Cyber Governance, Risk

7 months ago


Sydney, Australia King & Wood Mallesons Full time

New role to the firm - Enhance what we have and take the next step in your career- With a few years experience behind you, you will be looking to introduce what you’ve learnt in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.- As a leading law firm, we actively seek people from diverse backgrounds to enrich our culture and performance.

Who are we?

A firm born in Asia, underpinned by world class capability.

With over 3000 lawyers in 29 global locations, we help our clients manage their risk and enable their growth. Our full-service offering combines un-matched top tier local capability complemented with an international platform.

We have deep roots in Australia spanning almost 200 years and acknowledge Aboriginal and Torres Strait Islander peoples as the traditional owners and custodians of these lands and waters.

Role Detail

With a ‘continuous improvement lens’ on our cyber governance and compliance obligations, this new role to the firm will help us continue to lead in managing our cyber risk internal and external compliance obligations. Freeing up the team to focus on their BAU, this role will give you the opportunity to enhance our cyber security culture through robust processes and reporting.

Based in the Sydney CBD office, with a balanced approach to WFH, you will play a key role in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.

Reporting to the Information Security Manager, you will also create and maintain documentation to demonstrate our adherence to organisational and regulatory policies, standards and best practices. You will be integral with helping the firm manage third party vendor risk and meet its client information security compliance obligations.

Key responsibilities:
- Manage and oversee the organisation's third-party vendor management program, including the assessment and ongoing monitoring of our vendors' cyber security practices.- Collaborate with internal stakeholders to identify and evaluate potential cyber security risks associated with third-party vendors.- Develop and maintain strong relationships with vendors to ensure compliance with contractual obligations and cyber security requirements.- Working closely with our Risk and Compliance team, respond to client third-party security audits by coordinating and providing necessary documentation, evidence, and responses to address audit findings.- Conduct regular assessments of vendors' cyber security controls, policies, and practices to identify potential vulnerabilities and areas for improvement.- Assist with maintaining our internal cyber security compliance programs, ensuring alignment with industry best practices and frameworks such as ISO27001.- Supporting the maintenance and operation of our policies, procedures and standards, registers, guides and reporting.- Supporting and coordinating internal and external audit programs.- Monitor and assess cyber security risks and compliance issues, providing recommendations for remediation and improvement.- Provide cyber risk support for projects and business as usual initiatives.- Stay up to date with emerging cyber security threats, trends, and regulatory requirements, and provide guidance on their potential impact on the organisation.- Collaborate with cross-functional teams to develop and deliver cyber security awareness and training programs for employees.- Assisting the Head of Information Security and Information Security Manager with maintaining operational metrics on the effectiveness of the firm’s Information Security program.

About You

Your natural curiosity will fit nicely, and your collaborative approach will be celebrated. As the SME in this area, you will be looked to for direction which requires confidence in your ability, backed by the experience from lessons learnt.

You will also bring:
- Solid knowledge of information security concepts and practices, such as risk assessment and assurance.- Strong knowledge of third-party vendor management principles, practices, and frameworks.- Proven experience in responding to client third-party security audits and addressing audit findings.- In-depth understanding of cyber security compliance frameworks, particularly ISO27001.- Familiarity with other relevant frameworks and regulations such as NIST, GDPR, or APRA CPS 234 is highly desirable.- Excellent analytical and problem-solving skills, with the ability to assess and mitigate cyber security risks effectively.- Strong communication and interpersonal skills, with the ability to collaborate with internal and external stakeholders at various levels.- Demonstrated ability to develop and implement cyber security compliance programs and policies.- Relevant certifications such as CISSP, CISM, CRISC, or ISO27001 Lead Auditor are highly desirable.- Proven ability to stay up to date with eme



  • Sydney, Australia Interactive Pty Ltd Full time

    **LOCATION(S)** - Sydney *** **POSITION** - Permanent - **DEPARTMENT** - IT & Telecomms - Our Cyber Security team protects and defends our customers’ and own internal systems and our cyber offering includes threat & vulnerability assessments, cyber risk & governance consulting and 24/7 managed security services. Our Cyber, Risk & Governance team work...


  • Sydney, Australia Domain Group Full time

    **Cyber Governance, Risk and Compliance Lead - Sydney Office - Permanent Full Time** A great opportunity for a **Cyber Security Governance, Risk and Compliance** **(GRC) Lead**, in partnership with the Cyber Security GRC Manager, the Lead will be responsible for the delivery of the Cyber Security Governance, Risk and Compliance initiatives. You will work...


  • Sydney, Australia TAL Full time

    Company Description Welcome to This Australian Life. From the millions of Australians we protect, to those that make it happen every day at TAL, people really are what we’re all about. We want to grow with you. Achieve with you. And support you to do your best work. That's why we're focused on developing leadership, promoting diversity, rewarding...


  • Sydney, Australia Latitude IT Full time

    ASX company undergoing comprehensive transformation - Hybrid work model - Collaborate closely with CISO Our client, an ASX HQ'd in Sydney with a nationwide footprint, is seeking an experienced Cyber Governance Manager to work closely with the CISO and take ownership of all cyber governance policies, standards & procedures across their nationwide network. -...


  • Sydney, Australia Sirius People Full time

    **Seeking a Senior Cyber Risk Manager!** **Join a Leading Team in the Banking Industry!** Are you a seasoned professional in the world of cyber risk and security? Do you have a track record of designing controls, setting standards, and providing expert governance advice in the realm of cyber security? If you're ready to make a significant impact and operate...


