Risk & Compliance Analyst

Location
Sydney
Workplace
Hybrid

About this role

PURPOSE OF THE ROLE

The Risk & Compliance Analyst plays a key Line 2 oversight role in strengthening enterprise‑wide risk management, risk & compliance governance and resilience. The role supports independent challenge, insights‑driven analysis, and high‑quality risk and compliance reporting to support Executive and Board decision‑making.

A critical focus of the role is supporting the organisation in maturing risk & compliance management including APRA CPS 230 by enhancing risk & compliance practices. The role also enhances data integrity, predictive analytics and real‑time monitoring across the GRC environment to enable proactive identification of emerging risks and control weaknesses.

KEY RESPONSIBILITIES

Risk & Compliance Reporting, Insights and Analytics

· Develop, maintain, and continuously enhance enterprise risk, compliance and resilience dashboards with predictive and early‑warning indicators.

· Produce high‑quality, insight‑driven reporting for the Board, Executive and Risk Committees, translating complex risk, compliance and resilience data into succinct senior‑level narratives.

· Support deep‑dive / thematic analysis on emerging risks, operational incidents, breaches, change‑related impacts and resilience vulnerabilities.

· Develop trend, scenario‑based and predictive insights to support proactive management of risk exposures and regulatory obligations.

· Ensure continual Risk & Compliance oversight of GRC data

GRC Systems, Data Quality & Technology Enablement

· Serve as a functional specialist for the enterprise GRC platform (e.g., Protecht, Archer), including workflow, taxonomy, hierarchy and data model design.

· Maintain and enhance GRC data structures to improve accuracy, completeness, lineage, and integrity of risk‑related data.

· Partner with technology teams to optimise system integrations and automation to enhance real‑time reporting capability.

· Conduct recurring data quality reviews, integrity testing and cleansing to ensure reliable operational risk, resilience and compliance data for decision‑making.

CPS 230 Operational Risk & Resilience Oversight

· Have effective understanding of Operational Risk and Compliance frameworks, structures and approaches including APRA & ASIC requirements.

· Support Line 2 oversight of operational risk management consistent with APRA CPS 230, including operational risk profile development, control effectiveness monitoring and exposure trend analysis.

· Assist in the review and challenge of critical operations mapping, impact tolerances, scenario testing design, results analysis and resilience uplift activities.

· Supporting Line 2 analysis of root causes, escalation quality, recovery timeframes and compliance with CPS 230 reporting expectations.

Governance, Compliance & Regulatory Support

· Support monitoring and reporting of regulatory obligations including APRA and ASIC requirements.

· Assist in uplift of frameworks, policies, and procedures in line with evolving regulatory expectations

· Monitor adherence to the risk appetite statement and thresholds, advising where metrics indicate deteriorating risk posture.

· Manage Line 2 thematic reviews and targeted control assessments to provide assurance over key risk and compliance domains.

Stakeholder Engagement, Culture & Capability Uplift

· Promote a strong risk, compliance and resilience culture across the organisation through training, coaching and advisory support.

· Build relationships with business units, change teams and service provider oversight teams to uplift risk literacy and effective risk management behaviours.

· Provide tailored Line 2 guidance to improve understanding and usage of GRC tools, and quality of reporting inputs.

· Collaborate across business functions to ensure clear, consistent, and timely risk management communications.

ROLE REQUIREMENTS

· Reporting: This role reports to the Manager, Risk

· Education: Bachelor’s degree in finance, Business, Risk Management, or a related field. A professional certification (e.g., CA, CFA, FRM) is highly regarded.

· Experience: 3-8 years of experience in risk & compliance management in financial services in Australia or similar regulated jurisdiction.

Technical Skills

o Demonstrated understanding of APRA and ASIC regulations, with strong working knowledge of CPS 230, CPS 220, CPS 234 and risk in change governance.

o Advanced analytical and problem‑solving skills, including use of BI tools, data modelling and predictive analytics.

o Strong capability in GRC platforms and risk data structures.

o Ability to interpret and communicate complex risk and resilience insights to Executive‑level audience.

Personal Attributes:

o High ethical standards and integrity.

o Detail-oriented with a proactive approach to risk & compliance management.

o Strong organisational and time management skills.

o Ability to work in a dynamic and fast-paced environment.

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?