Head of Cyber GRC
Job in
Richmond, Chesterfield County, Virginia, 23234, USA
Listed on 2026-07-15
Listing for:
REA GROUP LTD
Full Time
position Listed on 2026-07-15
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below
* Lead the next evolution of cyber GRC at REA through platform, automation and smarter risk reporting
* Shape how a product-led technology organisation understands and reduces cyber risk
* Lead a distributed team across Australia and India while partnering closely with senior leaders
We're REA
With bold and ambitious goals, REA Group is changing the way the world experiences property. No matter where you're at on your property journey, we're here to help with every step - whether that's finding or financing your next home. Our people are the key to our success. At the heart of everything we do is a thriving culture centred around high performance and care.
We are purpose driven and collaborative, which drives innovation and our ability to make a real impact.
As such, we're proud to have been named one of Australia's Best Workplaces four times since 2021 - including third place in 2025 - plus Best Workplace for Women in 2023 and Best Workplace in Technology in 2024 and 2025. These listings are testament to every person who helps make REA a great place to work.
Where the team fits in
Our Cyber Governance, Risk and Compliance team exists to ensure REA has a shared understanding of cybersecurity risk, a practical approach to compliance, and a policy and control environment that is simple to understand and apply.
This team is already well established, but the way it works needs to evolve. That evolution is at the heart of this role. You'll be the person our leaders turn to when deciding what to work on next - driving a shared understanding of our cyber risks.
What the role is all about
This is a rare opportunity to reshape how cyber GRC is done inside a modern product and technology business. Over your first year, you will make the case for and implement a GRC platform, overhaul how we measure and report cyber risk, automate compliance evidence collection, and modernise or replace existing processes so the team's time is invested where it most reduces risk.
You'll be the clearest voice on cyber risk at REA, helping leaders make better decisions about what to prioritise and why. You'll sit on the Security leadership team and work closely with peers across Product Security, Enterprise Security, and Detection and Response.
Day to day, you can expect to:
* Drive a shared understanding of cyber risk across the security organisation and broader business so investment is focused on the controls and remediation that most reduce risk
* Establish, manage and report on security metrics that make performance, exposure and priorities easy for the business to understand
* Support the CISO with regular reporting to senior governance forums and provide confident, constructive challenge when priorities need to shift
* Lead the Cyber GRC team through a shift from routine process execution to higher-value, risk-focused work
* Directly manage the Australian team and provide functional leadership to team members in India, in partnership with their local people manager
* Lead the Business Information Security Officer capability, including the current BISO supporting Financial Services
* Lead the selection, business case creation and implementation of a GRC platform
* Redesign the third-party risk process so it delivers more signal with far less effort
* Establish automated compliance artefact collection to support efficient certification and assurance activity
* Ensure the business understands and manages its obligations across standards including ISO 27001, PCI-DSS and SOC 2
* Oversee the ongoing measurement of cyber maturity using NIST CSF
* Own cybersecurity policies and key governance controls, ensuring they are pragmatic, clear and aligned to business needs
* Establish REA's approach to supporting minority investments with cyber advice and visibility of cyber risk
* Support cyber due diligence on future acquisition targets
Who we're looking for:
You're someone who loves technology and enjoys improving the way work gets done. You understand how product development organisations operate, and you know how to make the right way the simplest way.
We're looking for someone with:
* A track record of delivering technology-enabled change in GRC,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×