Head of Information Security
1 day ago
Reporting to the Chief Operating Officer (COO), the Head of Information Security leads ARPC’s enterprise approach to cyber security covering strategy, implementation, compliance, and incident response.
A core accountability of the role is to advise, write for, and present to the ARPC Board and its Committees supporting the COO, ensuring the Board has clear, timely, and risk-informed visibility of ARPC’s cyber security posture.
The position provides strategic direction and practical leadership to protect ARPC’s information assets and maintain compliance with Government and organisational standards. The role also carries responsibility as ARPC’s Information Security Adviser under the Protective Security Policy Framework (PSPF) for Government.
Key responsibilities
Board Reporting and Advisory
- Prepare, write, and present high-quality cyber security papers and reports to the ARPC Board and Risk Committee supporting the COO, providing clear, risk-informed insights into ARPC’s cyber posture, key risks, and investment priorities.
- Advise the Board and Committees supporting the COO on emerging threats, compliance obligations, and strategic priorities to support effective oversight and decision-making.
- Ensure Board reporting is integrated with executive risk management processes and aligned to ARPC’s enterprise governance frameworks.
Leadership and Management
- Team Leadership: Provide clear direction, coaching, and support to internal team members, fostering a high-performance culture and continuous capability uplift in cybersecurity awareness and technical proficiency.
- Partner Management: Oversee relationships with external cybersecurity partners, including managed service providers, ensuring service delivery meets agreed standards, contractual obligations, and ARPC’s security requirements.
- Role model ARPC’s Values and Code of Conduct and Capabilities set out in ARPC’s Capability Framework.
Strategic Oversight
- Lead and continuously evolve ARPC’s Information Security Strategy, ensuring alignment between strategic intent and operational execution.
- Own ARPC’s Information Security Policy and Strategy, providing direction and oversight for their effective implementation across the enterprise in partnership with the Technology Team.
- Ensure ongoing compliance with the PSPF, Information Security Manual (ISM), Essential Eight, Privacy Act, and other applicable legislative and policy frameworks.
- Oversee governance and management of emerging security risks including those related to artificial intelligence, cloud services, and third-party environments ensuring alignment with government and industry best practice standards.
- Prepare and present high-quality papers and reports to the Board and Risk Committee, delivering clear insights on ARPC’s cyber posture, key risks, and investment priorities.
- Maintain and continuously improve the Information and Cyber Security Risk and Control Library, ensuring accuracy, traceability, and alignment with ARPC’s enterprise risk management framework.
- Lead cyber risk management, assurance, logging and incident response activities to maintain cyber exposure within approved risk appetite.
- Define, implement, and monitor data loss prevention and protection controls in close partnership with the Technology Team.
- Establish, govern, and monitor Zero Trust Network Access (ZTNA) and Security Platform (e.g. EDR/XDR) policies, ensuring compliance, operational effectiveness, and continuous improvement
Organisational Awareness & Training
- Lead the design and delivery of ARPC’s enterprise-wide security awareness and training program, building a strong security culture across all levels of the organisation.
- Oversee implementation of ongoing education initiatives — including phishing simulations, targeted learning campaigns, and behavioural reinforcement — to strengthen cyber resilience.
- Ensure all employees understand and fulfil their security responsibilities, particularly regarding safe use of AI tools, information classification, and secure data handling practices.
- Embed security awareness into onboarding, learning programs, and continuous capability development
- Rationalise and optimise security tools, platforms, and licensing to reduce duplication and maximise value.
- Ensure all security investments are proportionate to ARPC’s risk profile, deliver measurable risk reduction, and support business outcomes
Reporting & Visibility
- Maintain clear, data-driven dashboards and reports for executive and Board assurance, covering cyber risk, control effectiveness, and compliance status.
- Provide visibility into emerging areas such as AI-related security metrics, third-party risks, and Zero Trust maturity.
Owns vendor governance for security-specific providers, including:
- Own governance of all security-specific vendors and service providers, ensuring performance, compliance, and value-for-money outcomes.
- Oversee Managed SOC/SIEM services for 24/7 monitoring, detection, and escalation.
- Manage penetration testing, vulnerability management, and threat intelligence partners.
- Coordinate with providers of security awareness and training to ensure alignment with ARPC’s learning and resilience objectives.
#J-18808-Ljbffr
-
Head of Information Security
5 days ago
Sydney, Australia Fernway Full timeNewly Licenced Bank! - growing to full ADI Status - Own Information Security - Strategy, Policy, Systems, Vendors - Banking with purpose - An Australian first! Join this newly licenced bank as HO Information Security! Develop and execute a comprehensive information security capability to navigate rapid growth **The Role**: As Head of Information Security...
-
Information Security Manager
6 days ago
Council of the City of Sydney, Australia Rabobank Gruppe Full timeRabobank is the world’s leading specialist in food & agribusiness banking. One of our key strengths lies in our people who have a deep understanding of agriculture & are committed to adding long-term value for clients. Our commitment to our employees & clients is at the heart of everything we do.Rabobank’s Security & Control department, part of the...
-
Council of the City of Sydney, Australia Bank of America Full timeOverview Job Description: At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This...
-
▷ Urgent Search! Information Security Engineer
3 weeks ago
Council of the City of Sydney, Australia ING Group Full timeOverview At ING Australia, you will have the chance to build a career as unique as you are, with the global scale, support, inclusive culture, and technology to become the best version of you. Reporting to the Senior Tech Operations Manager this role supports the development of secure solutions by defining and enforcing information security requirements,...
-
Council of the City of Sydney, Australia Bank of America Full timeJob Description: At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day. One of the keys to driving Responsible Growth is being a great place to work for...
-
Head of Primary
4 weeks ago
Council of the City of Sydney, Australia Montessori School of Tokyo Full timeMontessori International College is seeking a Montessori qualified, experienced and dedicated Head of Primary, commencing Term 3 2025. The Head of Primary is responsible for setting the curriculum in line with educational requirements and the Montessori pedagogy. As a leader, the Head of Primary underpins the future success of the College through mentoring...
-
Senior Cyber Security Analyst
2 weeks ago
Council of the City of Sydney, Australia Reserve Bank of Australia Full time**Senior Cyber Security Analyst (Cyber Hunt and Incident Response Team)*** Play an important part shaping the future of our iconic Australian institution.* Hybrid work environment.* Permanent position.* Join a team focused on remaining at the forefront of technology.**About the Role**The Reserve Bank of Australia is hiring for a **Senior Cyber Security...
-
Immediate Start! Senior Manager
4 weeks ago
Council of the City of Sydney, Australia Macquarie Bank Limited Full timeSenior Manager - Data Security Information and Governance Our central Information Governance team plays a vital role in supporting Macquarie’s diverse groups to manage risks associated with data retention, data sovereignty, and information security. Our team is responsible for maintaining an enterprise-wide framework and providing advice and tools to...
-
Security Architect
4 weeks ago
Council of the City of Sydney, Australia Standards Australia Limited. Full timeDesign and implement security solutions and controls to maintain and improve the information security posture for Standards Australia. About the role You will be responsible for planning, assessing, designing and implementing security solutions and controls to maintain and improve the information security posture for Standards Australia, ensuring...
-
Information Security Assurance Coordinator
3 days ago
City of Melbourne, Australia ClearCompany Full time- Join one of Australia's largest healthcare providers on a major digital platform - Collaborate within a multidisciplinary delivery stream of engineers and analysts - Security coordination, assurance and communication internally and externally By official title, this is a Security Operations Analyst position within a large-scale program modernising...