  • Sydney, Australia Domain Group Full time

    **Cyber Governance, Risk and Compliance Manager - Sydney Office - Permanent Full Time** We have a high impact; newly created opportunity for an experienced Cybersecurity Governance, Risk and Compliance (GRC) Manager, to join our Domain team. Reporting into the Chief Information Security Officer (CISO); you will be responsible for the implementation and...


  • Sydney, Australia iCare External Full time

    **About the Role** Accountable for leading our cyber-security assurance and governance team within digital and transformation, you will develop and drive icare’s Cyber Security posture and maturity against required policies and standards and uplift compliance of our partners and third-party suppliers. You will use your professional cyber expertise,...


  • Sydney, Australia HAYS Full time

    12-month contract role - federal government agency - Cyber Security Risk Assessment Officer **Your new company** This government agency is looking for a Cyber Security Risk Assessment Officer to join their Cyber Security team in an initial 12-month contract role with room for extension. You will have the opportunity of working at a federal government...


  • Sydney, New South Wales, Australia This Is An IT Support Group Full time

    Job DescriptionThis Is An IT Support Group is seeking a highly experienced Cyber Security Governance Strategist to join our team. As a key member of our Cyber Security team, you will play a crucial role in shaping the University's cyber security posture and ensuring compliance with internal standards, industry regulations, and legislative requirements.The...


  • Sydney, Australia University of New South Wales Full time

    **Job no**: 529814 **Work type**: Full Time **Location**: Sydney, NSW **Categories**: Information Technology, Cyber - Employment Type: full time continuing role as Head of Cyber Security and Governance - Excellent salary package including superannuation - Based Kensington, Sydney. Hybrid options available **Join Our High-Performing Cyber Security Team at...


  • Sydney, Australia NSW Department of Parliamentary Services Full time

    Temporary for up 12 months, with a view to ongoing employment - $106,025-$117,363 per annum (Clerk Grade 7/8), plus employers’ contribution to superannuation and annual leave loading - Hybrid work environment, located at NSW Parliament, Sydney CBD **About us** The Department of Parliamentary Services (DPS) is a specialist service department working to...


  • Sydney, Australia NSW Department of Parliamentary Services Full time

    Temporary for up 12 months, with a view to ongoing employment - $120,859.00 - $133,183.00 per annum (Clerk Grade 9/10) plus employers’ contribution to superannuation and annual leave loading - Hybrid work environment, located at NSW Parliament, Sydney CBD **About us** The Department of Parliamentary Services (DPS) is a specialist service department...


  • Sydney, Australia LGT Crestone Wealth Management Full time

    Min Experience- 10 yearsYour team - Working as a part of the Risk, Legal & Compliance team with overall responsibility to drive all strategic and operational cyber security and IT risk functions. - Working alongside the Head of Technology, senior business and risk executives and project management team within the reporting structure of the Chief Risk...


  • Sydney, Australia University of New South Wales Full time

    **Job no**: 527962 **Work type**: full time **Location**: Sydney, NSW **Categories**: Information Technology, Cyber - Employment Type: full time continuing role as a Cyber Security Risk Manager - Excellent salary package including superannuation - Location: UNSW Kensington Campus (Hybrid Working Opportunities) **About UNSW**: UNSW isn’t like other places...


  • Sydney, Australia APRA Full time

    Head of Cyber Risk and Response As a senior leader in the Non-Financial Risk team, the **Head of Cyber Risk and Response** will work collaboratively to deliver a range of initiatives and activities which drive the transformation of operational resilience across the industries APRA regulates. The scope of work will include the implementation of strategies...

  • Cyber Sec Governance

    3 months ago


    Sydney, Australia University of New South Wales Full time

    **Job no**: 528006 **Work type**: full time **Location**: Sydney, NSW **Categories**: Information Technology, Cyber - Employment Type: full time continuing role as a Cyber Security Governance and Compliance Manager - Excellent salary package including superannuation - Location: UNSW Kensington Campus (Hybrid Working Opportunities) **About UNSW**: UNSW...


  • Sydney, Australia Australian Prudential Regulation Authority (APRA) Full time

    As a senior leader in the Non-Financial Risk team, the **Head of Cyber Risk and Response** will work collaboratively to deliver a range of initiatives and activities which drive the transformation of operational resilience across the industries APRA regulates. The scope of work will include the implementation of strategies and work programs to enable...


  • Sydney, Australia University of New South Wales Full time

    **Job no**: 525136 **Work type**: full time **Location**: Sydney, NSW **Categories**: Information Technology, Cyber - Employment: Full time (35 hours per week) - Continuing role as a Cyber Security Risk Advisor - Remuneration: Excellent salary package including leave loading and generous superannuation - Location: Based in Kensington, Sydney (hybrid...


  • Sydney, Australia University of New South Wales Full time

    **Job no**: 527915 **Work type**: Full Time **Location**: Sydney, NSW **Categories**: Information Technology, Cyber - Employment Type: full time continuing role as a Cyber Security Risk Advisor - Exceptional salary package including generous superannuation - Location: UNSW Kensington Campus (Hybrid Working Opportunities) **About UNSW**: UNSW isn’t like...


  • Sydney, New South Wales, Australia Steadfast Group Limited Full time

    We are leaders in the general insurance broking and underwriting industry, with a strong presence in Australasia and growing international operations. Our company is built on the idea that a network of brokers would be stronger together, which has been the backbone of our culture since our founding.Job OverviewWe are seeking an experienced Cyber Security...