Cyber Security Risk Manager

3 months ago


Sydney, Australia University of New South Wales Full time

**Job no**: 527962
**Work type**: full time
**Location**: Sydney, NSW
**Categories**: Information Technology, Cyber
- Employment Type: full time continuing role as a Cyber Security Risk Manager
- Excellent salary package including superannuation
- Location: UNSW Kensington Campus (Hybrid Working Opportunities)

**About UNSW**:
UNSW isn’t like other places you’ve worked. Yes, we’re a large organisation with a diverse and talented community, a community doing extraordinary things. Together, we are driven to be thoughtful, practical, and purposeful in all we do. Taking this combined approach is what makes our work matter. If you want a career where you can thrive, be challenged and do meaningful work, you’re in the right place.

The Cyber Security Risk Manager is responsible for providing strategic leadership in developing and continuously improving the University’s cyber security risk management practices, ensuring that risks are continually identified, assessed, prioritised, monitored, and mitigated in line with UNSW’s Enterprise Risk Management framework. Key responsibilities include managing cyber security risk registers, leading risk remediation efforts, and developing risk mitigation strategies with measurable key risk indicators (KRIs) and key performance indicators (KPIs). The role also oversees vendor security risk management and annual threat assessments, while delivering regular risk updates to senior leadership and governance forums. The Cyber Security Risk Manager reports to the Head of Cyber Security Governance & Assurance and has direct reports.

**Accountabilities**:

- Provide strategic leadership in the development, execution and continuous improvement of the cyber security risk management practices in alignment with UNSW’s Enterprise Risk Management framework.
- Manage Cyber Security Risk Registers, ensuring identified risks are documented, assessed, prioritised, and remediated.
- Lead and direct risk remediation efforts, ensuring timely closure of identified risks.
- Develop and implement effective risk mitigation strategies and ensure alignment with business goals.
- Develop key risk indicators (KRIs) and key performance indicators (KPIs) to measure and track the effectiveness of risk management strategies.
- Ensure new risks are promptly registered and managed following assessments, assurance activities, or security incidents.
- Ensure that the threat, risk and control libraries on the GRC platform are up to date.
- Lead the execution, and continuous improvement of the annual threat and risk assessment process, including maturity assessments
- Lead and deliver the end-to-end vendor security risk management lifecycle process, including annual risk assessments for high-risk vendors, periodic scorecard reviews, and continuous monitoring through platforms such as UpGuard, CyberGRX and BitSight.
- Oversee and deliver the security review process for Requests for Information (RFIs) and Requests for Proposals (RFPs), embedding contractual security requirements in vendor agreements.
- Design and optimise operational metrics to drive continuous improvement of the overall cyber security risk management practice, ensuring timely and accurate reporting through the metrics dashboard for inclusion in the quarterly Risk and Safety Committee submissions.
- Lead the development and delivery of quarterly cyber security risk updates and briefings to IT executives, business partners, and relevant stakeholders, providing detailed insights into risks and mitigation action status and trends.
- Lead and manage the Cyber Security Risk Working Group, fostering cross-functional collaboration and driving key security risk management initiatives.
- Monitor internal and external environments for emerging threats, vulnerabilities, and regulatory changes.

**Who you are**:

- Extensive experience (7+years) in cyber security risk management, with demonstrated experience in conducting risk assessments, managing risk registers, and overseeing vendor security risk management programs.
- Proven experience in developing, implementing and operationally running the cyber security risk management practice in large and complex organisations.
- Hands on experience with security tools and platforms for monitoring, managing, and reporting on cyber security risks such as Protecht GRC tool, CyberGRX, UpGuard, and BitSight is highly desirable.
- Certifications such as CISM, CISSP, CRISC, AWS Security Speciality, Azure Security or related certifications are highly desirable.
- Strong knowledge of cyber risk management principles, methodologies, frameworks, such as ISO 27001, ISO 31000, NIST 800-53, FAIR and other industry standards.
- Proven experience in managing vendor security risk and developing operational metrics for risk management.
- Strong project management skills with the ability to balance multiple initiatives and deadlines.
- Excellent communication, negotiation and interpersonal skills, with a proven ability t



  • Sydney, Australia University of New South Wales Full time

    **Job no**: 527915 **Work type**: Full Time **Location**: Sydney, NSW **Categories**: Information Technology, Cyber - Employment Type: full time continuing role as a Cyber Security Risk Advisor - Exceptional salary package including generous superannuation - Location: UNSW Kensington Campus (Hybrid Working Opportunities) **About UNSW**: UNSW isn’t like...


  • Sydney, Australia University of New South Wales Full time

    **Job no**: 525136 **Work type**: full time **Location**: Sydney, NSW **Categories**: Information Technology, Cyber - Employment: Full time (35 hours per week) - Continuing role as a Cyber Security Risk Advisor - Remuneration: Excellent salary package including leave loading and generous superannuation - Location: Based in Kensington, Sydney (hybrid...


  • Sydney, Australia LGT Crestone Wealth Management Full time

    Min Experience- 10 yearsYour team - Working as a part of the Risk, Legal & Compliance team with overall responsibility to drive all strategic and operational cyber security and IT risk functions. - Working alongside the Head of Technology, senior business and risk executives and project management team within the reporting structure of the Chief Risk...

  • Incident Responder

    7 months ago


    Sydney, Australia Quigly Cyber Full time

    Diverse, inclusive and supportive team - Proudly making a difference with the transition to renewable energy - You love Cyber Security Quigly are a boutique consultancy with a great network of clients across many industries. **Company Overview** Join one of Australia's top organizations. Our client improves the lives of millions - from lighting up sports...


