This is a hands-on role requiring strong judgement, regulatory and technical literacy, and the ability to balance safety, fairness, and commercial realities in complex, fast-moving environments.
Key Responsibilities
- Monitor and review compliance with applicable legislative and regulatory obligations, including the Australian Consumer Law, NDIS Act and Rules, Aged Care Act and Quality Standards, Privacy Act, and Australian Privacy Principles.
- Support the development, implementation, and continuous improvement of Attain Group’s risk and compliance framework.
- Identify, assess, and manage operational, regulatory, privacy, and consumer risks, and assist in maintaining risk registers, reporting, and governance documentation.
- Assist with the management, investigation, and escalation of incidents and breaches, including NDIS reportable incidents, SIRS matters, safeguarding concerns, and privacy breaches.
- Coordinate responses to actual or suspected data breaches, including assessing reporting obligations and supporting regulatory compliance.
- Partner with internal stakeholders to embed risk and compliance requirements into business processes, systems, and platform design.
- Liaise with regulators, auditors, and other external stakeholders as required.
- Provide practical guidance on risk and compliance matters and support the development and delivery of training, resources, and initiatives that strengthen safeguarding and consumer protection outcomes.
Key Capabilities and Experience
- Bachelor's degree in law, business, commerce, risk, compliance, or a related discipline.
- Demonstrated experience in risk, compliance, governance, or regulatory roles, ideally within a regulated or consumer-facing environment.
- Knowledge of Australian regulatory frameworks relevant to digital platforms, care services, privacy, or consumer protection.
- Strong judgement, problem-solving skills, and the ability to assess risk and make balanced, practical decisions.
- Confidence to identify, escalate, and challenge risks where required.
- Experience in the NDIS, aged care, health, or other regulated sectors is desirable.
- Exposure to incident management, safeguarding, privacy breach response, or platform-based business models is advantageous.
- Strong ethical judgement, a safeguarding mindset, and a commitment to consumer protection.
- Pragmatic, solutions-focused, and comfortable working with ambiguity.
- Clear communicator with the ability to engage effectively with a broad range of stakeholders.
- Strong attention to detail while maintaining a focus on broader risk and business outcomes.