Information Security Risk and Assurance Manager

6 months ago


Melbourne, Australia HESTA Super Fund Full time

**_Be inspired everyday_**

At HESTA we’re a leading national superannuation fund dedicated to people working in health and community services - a growing sector of ordinary people doing extraordinary things, day in day out, right across Australia.

More than 1 million Australians trust HESTA with their money. So together, we invest billions of their savings globally, striving to generate strong investment returns and make a real difference to their financial futures. Our focus is on helping our members enjoy the retirement they’ve worked hard for.
- **Do you have a passion for information and cyber security?**:

- **Do you want to be part of a talented team and a unique opportunity that blends leadership and technical skills?**

Our business is rapidly transforming and our information security capability is growing.

**The opportunity**

Reporting directly into the GM Information Security, this critical leadership role will oversee and implement robust information security governance, risk, and assurance practices through management of HESTA’s Information Security Management System (ISMS).

This role will lead the uplift of maturity and operations of HESTA’s Information Security Governance, Risk and Assurance Framework and team, and contribute to the delivery of HESTA’s information security program, strategy implementation, key initiatives and priorities.

This includes maintaining and evolving an ISO27001 based ISMS framework, ensuring alignment with the organisation's security objectives, regulatory obligations, and risk appetite.

You will play a vital part in making sure information security is implemented and operated in the way it should be, adhering to regulatory requirements as well as our own policies, standards and procedures, to keep us in check and secure

**About you**

You will be a seasoned Information Security leader that has built and lead security risk and assurance teams. You will have experience working with or working knowledge of governance tools such as One Trust or Archer GRC, and a working understanding of enterprise operations that span across Public Cloud environments, and security principles across Iaas, PaaS and SaaS. This role will also develop, govern and oversee technical security assurance capabilities across penetration testing, vulnerability management, and security controls testing.

You will have a strong understanding of security obligations for APRA regulated entities, experience and knowledge of security standards and frameworks such as NIST Cybersecurity Framework, ISO27001/2, including security controls and compliance requirements.

You will be agile in your approach, embrace impactful leadership and develop your team to be the best they can be. You will work collaboratively with key stakeholders to ensure outcomes are achieved and provide leadership and support to ensure a strong security posture is achieved and maintained in alignment with the HESTA’s Information Security Strategy.

**_We will leave all the ‘work you’ll be doing’ stuff in the PD but here’s a few things that you’ll get to enjoy working at HESTA:_**
- Your leave and time off matters, up to 6 days paid volunteer leave, up to an additional 5 days of leave over the end of year and new year period, access your LSL after 3 years Take AL at half pay, and purchase up to 2 weeks additional leave
- Your professional development matters, up to $5k per year professional development and up to 8 days professional development leave, HESTA scholarships and free access to a range of premium learning tools
- Your health and wellbeing matters, free annual flu shots and skin checks, incredible social events throughout the year and a comprehensive employee assistance program available 24/7
- Your financial wellbeing matters, financial planning support, end of year payment for all Enterprise Agreement-covered employees, incentivised Employee Referral Program and novated lease options

HESTA is a great place to work but don’t take our word for it, we were named (again) Employer of Choice for Gender Equality 2022.



  • Melbourne, Australia HESTA Full time

    Information Security Risk and Assurance Manager **Be inspired everyday** At HESTA we're a leading national superannuation fund dedicated to people working in health and community services - a growing sector of ordinary people doing extraordinary things, day in day out, right across Australia. More than 1 million Australians trust HESTA with their money....


  • Melbourne, Australia Australian Unity Full time

    **Join us and let’s make a bigger difference together.** It’s an exciting time to be joining Australian Unity - we have grown significantly over recent years and are transforming to capitalise on further growth opportunities to help our customers and employees thrive. We operate with commercial principles and with a strong social purpose to create...


  • Melbourne, Victoria, Australia Bank of Queensland Full time

    About the RoleWe are seeking an experienced Risk Management Leader to drive the implementation, monitoring, and assurance of our Risk Management Strategy (RMS) and operational risk management framework (ORMF). As a key member of our team, you will play a crucial role in managing technology, information security, and service delivery risks, ensuring alignment...


  • Melbourne, Australia Department of Education Full time

    Location: Melbourne | CBD Job type: Full time Organisation: Department of Education **Salary**: $134,593 - $180,115 Occupation: IT and Telecommunications Reference: VG/DE/FPIS/1835672 **About the Department** The department provides a wide range of learning and development support and services. The department provides policy leadership, plans for...


  • Melbourne, Australia Experis Full time

    Shape the security strategy for a renowed educational instituate. - Permanent opportunity with a competive salary package - Hybrid work arrangement - Footscray Office As the Cyber Risk and Assurance Manager you will lead cybersecurity governance, risk, compliance, and assurance. You will establish strong security practices, define standards, and manage...


