About this role
<p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="background-color:white"><strong><span style="font-family:Verdana, sans-serif">You’re only human. </span></strong></span></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Verdana, sans-serif;background-color:white">It’s a strange thing to say, because us humans are capable of incredible things. And at Medibank, we know our greatest potential lies in the people who work with us. </span></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Verdana, sans-serif;background-color:white">We strive to make real, fundamental change, driven by a simple purpose: to create the best health and wellbeing for all of Australia. </span></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p><p><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><strong>About the role:</strong></span></p> <p><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">We are looking for a Senior GRC Specialist to support implementation, maintenance and continuous improvement of operational risk and control frameworks across D&T. This role combines day-to-day risk management advisory (Line 1.5) with governance design, GRC system administration and regulatory alignment (APRA CPS 220/230/234, ISO 27001/27005, FAR, NIST Cybersecurity Framework). You will work closely with D&T teams, Group Risk & Compliance (Line 2), Internal Audit (Line 3), Legal, Privacy and other stakeholders to embed a strong risk culture and deliver timely, audit ready governance reporting. </span></p> <p> </p> <p><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><strong>Key responsibilities:</strong></span></p> <ul> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Maintain and improve D&T risk and control frameworks: update taxonomies, controls libraries and governance protocols. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Operate and administer the GRC system: maintain risks, controls, obligations, actions and KRI registers; ensure data integrity and accurate linkages. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Conduct risk assessments for business and technology activities; evaluate control effectiveness and recommend treatments. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Monitor KRIs and action tracking; flag trends and breaches and escalate appropriately. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Prepare risk dashboards, heatmaps and materials for governance forums, Board/Executive reporting and the CIO/D&T leadership. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Support obligation management and the annual risk profiling process. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Contribute to governance forums and cross functional risk initiatives; collaborate with Group Risk, Security, Technology and Business teams. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Ensure compliance with relevant regulatory and industry frameworks; support internal and external audits and attestation processes. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Promote continuous improvement of GRC practices and risk governance across D&T. </span></li> </ul> <p> </p> <p><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><strong>What we’re looking for: </strong></span></p> <ul> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">5+ years’ experience in risk governance or risk management roles within technology, security or data domains. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Hands on experience with operational risk frameworks, risk assessments and control monitoring. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Practical experience with GRC tools (risk registers, controls, actions, issues). </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Familiarity with APRA CPS 220/230/234, ISO 27001/27005, FAR, NIST Cybersecurity Framework or similar. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Proven ability preparing risk reporting and materials for management and governance forums; experience maintaining KRIs. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Strong analytical, communication and stakeholder engagement skills; detail oriented and audit ready documentation focus. </span></li> </ul> <p> </p> <p><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><strong>Desirable: </strong></span></p> <ul> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Degree in Risk Management, Business, IT or related field. </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Governance/risk certifications (CRISC, CISA, CGEIT, COBIT, ISO 31000). </span></li> <li style="font-family:helvetica, arial, sans-serif;font-size:12.0pt"><span style="font-family:helvetica, arial, sans-serif;font-size:12.0pt">Experience in regulated industries such as health insurance or critical infrastructure. </span></li> </ul><p> </p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"><strong><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">Imagine working with us </span></strong></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">We understand that work means different things to everyone... We know happy, healthy people make great teams, and great teams put more heart into each customer and patient interaction. And that</span><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">’</span><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">s why we</span><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">’</span><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">re reinventing work. </span><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white"> </span></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">Imagine a workplace that helps you and your family thrive. Where connection, personal development and health and wellbeing are front of mind. To learn more about our benefits go to https://careers.medibank.com.au/culture/rewards-benefits/</span></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">For you, work should help you Live Better. It should bring you fulfillment and joy. And with Medibank, it could. </span></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"><strong><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">Inclusion and Accessibility </span></strong></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">We believe in everyone's potential and strive to make Medibank inclusive for all because different perspectives make us better. We encourage applications from everyone, including Aboriginal and Torres Strait Islander peoples, neurodivergent candidates, LGBTQIA+ community including transgender and gender diverse candidates and candidates with a disability.</span></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">If you need adjustments or alternative formats at any stage of the recruitment or employment journey, we’re here to help. You can let us know directly in the application form, or if you’d prefer to discuss before applying, please reach out to us </span><span style="font-family:Verdana, sans-serif;color:#00b0f0;background-color:white">[email protected] </span><span style="font-family:Verdana, sans-serif;color:#404040;background-color:white">or (03) 8622 5666. Learn more about our commitments and employee stories at https://careers.medibank.com.au/diversity-inclusion</span><span style="font-size:11.0pt;line-height:115%;font-family:Verdana, sans-serif;color:#404040;background-color:white">/(please copy and paste the URL onto your browser)</span></p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0cm;line-height:115%;font-size:12.0pt;font-family:'Times New Roman', serif"><strong><span style="font-size:11.0pt;line-height:115%;font-family:Verdana, sans-serif;color:deepskyblue;background-color:white">Medibank proudly recognised as Best Enterprise Organisation, 2026 AFR BOSS Best Places to Work</span></strong><span style="font-size:11.0pt;line-height:115%;font-family:Verdana, sans-serif;color:black;background-color:white"> </span></p>