Information Security Risk Management Lead
2 months ago
**Job Description** Our client’s success is our success. And you make it happen**
Payment systems are complex, regulated and everchanging. We are an established market leading brand who are focused on driving client growth. We’re at the forefront of innovation punching above our weight. We’re enabling the future for our clients through innovative technology like the New Payments Platform (NPP) and open banking.
We are an unlisted public company and one of five licensed banks in Australia with full direct connectivity and production capability across all domestic payment systems. Whilst the major banks leverage this capability for their consumer and business clients, our B2B model focuses on enabling other banks, fintech’s and corporates to deliver innovative and competitive payment and digital solutions to their clients and customers.
**We are looking for an Information Security Risk Management Lead in our Group Risk and Compliance Team.**
Reporting to the Head of Operational Risk and Compliance, the Information Security Risk Management Lead is responsible for technology risk advisory, review/challenge, oversight and monitoring over information security and data risk frameworks and how it is operationalised.
This is a highly visible role in the business ensuring technology risks are effectively identified, assessed, managed and monitored across Cuscal. Responsibilities of the Information Security Risk Management Lead in the team’s capacity as the second line of defence under the Risk Management Framework fall into four key areas:
**1) Technology Risk Management Framework Advisory, Oversight and Monitoring**
- Ensure Information Security Risks (technology and cyber) and Data risks are adequately managed through Cuscal’s frameworks in line with regulatory requirements (e.g. CPS 234,230, CPG 235 etc.), industry best practices and operating environment in line with three lines of defence
- Ensure line 2 risk management capability is built and sustained to review, challenge, oversight and assurance reinforcing and maturing line 1 accountability with the business owners
- Work collaboratively with Product domains, Engineering and corporate functions to embed technology risk management practices into everyday activities, embed controls, and monitor/report on issues.
- Foster a risk culture that promotes open communication, transparency, and ownership of risk at all levels of the organisation
- Risk Reporting & Analytics: Provide insights derived from technology and data risk reporting to the Board and Executive Leadership Team
**2) 2nd Line Review, Challenge and Oversight**
- Review and challenge risk/RiC assessments, adequacy and effectiveness of risk mitigation strategies, controls, and action plans implemented by 1st line teams.
- Critically assess incidents, breaches, and near misses to identify systemic issues and recommend appropriate remediation actions.
- Ensure the continuous improvement of risk management practices by engaging with business units to provide constructive feedback and challenge assumptions.
- Act as a trusted advisor to senior leadership and business units on operational risk matters, including emerging risks, regulatory changes, and industry trends.
- Drive education and training programs to elevate operational risk awareness and capabilities across the organisation.
- Collaborate with product, client, and technology teams to ensure operational risk considerations are integrated into new initiatives, system changes, and major projects.
- Line 2 support for assessments of third-party technology risks and controls.
**3) Emerging Risks and Innovation**
- Stay informed about the latest developments in AI and other emerging technologies to proactively identify potential risks. Support Cuscal teams in rapidly adopting new technologies in a safe and controlled manner.
- Review/provide oversight over initiatives to automate technology risk & controls monitoring processes using advanced tools and technologies.
- Promote a culture of innovation in risk management practices, encouraging the adoption of new approaches and technologies.
**4) Stakeholder Engagement**
- Work closely with internal and external stakeholders as required, to ensure a cohesive approach to technology risk management.
- Develop and deliver training programs to enhance technology risk awareness and competency across Cuscal.
- Promote and drive a positive risk culture to lift overall risk management maturity across Cuscal.
**About You**
To be successful in this position you will have the following skills and experience:
- Bachelor’s degree in information technology, Information Systems, Risk Management, Cybersecurity, Computer Engineering, or a related field. Relevant certifications (e.g., CRISC, CISA, CISSP) are desirable.
- Minimum of 4-6 years of experience in technology risk management within the financial services industry.
- Strong knowledge of risk management and IT frameworks and standards such a
-
Information Security Risk Management Lead
2 months ago
Sydney, Australia Cuscal Limited Full timeJob DescriptionOur client’s success is our success. And you make it happen! Payment systems are complex, regulated and everchanging. We are an established market leading brand who are focused on driving client growth. We’re at the forefront of innovation punching above our weight. We’re enabling the future for our clients through innovative technology...
-
Information Security Manager
2 months ago
Sydney, Australia Amex Full time**You Lead the Way. We’ve Got Your Back.** With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create...
-
Sydney, New South Wales, Australia Cuscal Full timeCompany OverviewCuscal is an established market-leading brand in the payments sector, driving client growth and innovation through cutting-edge technology like the New Payments Platform (NPP) and open banking.We are one of five licensed banks in Australia with full direct connectivity and production capability across all domestic payment systems.Cuscal's...
-
Cyber & Information Security Lead
1 month ago
Sydney, Australia MARS Recruitment Full timeJob Title: Cyber and Information Security LeadLocation: Sydney CBD (Hybrid Work - 3 days in the office, 2 days WFH)About the RoleWe are seeking a highly motivated and technically skilled Cyber and Information Security Lead to join a fast-growing, innovative organisation. This role is perfect for someone with a strong background in security architecture and...
-
Information Security Manager
2 months ago
Sydney, Australia GBST Full timePosted: 28/10/2024 Closing Date: 29/11/2024 **Job Type**: Permanent - Full Time Location: Sydney Job Category: Information Technology Joining GBST means you will be part of a global leader in financial services technology. We are a forward-thinking business, delivering innovative wealth management solutions to enable, support and scale wealth management...
