Information Security Risk Governance Specialist

3 weeks ago


Sydney, New South Wales, Australia Cuscal Limited Full time
Overview

Cuscal Limited is a pioneering leader in the Australian payments sector, empowering innovation and growth through cutting-edge technology.

About the Role

We are seeking an experienced Information Security Risk Governance Specialist to join our Group Risk and Compliance Team. Reporting directly to the Head of Operational Risk and Compliance, you will play a vital role in ensuring the effective identification, assessment, management, and monitoring of information security and data risks across Cuscal.

Key Responsibilities
  • Technology Risk Management Framework Advisory, Oversight and Monitoring:
    • Ensure that information security risks (technology and cyber) and data risks are adequately managed through Cuscal's frameworks in line with regulatory requirements, industry best practices, and operating environment, as per the three lines of defence model.
    • Develop and sustain second-line risk management capability to review, challenge, oversight, and assurance, reinforcing and maturing first-line accountability with business owners.
    • Collaborate with Product domains, Engineering, and corporate functions to embed technology risk management practices into everyday activities, implement controls, and monitor/report on issues.
    • Foster a risk culture that promotes open communication, transparency, and ownership of risk at all levels of the organization.
    • Risk Reporting & Analytics: Provide insights derived from technology and data risk reporting to the Board and Executive Leadership Team.
  • 2nd Line Review, Challenge and Oversight:
    • Review and challenge risk/RiC assessments, adequacy, and effectiveness of risk mitigation strategies, controls, and action plans implemented by first-line teams.
    • Critically assess incidents, breaches, and near misses to identify systemic issues and recommend appropriate remediation actions.
    • Ensure the continuous improvement of risk management practices by engaging with business units to provide constructive feedback and challenge assumptions.
    • Act as a trusted advisor to senior leadership and business units on operational risk matters, including emerging risks, regulatory changes, and industry trends.
    • Drive education and training programs to elevate operational risk awareness and capabilities across the organization.
    • Collaborate with product, client, and technology teams to ensure operational risk considerations are integrated into new initiatives, system changes, and major projects.
    • Second-line support for assessments of third-party technology risks and controls.
  • Emerging Risks and Innovation:
    • Stay informed about the latest developments in AI and other emerging technologies to proactively identify potential risks.
    • Support Cuscal teams in rapidly adopting new technologies in a safe and controlled manner.
    • Promote a culture of innovation in risk management practices, encouraging the adoption of new approaches and technologies.
  • Stakeholder Engagement:
    • Work closely with internal and external stakeholders as required to ensure a cohesive approach to technology risk management.
    • Develop and deliver training programs to enhance technology risk awareness and competency across Cuscal.
    • Promote and drive a positive risk culture to lift overall risk management maturity across Cuscal.
About You

To be successful in this position, you will possess the following skills and experience:

  • Bachelor's degree in information technology, Information Systems, Risk Management, Cybersecurity, Computer Engineering, or a related field. Relevant certifications (e.g., CRISC, CISA, CISSP) are desirable.
  • Minimum of 4-6 years of experience in technology risk management within the financial services industry.
  • Strong knowledge of risk management and IT frameworks and standards such as ITIL, ISO 27001, NIST, COBIT, and relevant APRA guidelines (CPS234, CPG235, CPS230, CPS220).
  • Demonstrated experience in managing risks associated with AI, machine learning, and other emerging technologies.
  • Prior experiencing leading risk maturity uplift at another organisation within a function, business unit or risk class.
  • Strong project management skills, including planning, execution, and stakeholder management.
Benefits

Cuscal offers a competitive salary range of $120,000 - $180,000 per annum, commensurate with experience, plus a wide range of financial, lifestyle, health & wellbeing benefits. We are committed to providing a diverse and inclusive workplace where the very best talent in Australia chooses to work. Flexible work arrangements are available through our hybrid model, supporting employees in achieving a better work-life balance.

Cuscal does not accept unsolicited resumes from recruitment agencies and search firms. Please do not email or send unsolicited resumes to any Cuscal employee, location or address.



  • Sydney, New South Wales, Australia HCF Australia Full time

    Overview:">This role plays a critical part in ensuring the operational excellence of IT services at HCF Australia. It focuses on performing IT governance and compliance to guarantee that services are aligned with regulatory and organisational requirements.">About the Role:">We are seeking an experienced Information Security Governance Specialist to join our...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time

    About the RoleWe are seeking an experienced Information Security Risk Manager to join our team at Pyramid Global Technologies. This role requires a minimum of 10 years of experience in cyber security roles within major organizations, focusing on management of governance, risk, and compliance.Key ResponsibilitiesSUPPORT THE DELIVERY AND CONTINUOUS IMPROVEMENT...


  • Sydney, New South Wales, Australia Local Peoples Full time

    We are seeking an experienced Cyber Security Risk Specialist to join our team in the Australian Capital Territory (ACT), Queensland (QLD), South Australia (SA), or Victoria (VIC). This role will involve working with government agencies to assess and mitigate cyber security risks.The ideal candidate will have extensive experience with risk and information...


  • Sydney, New South Wales, Australia Local Peoples Full time

    Senior Cyber Security Analyst PositionWe are seeking an experienced Senior Cyber Security Analyst to join our team in the ACT, QLD, SA, and VIC.The successful candidate will work within the Integrated Cyber Risk Management section, undertaking cyber risk assessments of key technology components and systems. A strong understanding of cyber security controls...