  • Melbourne, Victoria, Australia Bank of Queensland Full time

    About this RoleWe are seeking an experienced Chief Information Security and Risk Management Officer to join our team at Bank of Queensland. This is a key role in driving the implementation, monitoring, and assurance of our Risk Management Strategy (RMS) and operational risk management framework (ORMF).This position focuses on managing technology, information...


  • Melbourne, Australia Talent International Full time

    australia melbourne permanent negotiable- Permanent Position - Government Agency - CBD Location - Hybrid Working Environment - VPS6 - $130,673 - 174,869 + super **The role**: Our Victorian Government client is seeking a highly skilled and motivated Security Risk and Assurance Manager to join their Information Management and Technology Division...


  • Melbourne, Australia KPMG Full time

    Immerse yourself in our inclusive, diverse and supportive culture - Choose the way you want to work by embracing our flexible work arrangement - Collaborate with sector and technical experts to grow your knowledge and network KPMG Australia is part of a global network providing extensive services across a wide range of industries and sectors. Our people...


  • Melbourne City Centre, Australia Department of Education Full time

    About the Department The department provides a wide range of learning and development support and services. The department provides policy leadership, plans for the future of education in Victoria and leads key cross-sector collaboration. The department plays an important system steward role by providing support, guidance, oversight and assurance across...


  • Melbourne City Centre, Australia Department of Education Full time

    **About the Department** The department provides a wide range of learning and development support and services. The department provides policy leadership, plans for the future of education in Victoria and leads key cross-sector collaboration. The department plays an important system steward role by providing support, guidance, oversight and assurance...


  • Melbourne, Australia KPMGau Full time

    Job DescriptionImmerse yourself in our inclusive, diverse and supportive cultureChoose the way you want to work by embracing our flexible work arrangementCollaborate with sector and technical experts to grow your knowledge and networkKPMG Australia is part of a global network providing extensive services across a wide range of industries and sectors. Our...


  • Melbourne, Australia Guild Group Holdings Ltd Full time

    Head of Information Security **Head of Information Security** **Job Number**: 493552 **Work type**: Full Time Permanent **Location**: Melbourne (CBD) **Categories**: Technology **Head of Information Security** **About the role...** Reporting to the Chief Information Officer you will be part of our Group Technology function at Guild Group. The Head of...


  • Melbourne, Victoria, Australia Department of Government Services Full time

    Established in 2023, the Department of Government Services is dedicated to streamlining services for Victorians and businesses. As a Cyber Assurance and Risk Management Lead, you will support the Victorian Government Chief Information Security Officer and Executive Director, Data and Digital Resilience in uplifting cyber security across the Victorian Public...


  • Melbourne, Australia Angle Finance Full time

    Angle Finance is a leading non-bank asset finance company operating in the rapidly growing intermediary asset finance market. Our signature is Faster, Easier Finance, provided by consistent, predictable and reliable service propositions in everything we do. Our people make us remarkable. So we’ve built a culture of empowerment, enabling our people to make...


  • Melbourne City Centre, Australia Victorian Building Authority Full time

    Position overview The Manager, Information Security leads the Information Security function and is responsible for assisting business teams and projects understand information security risks, identification of treatments to manage those risks and compliance with VBA and VPDSS Information Security standards and policies. The role contributes to improving the...


  • Melbourne, Australia Victorian Building Authority Full time

    Location: Melbourne | CBD Job type: Full time Organisation: Victorian Building Authority **Salary**: $130,673 - $174,869 Occupation: IT and Telecommunications Reference: VG/6467 We are seeking a Manager, Information Security who will play a key role in leadership, both identifying and driving initiatives for the organisation's...


  • Melbourne, Australia Bupa Full time

    A full time, permanent opportunity has become available in our Risk & Assurance team within Bupa Government Contracts. This includes the Bupa ADF Health Services contract (ADFHS) which provides integrated and seamless end-to-end health support to 85,000 Australian Defence Force (ADF) personnel across 59 facilities as well as Bupa Medical Visa Services (BMVS)...


  • Melbourne, Australia Wyn&Co Full time

    Hybrid work environment / work from home / WFH - Exciting IT and Operational Technology Environment - Supportive and Inclusive Team Environment & Culture WYN&CO Recruitment have an exciting opportunity for an **Information Security Advisor** working with a leading public infrastructure and asset management company based in Melbourne. **ROLE...


  • Melbourne, Australia Aurecon Group Full time

    Just imagine your future with us - At Aurecon we see the future through a very different lens. Do you? - Innovation, eminence and digital are at the heart of everything we do. Are you excited about the future? Are you driven by the opportunity to work on some of the most challenging and complex projects around the world and to learn from the best? We...


  • Melbourne, Victoria, Australia Ntt Full time

    About the RoleThe estimated annual salary for this position is $85,000 to $110,000 depending on experience.Job OverviewWe are seeking an experienced Chief Information Security Risk Manager to join our team at NTT DATA. The successful candidate will be responsible for monitoring, analyzing, and interpreting client data to deliver security information and...