Technology Risk and Complaince Manager

4 weeks ago


Melbourne, Australia McMillan Shakespeare Full time

The McMillan Shakespeare Group (MMS) is a trusted provider of salary packaging, novated leasing, disability plan management and support co-ordination, asset management and related financial products and services. From our origins in 1988 when we created Australia’s salary packaging industry to today, MMS has a proud history of innovation and exceptional service.

Through our subsidiaries, we offer a breadth of services and expertise designed to responsibly deliver superior long-term value to our clients and customers, which include Federal and State governments and some of the largest public and private sector, health and charitable organisations.

The Manager Technology Risk & Compliance role can be done from Adelaide, Brisbane, Melbourne or Sydney and is a paternity cover for 6 months full time that may extend to one year.

MMS has a number of compliance obligations imposed by the regulatory and contractual environment in which we operate. The manager technology risk and compliance is to lead the analysis monitoring and strict compliance to internal, audit and contractual policies and controls in relation to the delivery of governance over digital and traditional on-premise services. A key component of the role is education and awareness ensuring staff and 3rd parties are abreast of the requirements in order to meet this compliance.

The Manager Technology Risk & Compliance is responsible for direct control of security owned controls and compliance obligations in addition to stakeholder management and leading oversight governance of first line of defense teams and their roles in monitoring, analysing, executing security governance controls. The manager must develop a strong working relationship with IT functional teams and business stakeholders to ensure baseline security requirements are met and assets remain protected within these functional areas and escalated where non-compliance exists.

The Manager Technology Risk & Compliance is also responsible for keeping abreast of legislative, compliance and security industry changes as they relate to MMS business whilst developing, maintaining and reporting risk management frameworks that aim to protect the confidentiality,

availability and integrity of group assets including data.

The Role:

- Map existing contracts against security standards identifying potential gaps in compliance and for input into the information security policy and standards
- Manage and lead internal and external audits end to end being the technology authoritative source and focal point whilst ensuring relevant artefacts are sourced and provided in a timely manner
- Evaluate cyber-security standards including NIST, ASD Essential 8, ISO27000 and PCI DSS for alignment with internal frameworks
- Ensure internal security standards, policy, audit and contracted security requirements are communicated across the business and with 3rd Parties
- Ensure 3rd parties comply with all relevant due diligence obligations and provide regular attestations
- Manage the cyber-security education, training and awareness program and educate employees in security best practices
- Periodically conduct security reviews and workshops to report business effectiveness in meeting documented standards, controls and compliance to contractual or policy objectives
- Lead, steer and oversee the Information, Communication and Technology Risk management framework
- Conduct regular risk assessments and workshops to ensure risks to the organisation are assessed and understood, and are fed back to stakeholders to ensure the continued effectiveness of the risk management strategy
- Manage and improve the risk posture, contribute and evaluate solutions for remediating or mitigating risks and assess residual risks
- Work with all stakeholders to educate and identify controls and compliance requirements that are applicable
- Undertake contract and 3rd party security reviews providing guidance, checklists to support business risk decisions
- Generate security metrics and provide regular reports on security compliance performance to technology management and risk and audit committees
- Lead and prepare Crisis management testing and response exercises and relevant reporting
- Respond to information security incidents
- Lead, maintain and develop incident response processes and procedures when new threats to the organisation arise
- Be an active participant in incident management to support controlled and coordinated responses
- Develop security policy, standards and develop processes and procedures for evaluation and exemption where required.
- When necessary, prepare Post Incident Reviews
- Any other security risk and compliance initiatives, as requested.

You will bring:

- 5-10 years experience in IT Security and Risk Management
- Experience with legal and regulatory obligations such as the Australian Privacy Principles.
- Supply chain risk management and assesments including 3rd party security risk assessments
- Experience


  • Risk Manager

    1 month ago


    Melbourne, Australia Compliance and Risk Management Recruitment Full time

    Government / Local Government - Local Government - Melbourne - Permanent / Full Time **09th January, 2023**: We are working with one of Victoria’s largest Council’s who is looking for a risk professional to join the team. This opportunity will have you develop the risk frameworks and provide business growth from the ground-up. With a collaborative and...

  • Risk Manager

    1 month ago


    Melbourne, Australia Compliance and Risk Management Recruitment Full time

    Transport / Logistics / Drivers - Supply Chain - Other - Melbourne - Permanent / Full Time **19th March, 2024**: **Exciting opportunity join a Global Freight Business. This role plays a pivotal role in supporting the business around its third party providers.** **Key Responsibilities** - Design, implement and manage a common and consistent third-party risk...


  • Melbourne, Australia Bluefin Resources Full time

    **The Company** You will join a leading Australian financial services organisation that puts its customers first and prides itself on the diversity of people. **A day in the Life of a Technology Risk Manager - Cloud** This second-line role is responsible for reviewing how well the organisation is adhering to the risk management framework, policies and...

  • Sustainability, Risk

    1 month ago


    Melbourne, Australia Compliance and Risk Management Recruitment Full time

    Education & Child Care - Secondary - Other - Melbourne - Permanent / Full Time **20th March, 2023**: Our client is a leading co-educational catholic school located in the South East of Melbourne. With a culture of continuous improvement coupled with respect, collaboration, and generosity they boast a long -term staff tenure on large & impressive grounds...


