Cyber Governance, Risk

1 week ago


Sydney, New South Wales, Australia King & Wood Mallesons Full time

New role to the firm - Enhance what we have and take the next step in your career- With a few years experience behind you, you will be looking to introduce what you've learnt in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.- As a leading law firm, we actively seek people from diverse backgrounds to enrich our culture and performance.

Who are we?

A firm born in Asia, underpinned by world class capability.

With over 3000 lawyers in 29 global locations, we help our clients manage their risk and enable their growth. Our full-service offering combines un-matched top tier local capability complemented with an international platform.


We have deep roots in Australia spanning almost 200 years and acknowledge Aboriginal and Torres Strait Islander peoples as the traditional owners and custodians of these lands and waters.

Role Detail


With a 'continuous improvement lens' on our cyber governance and compliance obligations, this new role to the firm will help us continue to lead in managing our cyber risk internal and external compliance obligations.

Freeing up the team to focus on their BAU, this role will give you the opportunity to enhance our cyber security culture through robust processes and reporting.


Based in the Sydney CBD office, with a balanced approach to WFH, you will play a key role in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.


Reporting to the Information Security Manager, you will also create and maintain documentation to demonstrate our adherence to organisational and regulatory policies, standards and best practices.

You will be integral with helping the firm manage third party vendor risk and meet its client information security compliance obligations.


Key responsibilities:

  • Manage and oversee the organisation's thirdparty vendor management program, including the assessment and ongoing monitoring of our vendors' cyber security practices.
  • Collaborate with internal stakeholders to identify and evaluate potential cyber security risks associated with thirdparty vendors.
  • Develop and maintain strong relationships with vendors to ensure compliance with contractual obligations and cyber security requirements.
  • Working closely with our Risk and Compliance team, respond to client thirdparty security audits by coordinating and providing necessary documentation, evidence, and responses to address audit findings.
  • Conduct regular assessments of vendors' cyber security controls, policies, and practices to identify potential vulnerabilities and areas for improvement.
  • Assist with maintaining our internal cyber security compliance programs, ensuring alignment with industry best practices and frameworks such as ISO Supporting the maintenance and operation of our policies, procedures and standards, registers, guides and reporting.
  • Supporting and coordinating internal and external audit programs.
  • Monitor and assess cyber security risks and compliance issues, providing recommendations for remediation and improvement.
  • Provide cyber risk support for projects and business as usual initiatives.
  • Stay up to date with emerging cyber security threats, trends, and regulatory requirements, and provide guidance on their potential impact on the organisation.
  • Collaborate with crossfunctional teams to develop and deliver cyber security awareness and training programs for employees.
  • Assisting the Head of Information Security and Information Security Manager with maintaining operational metrics on the effectiveness of the firm's Information Security program.
About You

Your natural curiosity will fit nicely, and your collaborative approach will be celebrated.

As the SME in this area, you will be looked to for direction which requires confidence in your ability, backed by the experience from lessons learnt.


You will also bring:

  • Solid knowledge of information security concepts and practices, such as risk assessment and assurance.
  • Strong knowledge of thirdparty vendor management principles, practices, and frameworks.
  • Proven experience in responding to client thirdparty security audits and addressing audit findings.
  • Indepth understanding of cyber security compliance frameworks, particularly ISO Familiarity with other relevant frameworks and regulations such as NIST, GDPR, or APRA CPS 234 is highly desirable.
  • Excellent analytical and problemsolving skills, with the ability to assess and mitigate cyber security risks effectively.
  • Strong communication and interpersonal skills, with the ability to collaborate with internal and external stakeholders at various levels.
  • Demonstrated ability to develop and implement cyber security compliance programs and policies.
  • Relevant certifications such as CISSP, CISM, CRISC, or ISO27001 Lead Auditor are highly desirable.
  • Proven ability to stay up to date with eme


  • Sydney, New South Wales, Australia Cyber Crime Full time

    Singtel The Singtel Group, Asia's leading communications group provides a diverse range of services including fixed, mobile, data, internet, TV, infocomms technology (ICT) and digital solutions. View company page We don't sit back and wait for the future to happen, we are out there crafting our own path through new technology, innovation, and investment....


  • Sydney, New South Wales, Australia TAL Full time

    Company DescriptionWelcome to This Australian Life.From the millions of Australians we protect, to those that make it happen every day at TAL, people really are what we're all about. We want to grow with you. Achieve with you. And support you to do your best work. That's why we're focused on developing leadership, promoting diversity, rewarding excellence...

  • Cyber Governance

    1 week ago


    Sydney, New South Wales, Australia AMP Limited Full time

    The Cyber Governance & Metrics Analyst is responsible for assisting with AMP's internal processes that provide assurance to our stakeholders that their information assets are appropriately secured.How you will make an impact Lead monthly governance meetings with senior stakeholders, to ensure they are meeting the Cyber metric targets for their respective...


  • Sydney, New South Wales, Australia Singtel Full time

    We don't sit back and wait for the future to happen, we are out there crafting our own path through new technology, innovation, and investment. We are truly a challenger brand, with challenger spirit. Reporting to the Associate Director, Cyber Security Governance, this role is a critical governance position within the Cyber Security team with accountability...


  • Sydney, New South Wales, Australia Domain Group Full time

    Cyber Governance, Risk and Compliance Manager - Sydney Office - Permanent Full TimeWe have a high impact; newly created opportunity for an experienced Cybersecurity Governance, Risk and Compliance (GRC) Manager, to join our Domain team. Reporting into the Chief Information Security Officer (CISO); you will be responsible for the implementation and management...

