IT Controls, Risk

5 days ago


Sydney, Australia Australian Prudential Regulation Authority (APRA) Full time

**The role**

The IT Controls, Risk & Audit Assurance Manager leads the oversight, development, and execution of organization-level IT control frameworks, risk assurance, and audit engagement activities. Operating independently, the role is responsible for ensuring that IT operations, projects, and systems meet internal control standards, regulatory expectations, and audit readiness across all technology domains.

The incumbent serves as the central point of coordination and escalation for all IT-related assurance matters and will actively engage with IT, second-line Risk/Compliance, and third line Internal/External Audit functions.

**The team**

IT Controls, Risk and Audit Assurance Manager, reporting to the Head of IT Governance in DTS (Data, Technology & Security) Department, is part of the IT Governance team. This team collaborates with stakeholders across the organisation to establish process and policies for managing IT, ensuring alignment between technology and business, with focus on managing risks and compliance with frameworks.

Key stakeholders include the CIO, CTO, Architecture, Enterprise Security, and Product delivery teams, along with the Chief Information Security Officer, Chief Data Officer, Chief Risk Officer, and Project Management Office.

**Key Responsibilities**

- End-to-end ownership of IT-related audits (internal/external/regulatory); issues addressed with validated evidence and sustained resolution.

- Create a detailed RCM process and perform periodic RCMs, control testing, and deep dives performed across IT domains with stakeholder engagement and risk-informed actions.

- Ensure all IT compliance obligations (e.g., PSPF, ISM) are mapped to controls; periodic assurance performed with documented evidence and reporting.

- Ensure all policies and processes are in place, up to date, accurate and regularly reviewed.

- Ensure regular and timely production of executive-level dashboards (e.g., audit status, risk posture, control effectiveness), used in governance forums.

- Perform Root cause analysis and ensure remediation plans for control gaps are defined, tracked, and independently validated.

- Be an active contributor to Risk and Audit Committees; trusted advisor to senior IT leadership.

- Supports or leads configuration and operation of Governance, Risk, and Compliance platforms.

- Oversee the assessment and management of risks associated with third-party vendors and service providers including FOCI risks, ensuring they meet the organization's IT control standards and compliance requirements.

- Lead and drive continuous improvement initiatives within the IT control and audit processes to enhance efficiency and effectiveness.

- Perform an advisory role in new system designs, major IT projects, and transformation initiatives to embed ‘right-first-time’ controls.

- Develop and deliver training and awareness programs to ensure that all relevant stakeholders are knowledgeable about IT control frameworks, risk management practices, and audit requirements.

- Maintain regular communication with key stakeholders, providing updates on IT control, risk, and audit activities, and ensuring alignment with business objectives and driving a risk aware culture

**About you**

- Extensive experience in IT audit, technology risk management, IT control assurance, including direct leadership roles.

- Strong background in regulated environments, particularly banking, insurance, or capital markets.

- Proven record of leading audit and regulatory engagements (e.g., PSPF, ISM, NIST etc.).

- Experience building and managing enterprise-wide control frameworks and assurance programs across hybrid IT environments.

- Desirable Professional Certification - CISA, CISM, CRISC or equivalent

**To work with us, you must be an Australian citizen with eligibility to gain a NV1 clearance through the Australian Government Security Vetting Agency.**

**About APRA**

Australian Prudential Regulation Authority (APRA) was established in 1998 as an independent statutory authority that supervises almost 1,200 financial institutions that manage $8.6 trillion in assets for Australians across the banking, insurance and superannuation sectors.
In overseeing the safety, competitiveness and stability of the financial system, we seek to recruit, develop and retain highly skilled professionals, who want to help shape financial services and protect the financial wellbeing of the Australian community. Our employee base of almost 900 come predominantly from the commercial financial services industry or other government agencies; as such, we have the feel of a small corporate organisation that can work flexibly and with agility.

