About the Role
The Risk & Compliance Analyst is a key Line 2 oversight role focused on strengthening enterprise-wide risk management, governance, and resilience. This position supports independent challenge, data-driven analysis, and high-quality reporting for executive and board decision-making, with a critical focus on maturing risk and compliance practices, particularly in relation to APRA CPS 230.
Responsibilities
- Develop, maintain, and enhance enterprise risk, compliance, and resilience dashboards with predictive and early-warning indicators.
- Produce insight-driven reports for the Board, Executive, and Risk Committees, translating complex data into senior-level narratives.
- Support deep-dive analysis on emerging risks, operational incidents, breaches, change impacts, and resilience vulnerabilities.
- Develop trend, scenario-based, and predictive insights for proactive management of risk exposures and regulatory obligations.
- Ensure continuous Risk & Compliance oversight of GRC data.
- Support Line 2 oversight of operational risk management consistent with APRA CPS 230, including profile development, control effectiveness monitoring, and exposure trend analysis.
- Assist in reviewing and challenging critical operations mapping, impact tolerances, scenario testing, and resilience uplift activities.
- Support Line 2 analysis of root causes, escalation quality, recovery timeframes, and compliance with CPS 230 reporting expectations.
- Support Line 2 review and challenge of material change initiatives, assessing operational risk, resilience impacts, regulatory obligations, and delivery risks.
- Review pre-implementation risk assessments, control design sufficiency, and testing outcomes.
- Provide insights on recurring delivery risks, common control failures, and opportunities for uplift.
- Support monitoring and reporting of regulatory obligations, including APRA and ASIC requirements.
- Assist in uplifting frameworks, policies, and procedures in line with evolving regulatory expectations.
- Monitor adherence to the risk appetite statement and thresholds, advising on deteriorating risk posture.
- Manage Line 2 thematic reviews and targeted control assessments to provide assurance over key risk and compliance domains.
- Serve as a functional specialist for the enterprise GRC platform, including workflow, taxonomy, hierarchy, and data model design.
- Maintain and enhance GRC data structures to improve accuracy, completeness, lineage, and integrity of risk-related data.
- Partner with technology teams to optimize system integrations and automation for enhanced real-time reporting.
- Conduct recurring data quality reviews, integrity testing, and cleansing to ensure reliable data for decision-making.
- Promote a strong risk, compliance, and resilience culture through training, coaching, and advisory support.
- Build relationships with business units, change teams, and service provider oversight teams to uplift risk literacy and effective risk management behaviors.
- Provide tailored Line 2 guidance to improve understanding and usage of GRC tools and reporting input quality.
- Collaborate across business functions to ensure clear, consistent, and timely risk management communications.
Requirements
- 3-8 years of experience in risk & compliance management in financial services in Australia or a similar regulated jurisdiction.
- A working knowledge of APRA & ASIC regulations is highly preferred.
- Demonstrated understanding of APRA and ASIC regulations, with strong working knowledge of CPS 230, CPS 220, CPS 234 and risk in change governance.
- Advanced analytical and problem-solving skills, including use of BI tools, data modelling and predictive analytics.
- Strong capability in GRC platforms and risk data structures.
- Ability to interpret and communicate complex risk and resilience insights to an Executive-level audience.
- Strong understanding of risk in change, regulatory compliance management and resilience concepts.
- High ethical standards and integrity.
- Detail-oriented with a proactive approach to risk & compliance management.
- Strong organisational and time management skills.
- Ability to work in a dynamic and fast-paced environment.
Skills
- APRA CPS 230
- APRA CPS 220
- APRA CPS 234
- Risk in change governance
- BI tools
- Data modelling
- Predictive analytics
- GRC platforms
- Risk data structures
- Risk management
- Compliance management
- Resilience concepts
Experience Level
- 3-8 years
Education Level
- Bachelor’s degree in finance, Business, Risk Management, or a related field.
- Professional certification (e.g., CA, CFA, FRM) is highly regarded.
