Cyber Governance, Risk

3 weeks ago


Sydney, Australia King & Wood Mallesons Full time

New role to the firm - Enhance what we have and take the next step in your career- With a few years experience behind you, you will be looking to introduce what you’ve learnt in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.- As a leading law firm, we actively seek people from diverse backgrounds to enrich our culture and performance.

Who are we?

A firm born in Asia, underpinned by world class capability.

With over 3000 lawyers in 29 global locations, we help our clients manage their risk and enable their growth. Our full-service offering combines un-matched top tier local capability complemented with an international platform.

We have deep roots in Australia spanning almost 200 years and acknowledge Aboriginal and Torres Strait Islander peoples as the traditional owners and custodians of these lands and waters.

Role Detail

With a ‘continuous improvement lens’ on our cyber governance and compliance obligations, this new role to the firm will help us continue to lead in managing our cyber risk internal and external compliance obligations. Freeing up the team to focus on their BAU, this role will give you the opportunity to enhance our cyber security culture through robust processes and reporting.

Based in the Sydney CBD office, with a balanced approach to WFH, you will play a key role in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.

Reporting to the Information Security Manager, you will also create and maintain documentation to demonstrate our adherence to organisational and regulatory policies, standards and best practices. You will be integral with helping the firm manage third party vendor risk and meet its client information security compliance obligations.

Key responsibilities:
- Manage and oversee the organisation's third-party vendor management program, including the assessment and ongoing monitoring of our vendors' cyber security practices.- Collaborate with internal stakeholders to identify and evaluate potential cyber security risks associated with third-party vendors.- Develop and maintain strong relationships with vendors to ensure compliance with contractual obligations and cyber security requirements.- Working closely with our Risk and Compliance team, respond to client third-party security audits by coordinating and providing necessary documentation, evidence, and responses to address audit findings.- Conduct regular assessments of vendors' cyber security controls, policies, and practices to identify potential vulnerabilities and areas for improvement.- Assist with maintaining our internal cyber security compliance programs, ensuring alignment with industry best practices and frameworks such as ISO27001.- Supporting the maintenance and operation of our policies, procedures and standards, registers, guides and reporting.- Supporting and coordinating internal and external audit programs.- Monitor and assess cyber security risks and compliance issues, providing recommendations for remediation and improvement.- Provide cyber risk support for projects and business as usual initiatives.- Stay up to date with emerging cyber security threats, trends, and regulatory requirements, and provide guidance on their potential impact on the organisation.- Collaborate with cross-functional teams to develop and deliver cyber security awareness and training programs for employees.- Assisting the Head of Information Security and Information Security Manager with maintaining operational metrics on the effectiveness of the firm’s Information Security program.

About You

Your natural curiosity will fit nicely, and your collaborative approach will be celebrated. As the SME in this area, you will be looked to for direction which requires confidence in your ability, backed by the experience from lessons learnt.

You will also bring:
- Solid knowledge of information security concepts and practices, such as risk assessment and assurance.- Strong knowledge of third-party vendor management principles, practices, and frameworks.- Proven experience in responding to client third-party security audits and addressing audit findings.- In-depth understanding of cyber security compliance frameworks, particularly ISO27001.- Familiarity with other relevant frameworks and regulations such as NIST, GDPR, or APRA CPS 234 is highly desirable.- Excellent analytical and problem-solving skills, with the ability to assess and mitigate cyber security risks effectively.- Strong communication and interpersonal skills, with the ability to collaborate with internal and external stakeholders at various levels.- Demonstrated ability to develop and implement cyber security compliance programs and policies.- Relevant certifications such as CISSP, CISM, CRISC, or ISO27001 Lead Auditor are highly desirable.- Proven ability to stay up to date with eme



  • Sydney, New South Wales, Australia Cyber Crime Full time

    Singtel The Singtel Group, Asia's leading communications group provides a diverse range of services including fixed, mobile, data, internet, TV, infocomms technology (ICT) and digital solutions. View company page We don't sit back and wait for the future to happen, we are out there crafting our own path through new technology, innovation, and investment....


  • Sydney, New South Wales, Australia King & Wood Mallesons Full time

    New role to the firm - Enhance what we have and take the next step in your career- With a few years experience behind you, you will be looking to introduce what you've learnt in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.- As a leading law firm, we actively seek...


  • Sydney, Australia Domain Group Full time

    **Cyber Governance, Risk and Compliance Lead - Sydney Office - Permanent Full Time** A great opportunity for a **Cyber Security Governance, Risk and Compliance** **(GRC) Lead**, in partnership with the Cyber Security GRC Manager, the Lead will be responsible for the delivery of the Cyber Security Governance, Risk and Compliance initiatives. You will work...


  • Sydney, Australia TAL Full time

    Company Description Welcome to This Australian Life. From the millions of Australians we protect, to those that make it happen every day at TAL, people really are what we’re all about. We want to grow with you. Achieve with you. And support you to do your best work. That's why we're focused on developing leadership, promoting diversity, rewarding...


  • Sydney, Australia The Decipher Bureau Full time

    This ASX listed organisation have seen considerable growth and investment in their cyber and risk team over the years, with lots of new initiatives in the GRC space that need to be delivered specifically defining group wide cyber principles.You will be across a number of accountabilities including leading security risk assessments and analysis, defining...