-
Sydney, New South Wales, Australia Tal Services Limited Full timeAbout TAL Services LimitedTAL Services Limited is a leading provider of risk management solutions, committed to fostering an inclusive and equitable culture for all its people. We value diversity in all its forms and strive to create a work environment that promotes equality and respect.Our mission is to provide innovative risk management solutions that meet...
-
Information Security Manager
6 months ago
Sydney, Australia NGS Super Full time**Introduction**: NGS Staff Benefits Before you learn more about the job ad, we encourage you to familiarise yourself with our fantastic NGS Staff Benefits page (link below) to understand our offering which includes Additional Leave Entitlements, Personal & Professional Development and Health & Wellbeing Benefits. About us We are an award winning,...
-
Cyber Security Risk Management Lead
4 weeks ago
Sydney, New South Wales, Australia Pyramid Global Technologies Full timeAbout the RolePyramid Global Technologies seeks a highly skilled Cyber Security Risk Management Lead to support the delivery and continuous improvement of its Information Security Management System (ISMS). The successful candidate will have a minimum of 10 years of experience in cyber security roles within major organisations, focusing on management of...
-
Information Security, Risk and Compliance Consultant
7 months ago
Sydney, Australia Launch Recruitment Full timeHybrid Working - 3 days in the office 2 days fromt home - ISO experience is essential certified is a beneficial - Insurance Expereince would be an advantage The Information Security, Risk and Complaince Consultant will collaborate with compliance, security, and general IT risks to ensure that IT supports the business objectives of the group, while enforcing...
-
Technology Risk Management Leader
4 weeks ago
Sydney, New South Wales, Australia Group Risk Full timeCompany Overview">The Star Entertainment Group is a leading gaming and hospitality company in Australia, committed to creating fun at trusted destinations. With a strong focus on sustainability, we aim to deliver exceptional experiences for our guests, employees, and the communities we serve.">Salary">We offer an attractive salary of $150,000 - $180,000 per...
-
Information Security Governance Lead
2 weeks ago
Sydney, New South Wales, Australia Cuscal Limited Full timeAbout the JobThis is a highly visible role that requires expertise in technology risk management, particularly in the financial services sector. As an Information Security Risk Management Lead, you will work closely with the Head of Operational Risk and Compliance to develop and implement technology risk management strategies that align with regulatory...
-
Protective Security Risk
6 months ago
Sydney, Australia Australian Security Recruitment Pty Ltd Full timeInteracting with the Executive, senior management, and key regulators. - Executive interaction as well as electronic security technical and/or specialist **Position Vacant**: **Protective Security Risk and Governance Manager (Sydney CBD Based)** **The Employer**: With this opportunity we represent the largest distributor of electricity on Australia’s...
-
Cyber Information Security Lead
4 weeks ago
Sydney, New South Wales, Australia Employers Mutual Management Pty Ltd Full timeJob OverviewEmployers Mutual Management Pty Ltd is seeking an experienced Cyber & Information Security Manager to join our team in Sydney. This permanent, full-time position offers a rewarding opportunity for individuals with expertise in information security management to contribute to the company's growth and success.
-
Information Security Risk Governance Specialist
4 weeks ago
Sydney, New South Wales, Australia Cuscal Limited Full timeOverviewCuscal Limited is a pioneering leader in the Australian payments sector, empowering innovation and growth through cutting-edge technology.About the RoleWe are seeking an experienced Information Security Risk Governance Specialist to join our Group Risk and Compliance Team. Reporting directly to the Head of Operational Risk and Compliance, you will...
-
IT Security Risk Manager
2 months ago
Sydney, Australia Ambition Full timeJob Title: IT Security Risk ManagerLocation: Sydney, Australia (Flexible Working)Contract Type: 6 months, immediate startJob Description:We are seeking an IT Security Risk Manager for a short-term project to implement an Information Security Management System (ISMS). This role offers the opportunity to collaborate with internal stakeholders, identify...
-
Security Manager
6 months ago
Sydney, Australia Constant Security Full time**The Company** We are placing this role into our client who were established in Australia in 2013, and is a leading, fully integrated owner, operator, investment manager and developer of purpose-built student accommodation (PBSA) and lifestyle solutions, with billions of dollars in assets under management, on behalf of global wholesale and institutional...
-
Cyber & Information Security Manager
4 months ago
Sydney, Australia EML Full timeEML is a leading Workers Compensation and Personal Injury Claims Management business. Our goal is to help people get their lives back through ongoing support during their return-to-work journey. We continue to experience ongoing growth and now have over 4,000 dedicated employees. We foster a learning culture that allows for us to continually invest in our...
-
Information Security Strategist
1 month ago
Sydney, New South Wales, Australia ClearCompany Full timeAt ClearCompany, we are seeking an experienced Chief Information Security Officer to lead our organization's information security efforts.OverviewWe are a cutting-edge technology firm dedicated to delivering innovative solutions that transform the way organizations operate. Our team is passionate about creating a secure and reliable environment for our...
-
Cyber & Information Security Manager
3 months ago
Sydney, Australia EML Group Full timeCyber & Information Security Manager EML is a leading **Workers Compensation** and **Personal Injury Claims Management** business. Our goal is to help people get their lives back through **ongoing support during their return-to-work journey**. We continue to experience ongoing growth and now have over **4,000 dedicated employees**. We foster a learning...
-
Chief Information Security Officer
2 weeks ago
Sydney, New South Wales, Australia Cuscal Limited Full timeJob TitleInformation Security Risk Management LeadAbout the RoleThis is a high-profile opportunity to join Cuscal Limited, a leading company in Australia, as an Information Security Risk Management Lead. The role involves overseeing technology risk advisory, review, challenge, and monitoring for information security and data risks.ResponsibilitiesEnsure...