Cyber Governance, Risk

6 months ago


Sydney, Australia King & Wood Mallesons Full time

New role to the firm - Enhance what we have and take the next step in your career- With a few years experience behind you, you will be looking to introduce what you’ve learnt in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.- As a leading law firm, we actively seek people from diverse backgrounds to enrich our culture and performance.

Who are we?

A firm born in Asia, underpinned by world class capability.

With over 3000 lawyers in 29 global locations, we help our clients manage their risk and enable their growth. Our full-service offering combines un-matched top tier local capability complemented with an international platform.

We have deep roots in Australia spanning almost 200 years and acknowledge Aboriginal and Torres Strait Islander peoples as the traditional owners and custodians of these lands and waters.

Role Detail

With a ‘continuous improvement lens’ on our cyber governance and compliance obligations, this new role to the firm will help us continue to lead in managing our cyber risk internal and external compliance obligations. Freeing up the team to focus on their BAU, this role will give you the opportunity to enhance our cyber security culture through robust processes and reporting.

Based in the Sydney CBD office, with a balanced approach to WFH, you will play a key role in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.

Reporting to the Information Security Manager, you will also create and maintain documentation to demonstrate our adherence to organisational and regulatory policies, standards and best practices. You will be integral with helping the firm manage third party vendor risk and meet its client information security compliance obligations.

Key responsibilities:
- Manage and oversee the organisation's third-party vendor management program, including the assessment and ongoing monitoring of our vendors' cyber security practices.- Collaborate with internal stakeholders to identify and evaluate potential cyber security risks associated with third-party vendors.- Develop and maintain strong relationships with vendors to ensure compliance with contractual obligations and cyber security requirements.- Working closely with our Risk and Compliance team, respond to client third-party security audits by coordinating and providing necessary documentation, evidence, and responses to address audit findings.- Conduct regular assessments of vendors' cyber security controls, policies, and practices to identify potential vulnerabilities and areas for improvement.- Assist with maintaining our internal cyber security compliance programs, ensuring alignment with industry best practices and frameworks such as ISO27001.- Supporting the maintenance and operation of our policies, procedures and standards, registers, guides and reporting.- Supporting and coordinating internal and external audit programs.- Monitor and assess cyber security risks and compliance issues, providing recommendations for remediation and improvement.- Provide cyber risk support for projects and business as usual initiatives.- Stay up to date with emerging cyber security threats, trends, and regulatory requirements, and provide guidance on their potential impact on the organisation.- Collaborate with cross-functional teams to develop and deliver cyber security awareness and training programs for employees.- Assisting the Head of Information Security and Information Security Manager with maintaining operational metrics on the effectiveness of the firm’s Information Security program.

About You

Your natural curiosity will fit nicely, and your collaborative approach will be celebrated. As the SME in this area, you will be looked to for direction which requires confidence in your ability, backed by the experience from lessons learnt.

You will also bring:
- Solid knowledge of information security concepts and practices, such as risk assessment and assurance.- Strong knowledge of third-party vendor management principles, practices, and frameworks.- Proven experience in responding to client third-party security audits and addressing audit findings.- In-depth understanding of cyber security compliance frameworks, particularly ISO27001.- Familiarity with other relevant frameworks and regulations such as NIST, GDPR, or APRA CPS 234 is highly desirable.- Excellent analytical and problem-solving skills, with the ability to assess and mitigate cyber security risks effectively.- Strong communication and interpersonal skills, with the ability to collaborate with internal and external stakeholders at various levels.- Demonstrated ability to develop and implement cyber security compliance programs and policies.- Relevant certifications such as CISSP, CISM, CRISC, or ISO27001 Lead Auditor are highly desirable.- Proven ability to stay up to date with eme



  • Sydney, New South Wales, Australia Cuscal Full time

    Job DescriptionWe are seeking a seasoned cybersecurity professional to join our dynamic IT Security team as a Chief Cyber Governance Risk Strategist.This role requires an expert who can lead the development and execution of our cyber governance, risk management, and assurance strategy. The successful candidate will be responsible for ensuring that...


  • Sydney, Australia Domain Group Full time

    **Cyber Governance, Risk and Compliance Lead - Sydney Office - Permanent Full Time** A great opportunity for a **Cyber Security Governance, Risk and Compliance** **(GRC) Lead**, in partnership with the Cyber Security GRC Manager, the Lead will be responsible for the delivery of the Cyber Security Governance, Risk and Compliance initiatives. You will work...


  • Sydney, New South Wales, Australia Cuscal Full time

    Job Title: Cyber Governance Risk Management LeadCyber Governance & Risk Management:We are seeking a high-calibre Cyber Governance Risk Management Lead to join our IT Security team at Cuscal. This role is responsible for developing and maintaining the cybersecurity governance framework, ensuring alignment with industry best practices, regulatory requirements,...


  • Sydney, New South Wales, Australia Cuscal Full time

    We are seeking a highly skilled Cyber Governance Risk Management Leader to join our dynamic and evolving IT Security team at Cuscal.About the Role:This exciting opportunity will see you lead the development and execution of our cyber governance, risk management, and assurance strategy. As the Cyber Governance Risk Management Leader, you will ensure that...


  • Sydney, New South Wales, Australia Cuscal Limited Full time

    Company OverviewCuscal Limited is a leading provider of payment solutions, dedicated to delivering innovative and secure services to the Australian financial sector. Our company culture values diversity, inclusion, and employee growth, making us an attractive employer in the industry.About the RoleWe are seeking a highly experienced Cyber Governance Risk...