  • Sydney, New South Wales, Australia NSW Government Full time

    About the Role:We are seeking a highly skilled Cyber Security Risk Management Specialist to join our team. This is an exciting opportunity to work with a dynamic organization that values innovation and collaboration.The successful candidate will play a key role in safeguarding our digital assets through proactive measures, threat monitoring, and ensuring...

  • Cyber Security

    7 months ago


    Sydney, Australia The Recruitment Company Full time

    **Cyber Security & Risk Manager** **Location: South Sydney** **Permanent** **Salary: $190,000 - $230,000** **3 Days Office, 2 Days WFH** **The Role** This is your opportunity to work for a well regarded faith based organisation to help uplift their Security & IT Risk functions. The framework is in place but this is your opportunity to build on that. A...


  • Sydney, New South Wales, Australia Stockland Full time

    Stockland Overview">We are a leading retail property group in Australia, with a long history of innovation and commitment to customer satisfaction. Our technology team is at the forefront of driving digital transformation across the organization, and we are now seeking a highly skilled Cyber Security Risk Manager to join our team.">Job Description">In this...

  • Manager Cyber Risk

    4 months ago


    Sydney, Australia Commonwealth Bank Full time

    **See yourself in our team**: The Technology and Operations (Tech & Ops) Risk team is responsible for providing specialist Operational Risk and Compliance (OR&C) advice and assurance of decisions made across the Technology, Chief Operating Office, and Business Unit divisions. **Do work that matters**: The Manager Cyber Risk plays and essential role within...


  • Sydney, Australia HAYS Full time

    12-month contract role - federal government agency - Cyber Security Risk Assessment Officer **Your new company** This government agency is looking for a Cyber Security Risk Assessment Officer to join their Cyber Security team in an initial 12-month contract role with room for extension. You will have the opportunity of working at a federal government...


  • Sydney, Australia QBE Full time

    Primary Details Time Type: Full time Worker Type: Employee- Location: Sydney- Type: Permanent, full time The opportunity The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is a technical and people leader...


  • Sydney, New South Wales, Australia EFinancialCareers Ltd. Full time

    About the RoleCyber security is a critical component of our organization, and we're seeking an experienced Strategic Risk Leader to join our team. As a key member of our Cyber Security function, you will be responsible for providing strategic advice on operational and compliance risk management. Your expertise will help us design and implement effective...


  • Sydney, Australia Charterhouse Full time

    Excellent opportunity for senior Security professionals with aspirations to work towards the executive suite as you will be engaging with C level on a regular basis and operate at a strategic level. The ability to communicate technical terminology into business risks is essential and your communication style should be collaborative to see you successful in...


  • Sydney, Australia Commonwealth Bank of Australia Full time

    Cyber Defence Risk Manager **See yourself in our team**: The Technology and Operations (Tech & Ops) Risk team is responsible for providing specialist Operational Risk and Compliance (OR&C) advice and assurance of decisions made across the Technology, Chief Operating Office, and Business Unit divisions. **Do work that matters**: You will play a key role...

  • Cyber Security Manager

    11 minutes ago


    Sydney, Australia Siemens Full time

    Working in partnership with the NSW Government, the Parklife Metro consortium is working on an exciting new metro rail infrastructure project in Greater Western Sydney. Comprising, Plenary, RATP Dev, Siemens and Webuild, the private sector partners are looking to build their metro rail expertise to deliver this city-shaping project, which will be delivered...

  • Cyber Risk Analyst

    2 weeks ago


    Sydney, Australia GWG Full time

    12 month contract - 100% remote opportunity - Large well-established organisation **The Company** This large organisation is dynamic and rapidly evolving in a changing ecosystem. Seeking to improve safety, performance, and culture while driving efficiency, managing costs, and creating value in a best practice environment. As the business continues its path...

  • Cyber Security Officer

    34 minutes ago


    Sydney, Australia Charterhouse Full time

    **Join a NSW State Government Department and have an active role in keeping Australian's Cyber Safe**: - **Up to $700/day + Superannuation (PAYG or PTY options available) with weekly pay**: - **6-month contract with potential for extension**: - **Hybrid working from home, office located in Sydney Olympic Park** **Role Description** - Assisting the...


  • Sydney, Australia Service NSW Full time

    **Cyber Security Advisor Manager** - ** SNSW **G**rade** 11/12**: - ** 1** x **Ongoing Full-Time**: - ** Headquarter location is McKell, Sydney** As the Cyber Security Advisor Manager,** **you will provide complex cyber security, advice, awareness, resilience and/or training initiatives for Cyber Security to improve organisational or whole-of-government...

  • Cyber Security Analyst

    2 months ago


    Sydney, Australia CYOS Solutions Full time

    **Application closing date**: Tuesday, 12 November 2024 - 11:59pm, Canberra time **Estimated start date**: Monday, 16 December 2024 **Location of work**: NSW **Working arrangements**:Subject to negotiations with line manager, hybrid working arrangements in line with current NDIA policy are available (minimum of 3 days each week in the office, with...

  • Cyber Security Officer

    33 minutes ago


    Sydney, Australia Easy Authoring Full time

    **6 months contract role with possible extension.**: - **Daily pay rate up to $700 **+ Super.**: - **Working 38 hours per week, 7.6 hours per day.**: - **Work Location: Sydney Olympic Park.** **PURPOSE OF THE ROLE**: You will assist the manager and the team with the implementation of the Cyber Security Policy and Essential 8, including annual reporting...

  • Manager, Cyber Risk

    7 months ago


    Sydney, Australia Clyde&Co Full time

    Job Title - Manager, Cyber Risk - Job Location - Sydney - Job Type - Business Services - Country/Territory - Australia - Region - Asia Pacific - Description **About the team** Clyde & Co is an international law firm, with the largest, dedicated cyber incident response practice in Australia. The team advises small, medium, and large organisations...