Head of Security Advisory

1 week ago


Sydney, Australia Australian Prudential Regulation Authority (APRA) Full time

**The role**

The Head of Security Advisory and Engagement is a pivotal senior leadership role focused on positioning security as a business enabler through proactive customer engagement.

This role is responsible for consolidating all security initiatives, ensuring integration and dependency management, and leading internal customer security efforts. The incumbent will oversee security risk assessments, assurance management, and the close integration of security controls throughout the project and business-as-usual (BAU) lifecycles.

**The team**

The Security team sits within the Data, Technology and Security (DTS) division and with a new CISO recently started, the team is going through uplift. The Security team manages cyber, information and personnel security aligning with the Protective Security Policy Framework (PSPF). The team works in a highly collaborative manner with a wide range of stakeholders at all levels of the organisation to develop, communicate and implement the security strategy and governance arrangements.

**Key responsibilities**
- Customer Facing Engagement: Lead internal customer engagements with a focus on demonstrating security as a business enabler and business value alongside government security requirements (PSPF, Essential 8 and ISM)
- Customer Security Risk Assessments: Conduct and manage internal customer security risk assessments (across the spectrum of physical, personnel and cyber/information security) to identify and mitigate potential threats. Collaborate with Security Strategy, Governance & Privacy team to ensure risks are documented, tracked and reported
- Assurance Management: Develop and manage the security controls framework, assurance framework and lead assurance activities (e.g. IRAP assessments, penetration testing) to validate the effectiveness of security controls and ensure integration into secure by design lifecycle. Work closely with other security heads on reporting and tracking completion
- Security Culture and Awareness: Lead the development and execution of an engaging and comprehensive plan for security cultural change and awareness improvements. Ensure cohesive cultural change and communications are incorporated across all business projects and BAU activities
- High Performing Team: Work with the CISO, Executive Director of Technology & Data, CDO, CIO and Senior Manager peers to build a cohesive and collaborative high performing leadership and teams.

**About you**

Technical Skills:

- In-depth knowledge of Australian government security frameworks, standards, and best practices (i.e. PSPF, ISM and Essential 8)
- Proficiency in security risk assessment and management tools
- Proficiency in assurance activities such as penetration testing and compliance frameworks (e.g., IRAP, third party assurance)
- Strong understanding of security controls and Secure by Design principles.

Soft Skills:

- Excellent leadership and team management abilities. Consultative, collaborative and a proactive team player
- Strong analytical and problem-solving skills
- Ability to think strategically and make clear and immediate data-driven decisions
- Exceptional stakeholder engagement and relationship skills, highly adept in managing a diverse group of senior stakeholders and relationships
- Highly developed executive communication, leadership, negotiation, conflict resolution and interpersonal skills and the ability to represent APRA’s view in a highly professional and sensitive manner. The ability to translate complex technical issues into plain language
- Sees security as a business enabler with a strong ability to take a risk-based approach to security requirements.

To work with us, you need to be an Australian citizen with eligibility to gain NV1 security clearance.

**About APRA**

The Australian Prudential Regulation Authority (APRA) places you at the heart of Australia’s financial services industry. APRA serves the Australian community by helping ensure financial institutions deliver on the financial commitments they make, within a stable, efficient and competitive financial system.

At APRA we’re committed to providing an inclusive workplace where everyone belongs, feels valued and respected. We aspire to attract and foster diversity of background, thought, and experience, recognising that a broad range of perspectives, approaches and ideas makes us stronger, and better enables us to meet our obligation to protect the financial wellbeing of the Australian community. When applying, please inform us of any adjustments you may need during the interview process.



  • Sydney, New South Wales, Australia Australian Prudential Regulation Authority (Apra) Full time

    **The role**The Head of Security Advisory and Engagement is a pivotal senior leadership role focused on positioning security as a business enabler through proactive customer engagement.This role is responsible for consolidating all security initiatives, ensuring integration and dependency management, and leading internal customer security efforts. The...


  • Sydney, Australia iCare External Full time

    **Head of Cyber Strategy & Advisory** - **Sydney** Accountable the continuous improvement and delivery of cyber and information security strategy and advisory services. - Responsible for alignment of cyber & information security strategy to business objectives - 10 yrs’ experience in comparative organisations & support to achieve ISO27001 certification. -...

  • Cyber Advisory

    3 weeks ago


    Sydney, New South Wales, Australia Scyne Advisory Full time

    Cyber Advisory (Data & AI Governance) - Senior ManagerJoin to apply for the Cyber Advisory (Data & AI Governance) - Senior Manager role at Scyne AdvisoryCyber Advisory (Data & AI Governance) - Senior Manager2 days ago Be among the first 25 applicantsJoin to apply for the Cyber Advisory (Data & AI Governance) - Senior Manager role at Scyne AdvisoryGet...


  • Sydney, Australia Bank of Queensland Full time

    **About the Role** Join BOQ Group’s Risk division as our **Head of Compliance Advisory**, providing 12-month maternity leave coverage in a pivotal leadership role. This is a hands-on position where you'll be expected to roll up your sleeves and get involved in the detail, guiding business units with timely, risk-based regulatory advice and fostering a...


  • Sydney, New South Wales, Australia Buscojobs Full time

    Join to apply for the Head of Compliance Advisory role at BOQ Group Join to apply for the Head of Compliance Advisory role at BOQ Group Get AI-powered advice on this job and more exclusive features.About The Role Join BOQ Group's Risk division as our About The Role Join BOQ Group's Risk division as our Head of Compliance Advisory , providing 12-month...

  • Head Of Risk Advisory

    2 weeks ago


    Sydney, New South Wales, Australia Mlc Life Insurance Full time

    MLC Life Insurance. We have been protecting Australians for over 130 years. We respect the role we play in providing peace of mind for our customers, and we never lose sight of it.**Our Purpose**MLC Life Insurance is one of Australia's leading life insurance specialists and a member of the Nippon Life Insurance Group, one of the world's leading insurers. We...

  • Head Of Security

    3 weeks ago


    Sydney, New South Wales, Australia North Star Partners Full time

    This range is provided by North Star Partners.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.Base pay range A$200,000.00/yr - A$220,000.00/yr Direct message the job poster from North Star Partners Partner & Co-Founder@North Star Partners - Community builder - All things Cybersecurity - Connecting the...


  • Sydney, Australia ING Full time

    We are looking for an enthusiastic **Cloud Security Advisory Specialist **to join our Information security team based in Sydney. The Information Security team provides security capabilities and consultancy that enable the entire organisation to be successful in a safe and secure way. This is a **newly created role** reporting to the Information Security...


  • Sydney, New South Wales, Australia Decipher Bureau Full time

    Company:We're working with a highly regarded Australian enterprise that's renowned for its collaborative, innovative, and high-performance culture.Role:As Cyber Security Advisory Lead, you'll lead a high-performing team, shaping AWS and Azure security at enterprise scale. This is a technical leadership role, perfect for someone who can go deep into security...


  • Sydney, Australia ING Full time

    Maintaining security and being risk adverse are at the top of our priorities here at **ING**! Exciting opportunity to support with the implementation of the **ING Cybersecurity Strategy** and ensuring compliance to **Local and Global Regulatory standards** for these **two newly created positions**. You’ll have the opportunity to work across various...