  • Melbourne City Centre, Australia Victoria Police Full time

    **About the role**: The Technology Risk Manager role is a critical role to strengthen and drive effective Technology Risk Management practise, executing effective end to end risk assurance process for Victoria Police's technology services. Victoria Police is a contemporary and agile workplace and supports flexible working arrangements. **Your duties will...


  • Melbourne City Centre, Australia Victoria Police Full time

    **About the role**: The Technology Risk Manager role is a critical role to strengthen and drive effective Technology Risk Management practise, executing effective end to end risk assurance process for Victoria Police's technology services. Victoria Police is a contemporary and agile workplace and supports flexible working arrangements. **Your duties will...


  • Melbourne, Australia Victoria Police Full time

    Location: Melbourne | CBD Job type: Full time Organisation: Victoria Police **Salary**: $129,379 - $173,138 Occupation: IT and Telecommunications Reference: VG/E20042908 **About the role**: The Technology Risk Manager role is a critical role to strengthen and drive effective Technology Risk Management practise, executing effective end to end risk...


  • Melbourne, Australia Victoria Police Full time

    Location: Melbourne | CBD Job type: Full time Organisation: Victoria Police **Salary**: $129,379 - $173,138 Occupation: IT and Telecommunications Reference: VG/JE20042908 **About the role**: The Technology Risk Manager role is a critical role to strengthen and drive effective Technology Risk Management practise, executing effective end to end risk...


  • Melbourne, Australia ANZ Banking Group Full time

    About the role The purpose of the Technology Assurance Team is to manage and uplift awareness of operational risk caused by the use of Technology, and to embed sustainable risk management practices. As a Technology Assurance Management Expert your role will be to support either the Tribes, Technology Areas or Australia Division & Domain (AR&C) Teams in...


  • Melbourne, Australia Capgemini Full time

    **Come and join a thriving company and become part of a diverse global collective of free-thinkers, entrepreneurs and industry experts who are all driven to use technology to reimagine what’s possible. Capgemini. Get the future you want.** **Let’s talk about the role and responsibilities** - **Understand, identify, and assess risks during the project...


  • Melbourne, Australia ANZ Banking Group Full time

    **Req ID**: 39950 **Department**: Insto Markets COO **Division**: Institutional **Location**: Melbourne About the role This role represents 1st line assurance for the Markets business and provides specialised advice, guidance and oversight on business technology risk topics including information security, cyber risk management, operational risk caused by...


  • Melbourne, Australia Grant Thornton Full time

    Grant Thornton Australia is a leading audit, tax and advisory firm where care is just as important as capability – because we believe that the experience is just as important as the outcome. With our values at the core, we are creating a unique and constructive culture where we care for our people, clients and communities and support them to thrive. ...


  • Melbourne, Australia IOOF Holdings Limited Full time

    Drive key outcomes to future-proof our business Work for a leading wealth management company Hybrid working environment – Melbourne or Sydney We are seeking an experienced Manager to lead the design and delivery of our approach to managing technology risk in the business. The Role Reporting to the Head of 1st Line Risk & Compliance, you will be managing...


  • Melbourne, Australia Swinburne University of Technology Full time

    This position is responsible for the monitoring and reporting on academic standards, assisting in the identification and mitigation of academic risk, and promoting and developing academic quality relating to the University’s quality assurance systems and processes for Higher Education, including: preparation for Internal and external quality audits and...


  • Melbourne, Australia Swinburne University of Technology Full time

    This position is responsible for the monitoring and reporting on academic standards, assisting in the identification and mitigation of academic risk, and promoting and developing academic quality relating to the University’s quality assurance systems and processes for Higher Education, including: preparation for Internal and external quality audits and...


  • Melbourne, Victoria, Australia Robert Walters Full time

    Our client is seeking a talented Senior Manager for Compliance & Capability within Resilience, Technology & Data to join their Operational Risk & Compliance team. This role offers stimulating and rewarding work with reach and impact across the Enterprise. The successful candidate will have the opportunity to learn, grow and develop within a global footprint....


  • Melbourne, Australia CitiPower and Powercor Full time

    **HSE Systems, Reporting & Risk Manager**: - Melbourne, VIC, AU, 3000**About us**: CitiPower, Powercor and United Energy own and operate the electricity distribution networks servicing 1.9 million customers located across 65% of Victoria. These customers include large numbers of households as well as commercial and industrial businesses, world class arts,...

  • IT Risk, Controls

    1 month ago


    Melbourne, Australia Asahi Beverages Full time

    **Your impact**: We have an outstanding opportunity for an experienced IT Risk, Controls & Compliance Manager to join the team working across our Technology and our outsourced Technology teams. As the IT Risk, Controls & Compliance Manager, you will play a vital role in ensuring the safety and integrity of our technology systems and infrastructure. Your...

  • Risk Manager

    4 weeks ago


    Melbourne, Australia ANZ Full time

    The Risk Manager (Customer Due Diligence) is a key managerial role within the First Line Risk & Compliance (1LRC) team, which is responsible for Customer Due Diligence (CDD) of ANZ Worldline merchant acquiring customers, which includes Initial Customer Due Diligence, Enhanced Customer Due Diligence (ECDD) and Ongoing Customer Due Diligence (OCDD). CDD is a...


  • Melbourne, Australia Talent International Full time

    australia melbourne contract negotiable**Opportunity** Three month initial term day rate contract with potential to extend on an ongoing basis into 2024. CBD Based with great work from home flexibility. ASX listed international business of 1200 staff. Great opportunity for a “hands on” Enterprise Risk Manager to make visible impact from day 1 and...