Security Risk and Compliance Specialist

2 weeks ago


Sydney, Australia Xero Full time

Xero is a beautiful, easy-to-use platform that helps small businesses and their accounting and bookkeeping advisors grow and thrive.

At Xero, our purpose is to make life better for people in small business, their advisors, and communities around the world. This purpose sits at the centre of everything we do. We support our people to do the best work of their lives so that they can help small businesses succeed through better tools, information and connections. Because when they succeed they make a difference, and when millions of small businesses are making a difference, the world is a more beautiful place.

**About the role**

The Security Risk and Compliance Specialist will bring their experience to a team working with all parts of the business to improve Xero’s security risk and compliance posture, to reduce the risk of security incidents and improve the efficiency and effectiveness of Xero’s security controls.

**What you'll do**:
- Support contributors across Xero in conducting risk assessments to identify potential security threats and vulnerabilities, and evaluate security risks across all areas of Xero’s business, including product and technology, and third party software and services, to ensure these are well understood and managed within Xero’s risk tolerance.
- Ensure security compliance obligations with applicable laws, regulations and standards such as ISO 27001, SOC 2, PCI-DSS or other international or regional frameworks, are understood and met across Xero.
- Support product teams in performing threat modeling of new/updated product features.
- Perform risk assessments for Ecosystem partners and third party suppliers, ensuring that security risks are assessed and understood prior to, and during the engagement with the third party.
- Using the security risk management framework, ensure risks are documented, quantified, owned, communicated and escalated as appropriate across Xero.
- Provide input to responses to customer and supplier security assessments.
- Monitor and assess emerging security threats that could affect Xero, and propose strategies to mitigate them.
- Support process improvement and automation using technical skills and experience.
- Foster cross-disciplinary understanding of security risk and compliance and raise awareness of risk

**What success looks like**:
- Changes to Xero’s product and corporate infrastructure are in compliance with the IT Security Policy and standards and meet Xero’s compliance obligations.
- Risks are identified and managed according to Xero’s risk appetite, in a timely manner and in alignment with business objectives.
- Security assessments are completed and documented for all new third party software and technology services.
- Audits and other compliance assessment activities are completed successfully, and compliance is maintained with required standards.
- Management has timely and appropriate visibility of Xero’s security risk status.

**What you'll bring**:
- 3+ years in a role in an information security and risk management practice
- Experience with ISO27001:2022, SOC 2 Type 2 or PCI-DSS compliance frameworks
- Recognised as a high performer and leading contributor in your team.
- Experience working with AI and data to drive automation.

**Why Xero?**

Offering very generous paid leave to use however you’d like (plus statutory holidays), dedicated paid leave to care for your physical and mental wellbeing as well as an Employee Assistance Program to access mental health care for you and your family, health insurance, life insurance, and income protection, wellbeing and sports programmes, employee resource groups, 26 weeks of paid parental leave for primary caregivers, an Employee Share Plan, beautiful offices, flexible working, career development, and many other benefits that reflect our human value, you’ll do the best work of your life at Xero.


  • Compliance Specialist

    6 months ago


    Sydney, Australia Risk Full time

    **We are Woolworths Group **We are Woolworths Group. 200,000+ bright minds, passionate hearts and unique perspectives connected by a shared Purpose - ‘to create better experiences together for a better tomorrow.’ It’s that Purpose that fuels our ambition to explore new ideas, make brave commitments and innovate better ways to meet the food and everyday...


  • Sydney, New South Wales, Australia Google Full time

    About the RoleWe are seeking a highly skilled Senior Cloud Security Specialist to join our team as Regional Cloud Risk and Compliance Lead. In this role, you will be responsible for establishing and maintaining a comprehensive information security program that protects business and unlocks markets.The ideal candidate will have a strong background in cloud...


  • Sydney, Australia Australian Security Recruitment Pty Ltd Full time

    Interacting with the Executive, senior management, and key regulators. - Executive interaction as well as electronic security technical and/or specialist **Position Vacant**: **Protective Security Risk and Governance Manager (Sydney CBD Based)** **The Employer**: With this opportunity we represent the largest distributor of electricity on Australia’s...


  • Sydney, Australia NSW Department of Parliamentary Services Full time

    Exciting opportunity to work with a dynamic team leading the strategy, compliance and resilience of Australia’s oldest Parliament and State Electorate Offices - Temporary full-time position (with the possibility of ongoing) - $120,859 - $133,183 per annum (Clerk Grade 9/10), plus employers contribution to superannuation and annual leave loading - NSW...


  • Sydney, Australia Risk Full time

    **We are Woolworths Group** We are Woolworths Group. 200,000+ bright minds, passionate hearts, and unique perspectives across Australia and New Zealand. Connected by a shared Purpose - 'to create better experiences together for a better tomorrow'. That Purpose fuels our ambition to explore new ideas, make brave commitments, and innovate better ways to meet...


  • Sydney, Australia QBE Full time

    Primary Details Time Type: Full time Worker Type: Employee- Location: Sydney- Type: Permanent, full time The opportunity The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is a technical and people leader...