  • Sydney, Australia The Decipher Bureau Full time

    This ASX listed organisation have seen considerable growth and investment in their cyber and risk team over the years, with lots of new initiatives in the GRC space that need to be delivered specifically defining group wide cyber principles.You will be across a number of accountabilities including leading security risk assessments and analysis, defining...


  • Sydney, New South Wales, Australia TAL Full time

    Company DescriptionWelcome to This Australian Life.From the millions of Australians we protect, to those that make it happen every day at TAL, people really are what we're all about. We want to grow with you. Achieve with you. And support you to do your best work. That's why we're focused on developing leadership, promoting diversity, rewarding excellence...

  • Cyber Governance

    2 weeks ago


    Sydney, New South Wales, Australia AMP Limited Full time

    The Cyber Governance & Metrics Analyst is responsible for assisting with AMP's internal processes that provide assurance to our stakeholders that their information assets are appropriately secured.How you will make an impact Lead monthly governance meetings with senior stakeholders, to ensure they are meeting the Cyber metric targets for their respective...


  • Sydney, Australia Sirius People Full time

    **Seeking a Senior Cyber Risk Manager!** **Join a Leading Team in the Banking Industry!** Are you a seasoned professional in the world of cyber risk and security? Do you have a track record of designing controls, setting standards, and providing expert governance advice in the realm of cyber security? If you're ready to make a significant impact and operate...


  • Sydney, Australia Singtel Full time

    We don’t sit back and wait for the future to happen, we are out there crafting our own path through new technology, innovation, and investment. We are truly a challenger brand, with challenger spirit. Reporting to the Associate Director, Cyber Security Governance, this role is a critical governance position within the Cyber Security team with...

  • Cyber Governance Lead

    4 weeks ago


    Sydney, Australia Scentre Group Full time

    **Our Story** Scentre Group is the owner and operator of 42 Westfield living centers in Australia and New Zealand; partnering with the world’s leading retail and luxury brands to create a unique shopping and leisure experience for our customers. A career with us fosters the chance to be a part of a company that is transforming the digital and physical...


  • Sydney, Australia NSW Government -Department of Premier and Cabinet Full time

    **You. At the centre of big ideas.**: - **Are you a senior professional with extensive experience in audit, **risk management or information security? If so, this role is for you! Come **join our remarkable team.**: - **This is an ongoing, Clerk Grade 11/12 role based in Martin Place.**: - **Flexible working is part of our DNA at DPC. It is not the way we...


  • Sydney, New South Wales, Australia Domain Group Full time

    Cyber Governance, Risk and Compliance Manager - Sydney Office - Permanent Full TimeWe have a high impact; newly created opportunity for an experienced Cybersecurity Governance, Risk and Compliance (GRC) Manager, to join our Domain team. Reporting into the Chief Information Security Officer (CISO); you will be responsible for the implementation and management...


  • Sydney, New South Wales, Australia Singtel Full time

    We don't sit back and wait for the future to happen, we are out there crafting our own path through new technology, innovation, and investment. We are truly a challenger brand, with challenger spirit. Reporting to the Associate Director, Cyber Security Governance, this role is a critical governance position within the Cyber Security team with accountability...

  • Cyber Governance Lead

    2 weeks ago


    Sydney, New South Wales, Australia Scentre Group Full time

    Our StoryScentre Group is the owner and operator of 42 Westfield living centers in Australia and New Zealand; partnering with the world's leading retail and luxury brands to create a unique shopping and leisure experience for our customers. A career with us fosters the chance to be a part of a company that is transforming the digital and physical retail...


  • Sydney, Australia NSW Government -Governance & Legal Full time

    **_Do you want your work to make a difference for NSW?_** - Together, we create thriving environments, communities and economies._ - **Diverse work - opportunity to grow and enhance your career**: - **Permanent full-time opportunities**: - **Parramatta location - flexible/hybrid working supported**: - **Clerk Grade 7/8 - Salary relative to experience, and...


  • Sydney, New South Wales, Australia Cyber Crime Full time

    KPMG Australia KPMG is a global network of professional firms providing Audit, Tax and Advisory services. View company page Immerse yourself in our inclusive, diverse and supportive cultureChoose the way you want to work by embracing our flexible work arrangementCollaborate with sector and technical experts to grow your knowledge and networkKPMG Australia...


  • Sydney, New South Wales, Australia Allianz Australia Full time

    **Cyber Governance Analyst | Location Sydney CBD**As a Cyber Governance Analyst, you'll enable Allianz Australia to operate with confidence by assisting with the identification, management and resolution of security noncompliances and risks, and by providing analytics and reporting that facilitates data driven decisionmaking.This role will be reporting to...

  • Manager Cyber Risk

    3 weeks ago


    Sydney, Australia NSW Government -Department of Customer Service Full time

    **Manager Cyber Risk, 12months Temporary, Sydney** The Department of Customer Service is looking for a Manager Cyber Risk Management to join our growing team! **Benefits** - Fantastic 12 month Temporary, clerk grade 11/12 Opportunity. - Salary range: $134,411-$155,445+ super, commensurate with experience. - Genuinely flexible working arrangements. -...


  • Sydney, Australia HAYS Full time

    12-month contract role - federal government agency - Cyber Security Risk Assessment Officer **Your new company** This government agency is looking for a Cyber Security Risk Assessment Officer to join their Cyber Security team in an initial 12-month contract role with room for extension. You will have the opportunity of working at a federal government...