry certification such as CISSP, CRISC, CISA, CISM, ISO 27001 Lead Implementer/Auditor or a related cyber security certification 5+ years' experience in cyber governance, risk and compliance, including cyber risk assessment, control effectiveness, remediation oversight and compliance frameworks Strong knowledge of cyber security governance frameworks, risk management methodologies and compliance practices Experience designing or improving control monitoring, reporting, metrics and remediation tracking, including through automation where appropriate Working understanding of AI cyber and technology risk Ability to communicate risk clearly to a technical and non-technical audience of varying levels of seniority in support of practical, proportionate decision-making Exposure to relevant tools and environments such as UpGuard, Archer, Microsoft Defender Suite, Tenable, AWS, Azure, GCP and corporate desktop operating environments About Wesfarmers As one of Australia's largest listed companies, we're proud of our longstanding contribution to Australians. We continually reinvent ourselves and invest in the businesses we own and operate, including leading retailers like Bunnings, Kmart, Target, Officeworks and Priceline. We also have an online offering, including OnePass and the Group shared data asset. Our work doesn't stop there, we operate in the industrials sector which supplies the nation with chemicals, energy and fertilisers, and industrial and safety products. And we participate in an integrated lithium joint venture, including the operation of a mine and concentrator and the development of a refinery. Join the team at Corporate Office which provides support and advice across the Wesfarmers Group The Corporate Office provides corporate services and support to the autonomous businesses within the Wesfarmers Group, enabling the achievement of Group objectives. It leads capital allocation and portfolio management for the Group and focuses on leveraging and enhancing the Group's reputation to support attraction and retention of talent, securing investment opportunities and maintaining a low-cost capital. To do this, we need great people, working together and role modelling our values and ways of working. Our culture We're focused on results, but we're a business that cares. Here we are less about titles and more about everyone playing a valuable role. We provide autonomy and space with freedom to operate, quickly learning from mistakes because we know they are part of the way forward. We're curious, open minded, and collaborative. And although we're thought leaders, we're humble, and willing to share knowledge and learn from one another. We know that diversity fosters greater innovation and better customer connection, so we strive to create an inclusive and diverse work environment. Next steps If this sounds like your next career move, then combine your cover letter and resume into one document and click on the 'Apply' button by Friday, 14 August 2026. Please note that we may commence interviewing of candidates prior to this closing date. For brief enquiries please contact Wesfarmers Corporate Talent Acquisition via [email protected] We're hiring the best and the brightest talent. Let's start to explore the possibilities of achieving great things together. For more information, visit our website at https://www.wesfarmers.com.au Related documents Senior Cyber GRC Engineer (Wesfarmers) - Ad 2026 Published on 31 Jul 2026, 12:09 AM