  • Sydney, New South Wales, Australia Cuscal Limited Full time

    Estimated salary: $150,000 - $200,000 per annumCuscal Limited is seeking a Cyber Governance Risk Assurance Leader to join our IT Security team. This role ensures that cybersecurity risks are effectively identified, assessed, managed, and mitigated, in line with the organization's risk appetite and regulatory requirements.Job Description:We are looking for a...


  • Sydney, New South Wales, Australia Softtest pays pty ltd Full time

    At Softtest pays pty ltd, we are seeking a highly skilled Cyber Security Risk Analyst to join our team.Estimated Annual Salary:$120,000 - $150,000 AUDAbout the RoleThis is an exceptional opportunity for a professional with a strong background in cyber governance, risk and compliance, or a related field of cyber security.Key ResponsibilitiesConduct thorough...


  • Sydney, Australia TAL Full time

    Company Description Welcome to This Australian Life. From the millions of Australians we protect, to those that make it happen every day at TAL, people really are what we’re all about. We want to grow with you. Achieve with you. And support you to do your best work. That's why we're focused on developing leadership, promoting diversity, rewarding...


  • Sydney, New South Wales, Australia Cuscal Limited Full time

    About This RoleCuscal Limited is seeking a highly skilled Senior Manager Cyber Governance Risk to join our dynamic IT Security team. This is an exciting opportunity to lead the development and execution of the cyber governance, risk management, and assurance strategy.Key ResponsibilitiesDevelop and maintain the Cuscal Limited cybersecurity governance...


  • Sydney, New South Wales, Australia HiTech Group Full time

    Cyber Security Risk Analyst Job DescriptionEstimated Salary: $120,000 - $150,000 per annum.About HiTech GroupA leading Federal Government department is seeking an experienced Cyber Security Risk Analyst to join a highly multidisciplinary team. The successful candidate will be responsible for identifying key security risks in the ICT environment and ensuring...


  • Sydney, Australia Cuscal Full time

    Job DescriptionWe are looking for Senior Manager, Cyber Governance, Risk & Assurance to join our dynamic and evolving IT Security team! What is this role about?As the Senior Manager, Cyber Governance, Risk & Assurance you will, lead the development and execution of the cyber governance, risk management, and assurance strategy. This role ensures that...


  • Sydney, Australia Cuscal Limited Full time

    Company DescriptionFor a winning team that is evolving.  Forward with Cuscal.At Cuscal, you’ll find a strong, successful company that’s reimagining the future. And our team is right there at the heart of it all. Here, you’ll deliver or support interesting, ground-breaking projects that have real impact - on Australia’s financial services sector and...


  • Sydney, Australia Sirius People Full time

    **Seeking a Senior Cyber Risk Manager!** **Join a Leading Team in the Banking Industry!** Are you a seasoned professional in the world of cyber risk and security? Do you have a track record of designing controls, setting standards, and providing expert governance advice in the realm of cyber security? If you're ready to make a significant impact and operate...


  • Sydney, Australia Domain Group Full time

    **Cyber Governance, Risk and Compliance Manager - Sydney Office - Permanent Full Time** We have a high impact; newly created opportunity for an experienced Cybersecurity Governance, Risk and Compliance (GRC) Manager, to join our Domain team. Reporting into the Chief Information Security Officer (CISO); you will be responsible for the implementation and...


  • Sydney, New South Wales, Australia HiTech Group Full time

    Job Summary:Cyber Security Risk Analyst required to join a multidisciplinary team in a leading Federal Government department. The successful candidate will be responsible for identifying key security risks in the ICT environment and ensuring the department is able to mitigate and be resilient to cyber threat activity.Key Responsibilities:Conducting security...

  • Cyber Risk Manager

    1 day ago


    Sydney, New South Wales, Australia Cuscal Full time

    About CuscalCuscal is a leading technology company that delivers innovative payment solutions to the banking and finance industry. Our team is passionate about creating secure and efficient payment systems that meet the evolving needs of our customers.Job SummaryWe are seeking an experienced Cyber Risk Manager to join our IT Security team. As a key member of...


  • Sydney, New South Wales, Australia Local Peoples Full time

    We are seeking an experienced Cyber Security Risk Specialist to join our team in the Australian Capital Territory (ACT), Queensland (QLD), South Australia (SA), or Victoria (VIC). This role will involve working with government agencies to assess and mitigate cyber security risks.The ideal candidate will have extensive experience with risk and information...


  • Sydney, New South Wales, Australia Cuscal Full time

    Job Overview:Cuscal is seeking a highly skilled Chief Information Security Officer - Cyber Governance and Risk Management to lead the development and execution of the cyber governance, risk management, and assurance strategy.


  • Sydney, New South Wales, Australia Cuscal Limited Full time

    Lead Cyber Governance and Risk Management RoleWe are seeking a highly experienced Senior Manager, Cyber Governance, Risk & Assurance to join our dynamic IT Security team at Cuscal Limited.About the Role:This is a leadership position responsible for developing and executing the cyber governance, risk management, and assurance strategy, ensuring alignment with...


  • Sydney, New South Wales, Australia XM Cyber Full time

    About the RoleXM Cyber is a leading provider of continuous threat and exposure management solutions. We are seeking an experienced Channel Manager to join our team in ANZ.The successful candidate will be responsible for building and managing a channel of enterprise cyber security solutions. This will involve working closely with our sales teams and channel...