Regional Cybersecurity Risk Manager

3 days ago


Canberra, Australia KBR Full time

**Title**:
Regional Cybersecurity Risk Manager

**The Company**

From individual technologies and services to comprehensive project delivery and mission execution, no other company can match the breadth and depth of KBR. Our strength as an Australian company is demonstrated through more than 60 years of successful project and solution delivery.

Headquartered in Canberra, KBR comprises a diverse team who provide a broad spectrum of capabilities across Australia and the Asia Pacific. Our proven project teams readily address complex and multi-disciplinary activities, providing a low-risk and cost-effective service to our customers.

Our combined experience and expertise delivers the right solutions, technology and equipment at the right time.

**The Role**

The APAC Regional Cybersecurity Risk Manager is a key role responsible for the overall management and implementation of information security programs within KBR’s APAC operating locations. The APAC Cybersecurity Risk Manager ensures the confidentiality, integrity, and availability of the organization's information assets and protects against unauthorized access, disclosure, alteration, and destruction. The APAC Cybersecurity Risk Manager reports directly to the Chief Information Security Officer (CISO). This position is based in Australia. **Applicant must be eligible to obtain Australia Government Level Security Clearance.**

Key Responsibilities:
1. Information Security Strategy and Governance: Develop and implement regional information security strategy, in alignment with KBR corporate policy, regional regulations, business objectives and industry best practices. Establish and maintain regional information security policies, standards, and procedures. Collaborate with executive leadership and stakeholders to ensure security goals are integrated into business processes and decision-making.

2. Risk Management and Compliance: Conduct regular risk assessments to identify security vulnerabilities and threats, both internal and external. Develop and implement regional risk mitigation strategies and security controls to reduce identified risks. Monitor compliance with applicable laws, regulations, and contractual obligations related to information security.

3. Incident Response and Management: Conduct post-incident analysis to identify lessons learned and implement improvements to prevent future incidents.

4. Security Awareness and Training: Develop and deliver region-specific security awareness and training programs for employees, contractors, and third-party partners. Promote a culture of security consciousness and ensure employees understand their roles and responsibilities in protecting information assets. Stay updated with emerging security threats and educate stakeholders on security best practices.

5. Vendor and Third-Party Risk Management: Assess and manage security risks associated with third-party vendors and partners. Conduct due diligence on vendors' security practices and contractual obligations. Collaborate with procurement and legal teams to include appropriate security clauses in contracts and agreements.

6. Security Incident Reporting and Metrics: Develop and maintain security metrics and reporting mechanisms to monitor the effectiveness of security controls and identify areas for improvement. Regularly report to CISO, business leadership and stakeholders on the regional security posture, incidents, and key security metrics.

7. Security Audits and Assessments: Coordinate and participate in security audits and assessments conducted by internal or external parties. Address audit findings, implement corrective actions, and ensure ongoing compliance with audit requirements.

**Required Qualifications, Experience and Knowledge**
- Bachelor's degree in computer science, information systems, or a related field (advanced degree preferred).
- Must be eligible to attain Australia Government Level security clearance
- Extensive knowledge of information security principles, practices, technologies, and regulatory requirements.
- Proven experience in information security management, risk assessment, and incident response.
- Strong analytical and problem-solving skills.
- Excellent communication and interpersonal skills to effectively engage with stakeholders at all levels.
- Leadership abilities to drive security initiatives, influence decision-making, and foster a culture of security awareness.
- Up-to-date knowledge of emerging security threats and trends.
- Familiarity with security frameworks and standards such as ISO 27001, NIST Cybersecurity Framework. Must demonstrate understanding of Australia Essential 8 Maturity Model, Information Security Manual, and Australia Defense Information Security Program (DISP).
- Relevant certifications such as CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) or equivalent are desired.

**Benefits of KBR**

KBR is committed to supporting the profession



  • Canberra, ACT, Australia beBeeCybersecurity Full time $120,000 - $140,000

    Job Title: Cybersecurity Risk ManagerAbout the RoleThis is a highly specialized position that involves undertaking ICT security assessments of classified systems in accordance with internal requirements.Key Responsibilities:Conduct thorough assessments to evaluate the effectiveness of security controls for a system and its operating environment;Produce...


  • Canberra, ACT, Australia beBeeCybersecurity Full time $120,000 - $150,000

    Job TitleA seasoned professional with advanced knowledge of cybersecurity principles is sought after by an esteemed organization in Canberra to assume a pivotal role as Cybersecurity Risk Consultant.Key ResponsibilitiesAssume a key role in building and maintaining technical expertise within the risk management team.Contribute towards formulating best...


  • Canberra, ACT, Australia It Alliance Australia Full time

    One of our Federal Government clients is looking for a Cybersecurity Risk Advisor in Canberra.We are seeking candidates with the following Skills/Experience:Building capacity and supporting staff development of relevant technical knowledge and skills within the TSRS section and Risk Assessment Branch.Contributing to the development of best practice...


  • Canberra, ACT, Australia IT Alliance Australia Full time

    One of our Federal Government clients is looking for a Cybersecurity Risk Advisor in Canberra.We are seeking candidates with the following Skills/Experience: Building capacity and supporting staff development of relevant technical knowledge and skills within the TSRS section and Risk Assessment Branch.Contributing to the development of best practice...


  • Canberra, ACT, Australia IT Alliance Australia Full time

    One of our Federal Government clients is looking for a Cybersecurity Risk Advisor in Canberra.We are seeking candidates with the following Skills/Experience:Building capacity and supporting staff development of relevant technical knowledge and skills within the TSRS section and Risk Assessment Branch.Contributing to the development of best practice...


  • Canberra, ACT, Australia IT Alliance Australia Full time

    One of our Federal Government clients is looking for a Cybersecurity Risk Advisor in Canberra.We are seeking candidates with the following Skills/Experience:- Building capacity and supporting staff development of relevant technical knowledge and skills within the TSRS section and Risk Assessment Branch.- Contributing to the development of best practice...


  • Canberra, ACT, Australia IT Alliance Australia Full time

    One of our Federal Government clients is looking for a Cybersecurity Risk Advisor in Canberra.We are seeking candidates with the following Skills/Experience:Building capacity and supporting staff development of relevant technical knowledge and skills within the TSRS section and Risk Assessment Branch.Contributing to the development of best practice...


  • Canberra, Australia Cisco Systems Full time

    As a leader in the cloud, data, and mobile solutions, security is more important than ever before. It’s also our customers number one concern. Through the Internet of Things (IOT), we connect billions of devices around the globe and that means delivering complex security solutions for todays connected world. We're driving groundbreaking technologies that...


  • Canberra, ACT, Australia beBeeCybersecurity Full time

    Secure the Future of Our Nation's CybersecurityAbout the RoleWe are seeking a highly skilled and experienced Cybersecurity Operations Lead to join our team in Canberra, Sydney, and Melbourne. As a key member of our cybersecurity team, you will play a critical role in ensuring the security and integrity of our government clients' ICT systems.Key...


  • Canberra, ACT, Australia beBeeCybersecurity Full time $100,000 - $133,333

    Cybersecurity Outreach and Capability OfficerOur organization requires a skilled professional to play a key part in helping us meet our cybersecurity obligations and drive behavioral change across the organization. The Cybersecurity Outreach and Capability Officer will be responsible for identifying and mitigating potential cybersecurity risks, developing...