  • Sydney, New South Wales, Australia EFinancialCareers Ltd. Full time

    At EFinancialCareers Ltd., we are seeking a highly skilled Information Security Risk Manager to lead our IT risk functions across the AUSPAC division and into QBE Global Technology Risk. This is a permanent, full-time opportunity based in Sydney, Australia.About the RoleThis role reports to the General Manager, Technology Strategy and Governance, and...


  • Sydney, New South Wales, Australia KPMGau Full time

    About KPMGauKPMGau is a global network of professional services firms that provide audit, tax, and advisory services to help clients overcome challenges and achieve their goals.Our Technology and Information Risk Management team is a dynamic and rapidly growing team that supports business stakeholders in bringing their ideas to life while helping them shape...

  • IT Security Manager

    4 weeks ago


    Sydney, New South Wales, Australia Employers Mutual Management Pty Ltd Full time

    Employers Mutual Management Pty Ltd is a leading Workers Compensation and Personal Injury Claims Management business.We foster a culture that allows for ongoing investment in our employees, ensuring a long-term career at EML. Our diverse team based in Sydney aims to make a positive impact on people's lives every day.As a Cyber & Information Security Manager...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time

    About Pyramid Global TechnologiesEstimated salary: $250,000 - $300,000 per year.Job OverviewThis role plays a critical part in the success of our organization's Information Security Management System (ISMS).We are seeking an experienced Information Security Risk Management Lead to join our team. The ideal candidate will have a minimum of 10 years of...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time

    About Pyramid Global TechnologiesSalary: $120,000 - $180,000 per yearJob Description:We are seeking a seasoned Cyber Security Specialist to lead our information security management system and drive risk mitigation initiatives.The ideal candidate will have at least 10 years of experience in cyber security roles within major organizations, focusing on...


  • Sydney, New South Wales, Australia Ethos BeathChapman Full time

    About the RoleEthos BeathChapman is seeking an experienced Information Security Risk Manager to join our team. This is a challenging opportunity for a professional with expertise in information security and risk management to make a significant impact in the financial services industry.Job DescriptionThe successful candidate will have responsibility for...


  • Sydney, New South Wales, Australia Tal Services Limited Full time

    About TAL Services LimitedTAL Services Limited is a leading provider of risk management solutions, committed to fostering an inclusive and equitable culture for all its people. We value diversity in all its forms and strive to create a work environment that promotes equality and respect.Our mission is to provide innovative risk management solutions that meet...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time

    About the RoleEstimated Salary: AU$250,000 - AU$350,000 per annum.Job Description:PYRAMID GLOBAL TECHNOLOGIES is seeking an experienced Cyber Security Specialist to join our team. The successful candidate will be responsible for managing our Information Security Management System (ISMS) and ensuring that cyber security risks are appropriately managed.Key...


  • Sydney, New South Wales, Australia KPMGau Full time

    Job OverviewKPMG, a leading professional services firm, is seeking an experienced Information Security Risk Management Specialist to join our team.About KPMGKPMG is a global organization with a strong presence in the industry. We offer a collaborative and dynamic work environment that fosters growth and development.Key ResponsibilitiesEvaluate technology...


  • Sydney, New South Wales, Australia Comcare Full time

    Job SummaryWe are seeking a highly skilled Cyber Security Assurance Specialist to join our Technology and Information Management Team at Comcare. As a key member of the team, you will play a crucial role in delivering ICT outcomes specifically within the fields of Cyber Security Operations while supporting the Governance, Risk and Compliance (GRC)...


  • Sydney, New South Wales, Australia Cuscal Limited Full time

    Lead Cyber Governance and Risk Management RoleWe are seeking a highly experienced Senior Manager, Cyber Governance, Risk & Assurance to join our dynamic IT Security team at Cuscal Limited.About the Role:This is a leadership position responsible for developing and executing the cyber governance, risk management, and assurance strategy, ensuring alignment with...


  • Sydney, New South Wales, Australia Raytheon Technologies Full time

    At Raytheon Australia, we are a trusted capability partner of the Australian Defence Force, providing engineering and technology solutions that protect and secure our nation.A key role is now available for a Chief Security Governance Specialist who wants to contribute to something big. We draw the brightest minds and give them work that excites them while...


  • Sydney, New South Wales, Australia HiTech Group Full time

    Cyber Security Risk Analyst Job DescriptionEstimated Salary: $120,000 - $150,000 per annum.About HiTech GroupA leading Federal Government department is seeking an experienced Cyber Security Risk Analyst to join a highly multidisciplinary team. The successful candidate will be responsible for identifying key security risks in the ICT environment and ensuring...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time

    About the role: Information Security Specialist at Pyramid Global TechnologiesEstimated Salary: AU$90,000 - AU$120,000 per annum (dependent on experience)Job Description:We are seeking an experienced Information Security Specialist to join our team in Sydney. As a key member of our IT department, you will be responsible for ensuring the security and...


  • Sydney, New South Wales, Australia Cuscal Limited Full time

    About the JobThis is a highly visible role that requires expertise in technology risk management, particularly in the financial services sector. As an Information Security Risk Management Lead, you will work closely with the Head of Operational Risk and Compliance to develop and implement technology risk management strategies that align with regulatory...


  • Sydney, New South Wales, Australia 023 Northern Trust Company Australia Full time

    Job SummaryWe are seeking a highly skilled and detail-oriented Senior Data Governance Associate to join our Asset Servicing Data Governance Team at 023 Northern Trust Company Australia.About the RoleThe ideal candidate will have strong analytical skills, knowledge of data governance, and a desire to grow their expertise in a collaborative environment. Key...