  • Sydney, Australia Reserve Bank of Australia Full time

    We have a 12 Month Contract opportunity for a motivated and knowledgeable security risk analyst to provide specialised skills in relation to security governance & compliance, risk and assurance to meet the requirements of the IT Department risk function. In this role you will provide assurance over the Bank’s controls for IT risk, as well continual...


  • Sydney, New South Wales, Australia Perpetual Full time

    About the OpportunityWe are seeking a highly skilled Risk and Compliance Specialist to join our team at Perpetual. This is an exciting opportunity to make a real impact in shaping our risk management framework and ensuring compliance with all applicable laws, regulations, and internal policies.As a Risk and Compliance Specialist, you will be responsible for...


  • Sydney, Australia Launch Recruitment Full time

    Hybrid Working - 3 days in the office 2 days fromt home - ISO experience is essential certified is a beneficial - Insurance Expereince would be an advantage The Information Security, Risk and Complaince Consultant will collaborate with compliance, security, and general IT risks to ensure that IT supports the business objectives of the group, while enforcing...


  • Sydney, New South Wales, Australia CMC Markets Full time

    CMC Markets, a global leader in CFD trading and share investing, is seeking a highly experienced Risk Compliance Specialist to join their team.As a key member of the compliance team, you will play a critical role in ensuring the company's risk management and regulatory compliance framework is effective and up-to-date.The ideal candidate will have at least 5...


  • Sydney, New South Wales, Australia TAL Full time

    At TAL, we are seeking a highly skilled Cyber Security Risk Management Specialist to join our team in Third-Party Tech & Cyber Risk. This role plays a critical part in aligning with our strategy and executing third-party technology risk management, cyber security management, and relevant technology and cyber clauses within the contractual management...

  • Terminal Security

    6 months ago


    Sydney, Australia Certis Security Australia Full time

    Certis Security Australia is one of Australia’s leading security service provider with over 3,000 employees nationwide, providing our clients with industry leading security services with our state-of-the-art technology and highly qualified staff. As part of the Certis Group, SNP Security and BRI Security deliver integrated security solutions including...


  • Sydney, New South Wales, Australia CMC Markets Stockbroking Limited Full time

    About the RoleWe are seeking a highly skilled Risk and Compliance Specialist to join our team at CMC Markets Stockbroking Limited. As a key member of our compliance team, you will play a crucial role in ensuring that our stockbroking operations are in line with regulatory requirements.Job DescriptionThis is a 12-month fixed-term contract based in either our...

  • Security Manager

    6 months ago


    Sydney, Australia Constant Security Full time

    **The Company** We are placing this role into our client who were established in Australia in 2013, and is a leading, fully integrated owner, operator, investment manager and developer of purpose-built student accommodation (PBSA) and lifestyle solutions, with billions of dollars in assets under management, on behalf of global wholesale and institutional...

  • Compliance Specialist

    7 months ago


    North Sydney, Australia TPG Telecom Full time

    We’ve only just begun, but what a beginning. In a once in a generation moment, we’ve brought together powerful brands to create one united force. TPG Telecom has a powerhouse of brands which include Vodafone, TPG, iiNet, Internode, Lebara, AAPT and felix. The latest technology and brave thinking let us connect our people and communities. You could play...

  • 1st Line Risk

    7 months ago


    Sydney, Australia Insignia Financial Full time

    1st Line Risk & Compliance Specialist - Technology Controls Testing - Collaborative & supportive team environment - opportunity to grow and develop - Work for a leading wealth management company - Hybrid working environment - WFH/Office (Sydney or Melbourne) **The Role** This is your opportunity to contribute to an organisation which focuses on its people...


  • Sydney, New South Wales, Australia Square Full time

    Job Description:We are seeking a highly motivated Risk Management Specialist to join our Line 2 Risk and Compliance Team in Australia. As a key member of our team, you will be responsible for helping us understand, manage, and take calculated risks to drive business growth.In this role, you will work closely with Senior Managers in Risk & Compliance to...


  • Sydney, New South Wales, Australia Pitcher Partners Australia Full time

    About Us:Pitcher Partners Sydney is a leading Professional Chartered Accounting firm located in the heart of the CBD, offering a vibrant culture and great flexible working policy. We are a network of independent firms working together to enable growth and ambition for our clients and people.The successful candidate will be joining a team with heart,...


  • Sydney, Australia Rabobank Full time

    Rabobank is the world’s leading specialist in food and agribusiness banking. One of our key strengths lies in our people who have a deep understanding of agriculture and are committed to adding long-term value for clients. Our commitment to our employees and clients is at the heart of everything we do. Rabobank has an opening for a Risk and Compliance...


  • Sydney, New South Wales, Australia SS&C Bluedoor Pty Limited Full time

    Job OverviewAt SS&C Bluedoor Pty Limited, we are seeking a skilled Compliance Risk and Governance Specialist to join our team. This role will involve working closely with the Compliance Team to monitor activities, improve compliance practices, and enhance the overall risk profile of the organization.