**Why Work for APRA**

We recognise the skills, experience and commitment that our staff bring to their professional lives, and we seek to reward them accordingly. We also recognise that for our staff to be able to perform at their best, we need to ensure that they are able to bring their best selve



  • Sydney, New South Wales, Australia Commonwealth Bank - Risk Management Full time $120,000 - $180,000 per year

    You are passionate about Financial CrimeBe part of a high performing team with a collaborative cultureClear career growth and development pathwaysSee yourself in our team The Business Banking (BB) Financial Crime Risk and Control team sits within BB Central Control Office (CCO). The BB Financial Crime Risk and Control (BB FC CCO) team is responsible for...


  • Sydney, New South Wales, Australia Commonwealth Bank - Risk Management Full time $104,000 - $130,878 per year

    Join a purpose-driven team supporting Institutional Banking & Markets (IB&M), including Global Economic and Markets Research and CommBank IQ. We focus on embedding strong risk practices that enable business outcomes while protecting customers and the organisation.Do work that matters Institutional Banking and Markets (IB&M) manages relationships with major...

  • IT Controls, Risk

    5 days ago


    Sydney, New South Wales, Australia Australian Prudential Regulation Authority (APRA) Full time $120,000 - $180,000 per year

    The roleThe IT Controls, Risk & Audit Assurance Manager leads the oversight, development, and execution of organization-level IT control frameworks, risk assurance, and audit engagement activities. Operating independently, the role is responsible for ensuring that IT operations, projects, and systems meet internal control standards, regulatory expectations,...


  • Sydney, Australia AMP Full time

    Risk & Controls Analyst If you live in Australia or New Zealand, you've likely heard of AMP. But at a time when society is changing, we are too. We're now a nimbler business with new leadership and thinking. For us, these are exciting times. There's a real potential for big thinkers to help us redefine what financial services could be. And turn our legacy...


  • Sydney, New South Wales, Australia TP ICAP Full time $90,000 - $120,000 per year

    Group Overview:The TP ICAP Group is a world leading provider of market infrastructure.Our purpose is to provide clients with access to global financial and commodities markets, improving price discovery, liquidity, and distribution of data, through responsible and innovative solutions.Through our people and technology, we connect clients to superior...


  • Sydney, Australia Commonwealth Bank of Australia Full time

    Manager Risk and Controls - **You are passionate about Financial Crime**: - **Be part of a high performing team with a collaborative culture**: - **Clear career growth and development pathways** **See yourself in our team** The Business Banking (BB) Financial Crime Risk and Control team sits within BB Central Control Office (CCO). The BB Financial Crime...


  • Sydney, Australia NSW Government -icare Full time

    **Open to all icare offices** - **Can work in Parramatta, Sydney-CBD, Newcastle, Gosford or Wollongong**: - **Permanent full-time **role managing and supporting Line 1 Risk activities**: - **Salary from $120** plus super, **hybrid/flexible working model **& company benefits** ***About the Role** This is a permanent full-time role, responsible for...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time $80,000 - $120,000 per year

    Opportunity to join an energetic, high performing team making real impact in Business Banking through applied risk management, with compliance and control development focusBusiness profile support for Relationship Managed Segments including close engagement with senior leaders across Business BankingA challenging and rewarding role that requires you to think...


  • Sydney, Australia The Star Entertainment Group Full time

    For two decades, The Star Sydney has been a local landmark, deeply ingrained in Pyrmont and Darling Harbour. Committed to our communities, we strive to create fun in trusted destinations as Australia's premier entertainment hub. The Darling, and state-of-the-art venues including The Star Event Centre and The Lyric Theatre have hosted prestigious events and...


  • Sydney, New South Wales, Australia Commonwealth Bank Full time $100,000 - $150,000 per year

    Opportunity to join an energetic, high performing team making real impact in Business Banking through applied risk management, with compliance and control development focusBusiness profile support for Relationship Managed Segments including close engagement with senior leaders across Business Banking A challenging and rewarding role that requires you to...