  • Cyber Governance Lead

    2 weeks ago


    Sydney, New South Wales, Australia Scentre Group Full time

    Our StoryScentre Group is the owner and operator of 42 Westfield living centers in Australia and New Zealand; partnering with the world's leading retail and luxury brands to create a unique shopping and leisure experience for our customers. A career with us fosters the chance to be a part of a company that is transforming the digital and physical retail...


  • Sydney, New South Wales, Australia Cyber Crime Full time

    KPMG Australia KPMG is a global network of professional firms providing Audit, Tax and Advisory services. View company page Immerse yourself in our inclusive, diverse and supportive cultureChoose the way you want to work by embracing our flexible work arrangementCollaborate with sector and technical experts to grow your knowledge and networkKPMG Australia...


  • Sydney, New South Wales, Australia Allianz Australia Full time

    **Cyber Governance Analyst | Location Sydney CBD**As a Cyber Governance Analyst, you'll enable Allianz Australia to operate with confidence by assisting with the identification, management and resolution of security noncompliances and risks, and by providing analytics and reporting that facilitates data driven decisionmaking.This role will be reporting to...


  • Sydney, New South Wales, Australia UNSW Australia Full time

    Cyber Security Risk AdvisorJob no: 525136Work type: full timeLocation: Sydney, NSWCategories: Information Technology, CyberEmployment: Full time (35 hours per week)Continuing role as a Cyber Security Risk AdvisorRemuneration: Excellent salary package including leave loading and generous superannuationLocation: Based in Kensington, Sydney (hybrid working...


  • Sydney, New South Wales, Australia Talent International Full time

    Job Details:LocationSydneySalaryAU$ AU$ per annum + plus bonusJob TypeFull TimeRefBBBH97822_ ContactElliott HowardPostedabout 1 hour agoA leading Financial Services provider is seeking a Cyber Governance Analyst with solid experience developing reports / metrics to join their team on a permanent basis.Another key focus of the role will be using Power BI to...

  • Cyber Risk Analyst

    1 week ago


    Sydney, New South Wales, Australia The Recruitment Company Full time

    The Opportunity This leading Not for Profit organisation are seeking 2x Cyber Risk Analysts to join the team. You will work closely with internal stakeholders to identify potential threats, evaluate security controls, and develop strategies to mitigate risks effectively. Your insights and recommendations will help strengthen cybersecurity posture and ensure...


  • Sydney, New South Wales, Australia University of New South Wales Full time

    Employment: Full time (35 hours per week) Continuing role as a Cyber Security Risk Advisor Remuneration: Excellent salary package including leave loading and generous superannuation Location: Based in Kensington, Sydney (hybrid working available) About UNSW Sydney:UNSW isn't like other places you've worked. Yes, we're a large organisation with a diverse and...


  • Sydney, New South Wales, Australia University of New South Wales Full time

    Job no: 525136Work type: full timeLocation: Sydney, NSWCategories: Information Technology, Cyber Employment: Full time (35 hours per week) Continuing role as a Cyber Security Risk Advisor Remuneration: Excellent salary package including leave loading and generous superannuation Location: Based in Kensington, Sydney (hybrid working available)About UNSW...


  • Sydney, New South Wales, Australia Aon Corporation Full time

    Posting Description: Key leadership opportunity for a senior Cyber specialist Work across an enviable portfolio for our Australian operations Join one of Australia's leading Cyber Risk solutions providerCyber Risk ConsultantYou will be an integral component of the Cyber Solutions Group, working closely with the Cyber Insurance Practice Leader and other key...


  • Sydney, New South Wales, Australia Qantas Airways Limited Full time

    Fantastic opportunity to join our Airline IT business and to join our Cyber, Technology risk & assurance function Be part of supercollaborative, passionate team that values cyber safe practice Permanent opportunity based at our Head Office in MascotAt Qantas, we represent Australia to the world. Our diverse country is known for its unique spirit, mateship,...


  • Sydney, New South Wales, Australia Tal Full time

    TAL We offer flexibility by letting you tailor your cover to suit your individual needs.Quick and easy to apply.Get An Online Quote. View company page From the millions of Australians we protect, to those that make it happen every day at TAL, people really are what we're all about.We want to grow with you.Achieve with you.And support you to do your best...

  • Cyber Risk

    2 weeks ago


    Sydney, New South Wales, Australia NTT Full time

    Cyber Risk & Compliance ManagerNTT is a leading global IT solutions and services organisation that brings together people, data and things to create a better and more sustainable future.In today's 'iNTTerconnected' world, connections matter more now than ever. By bringing together talented people, world-class technology partners and emerging innovators, we...

  • Cyber Risk Manager

    1 week ago


    Sydney, New South Wales, Australia Allianz Australia Full time

    CYBER RISK MANAGER - RISK AND COMPLIANCE MANAGER | SYDNEY, NSWAt Allianz, we're proud to be one of the world's leading insurance and asset management brands, with a workforce as diverse as the world around us.We care about our customers, which is why we hire the very best people to further our commitment to securing the future of our customers, partners, and...

  • Head of Cyber, Risk

    2 weeks ago


    Sydney, New South Wales, Australia BaptistCare NSW & ACT Full time

    • Permanent full-time position | Based in Norwest - Flexible/hybrid working• Join an industry leading Business Technology Solutions team• Well known Not-for-profit who put people at the centre of everything we doAbout the role:As the Head of Cyber, Risk, and Compliance, your primary responsibility is to create and drive the organisation's cyber...


  • Sydney, New South Wales, Australia Macquarie Full time

    Our diverse and global team are responsible for the Cyber Threat and Incident Response Program's cyber regulatory engagement and response, cyber risk assessment and obligation management, and organizational risk compliance and reporting. You'll help security leadership develop and grow the program's threat-driven risk structure and culture. At Macquarie, we...