
// Open Role at Aristocrat Gaming
Join Aristocrat Gaming's Cyber GRC team as an Application Risk Analyst to conduct technical risk assessments, ensure cybersecurity compliance, and contribute to a secure IT infrastructure in a world-leading gaming technology company.
At Aristocrat, we are driven by our mission to bring happiness to life through the power of play. We are a world-class team united by our passion for gaming and innovation, continually striving for excellence. As a Cyber Specialist, you'll be at the forefront of our cybersecurity efforts, ensuring our system, products, and processes are secure. This role is pivotal in maintaining our flawless security standards, and you'll have the chance to create a significant impact on our organization. Join us in our ambitious journey and be part of a team that values collaboration, inclusion, and continuous improvement!
This is a hybrid position based in Krakow, in the Unity Tower office. Team members are required to be in the office three days per week, with flexibility to select their in-office days based on personal preference and business needs.
What You'll Do
Perform technical security assessments of web apps, mobile apps, APIs, applications, systems, cloud services, technology platforms, business processes, and third-party solutions.
Evaluate application security controls, including authentication, authorization, session management, encryption, secrets management, logging, and secure configuration practices to detect potential risks, control gaps, and areas for improvement.
Develop practical, risk-based recommendations that balance security, operational requirements, and business objectives.
Document findings, conclusions, and risk decisions in a clear and professional manner.
Review evidence supporting security controls and evaluate control efficiency.
Produce executive-ready assessment summaries, threat analysis, and remediation recommendations.
Present findings to both technical and non-technical audiences.
Support reporting on assessment activity, emerging risks, remediation efforts, and security trends.
Review vendor security questionnaires, SOC reports, certifications, penetration testing reports, and supporting security documentation.
Evaluate the security measures of potential and current vendors, SaaS providers, cloud service providers, and technology partners.
Partner with Procurement, Legal, business teams, and vendors to resolve security concerns and detail residual risk.
Assist with internal audits, external audits, client assurance requests, and regulatory examinations.
Have a current, working awareness of ISO 27001, NIST CSF, NIST 800-53 and CIS Controls, PCI DSS, NIS2, OWASP, GLI and applicable regulatory requirements.
Contribute to the ongoing improvement of security assessment processes, templates, standards, and reporting practices.
What We're Looking For
Bachelor's degree in Cybersecurity, Information Security, Information Systems, Risk Management, Audit, Computer Science, or a related field, or equivalent experience.
Minimum of 5+ years of experience in cybersecurity, IT risk, IT audit, compliance, third-party risk management, security assessments, or related field.
Proven experience conducting independent security assessments and detailing risk-based findings.
Experience reviewing architecture and infrastructure security controls, vendor documentation, SOC reports, audit artifacts, remediation plans, and compliance evidence.
Experience collaborating within enterprise technology settings, cloud platforms, and third-party service vendors.
At least one of the following certifications: CISSP, CISA, CRISC, GIAC certifications (others are strongly preferred).
Experience performing vendor risk assessments or third-party security reviews.
Experience supporting audits, examinations, or client assurance activities.
Familiarity with cloud security, application security, identity and access management, or data protection controls.
Experience using GRC, workflow, ticketing, or evidence management platforms.
This job description may have been reviewed and enhanced using AI-assisted tools to improve clarity, consistency, and inclusivity. All final content, role requirements and hiring decisions remain subject to human review and approval by Aristocrat.
We offer a comprehensive pay and benefits package designed to stay competitive in the market, support your wellbeing, and recognise your contribution to our success. Our approach is underpinned by a pay-for-performance belief in rewarding individual impact. Your specific compensation package will be determined by factors such as your skills, experience, qualifications, and location.
Depending on your role and location, you may be eligible for annual bonuses and incentives, health and wellbeing benefits, paid time off, retirement plans, insurance coverage, and other local or statutory benefits.
Specific details about compensation and benefits for this position will be discussed during the recruitment process.
- Conduct technical application and third-party risk assessments to identify cyber vulnerabilities and operational and regulatory threats.- Collaborate with agile Product teams and GIS to implement mitigating technical controls aligned with GIS policies and regulatory standards.- Prepare detailed assessment reports for Business Unit owners, highlighting key risks and policy exceptions through threat modeling.- Partner with GIS and Business Units to develop and implement risk exception plans and strategies.- Support the development of automated quantitative and qualitative risk analyses and reporting processes.- Liaise with internal and external auditors to provide documentation and evidence for compliance with international security standards (SOC-2, ISO 27001, PCI DSS, NIST CSF 2.0).- Provide mentorship on changes in product security and regulatory landscapes, updating Aristocrat’s Security Policies, Standards, and Technical Security Requirements as needed.- Support the delivery of the wider GIS Security program in line with Aristocrat’s strategy and important metrics.- Self-motivated and adaptable to an ever-changing cybersecurity environment.- Excellent collaboration skills, eager to work as part of a cohesive, distributed team.- Outstanding analytical and critical thinking skills.- Comprehensive communication skills, including effective listening, data gathering, and idea articulation.- 5+ years of experience in information security with a relevant degree.- Familiarity with cybersecurity industry standards and frameworks such as NIST CSF, NIST 800-53, ISO 27001, and PCI DSS.- Candidates must be authorized to work in the job posting location for this position on a full-time basis without the need for current or future visa sponsorship.