Technology Risk and Complaince Manager

2 days ago


Melbourne, Australia McMillan Shakespeare Full time

The McMillan Shakespeare Group (MMS) is a trusted provider of salary packaging, novated leasing, disability plan management and support co-ordination, asset management and related financial products and services. From our origins in 1988 when we created Australia’s salary packaging industry to today, MMS has a proud history of innovation and exceptional service.

Through our subsidiaries, we offer a breadth of services and expertise designed to responsibly deliver superior long-term value to our clients and customers, which include Federal and State governments and some of the largest public and private sector, health and charitable organisations.

The Manager Technology Risk & Compliance role can be done from Adelaide, Brisbane, Melbourne or Sydney and is a paternity cover for 6 months full time that may extend to one year.

MMS has a number of compliance obligations imposed by the regulatory and contractual environment in which we operate. The manager technology risk and compliance is to lead the analysis monitoring and strict compliance to internal, audit and contractual policies and controls in relation to the delivery of governance over digital and traditional on-premise services. A key component of the role is education and awareness ensuring staff and 3rd parties are abreast of the requirements in order to meet this compliance.

The Manager Technology Risk & Compliance is responsible for direct control of security owned controls and compliance obligations in addition to stakeholder management and leading oversight governance of first line of defense teams and their roles in monitoring, analysing, executing security governance controls. The manager must develop a strong working relationship with IT functional teams and business stakeholders to ensure baseline security requirements are met and assets remain protected within these functional areas and escalated where non-compliance exists.

The Manager Technology Risk & Compliance is also responsible for keeping abreast of legislative, compliance and security industry changes as they relate to MMS business whilst developing, maintaining and reporting risk management frameworks that aim to protect the confidentiality,

availability and integrity of group assets including data.

The Role:

- Map existing contracts against security standards identifying potential gaps in compliance and for input into the information security policy and standards
- Manage and lead internal and external audits end to end being the technology authoritative source and focal point whilst ensuring relevant artefacts are sourced and provided in a timely manner
- Evaluate cyber-security standards including NIST, ASD Essential 8, ISO27000 and PCI DSS for alignment with internal frameworks
- Ensure internal security standards, policy, audit and contracted security requirements are communicated across the business and with 3rd Parties
- Ensure 3rd parties comply with all relevant due diligence obligations and provide regular attestations
- Manage the cyber-security education, training and awareness program and educate employees in security best practices
- Periodically conduct security reviews and workshops to report business effectiveness in meeting documented standards, controls and compliance to contractual or policy objectives
- Lead, steer and oversee the Information, Communication and Technology Risk management framework
- Conduct regular risk assessments and workshops to ensure risks to the organisation are assessed and understood, and are fed back to stakeholders to ensure the continued effectiveness of the risk management strategy
- Manage and improve the risk posture, contribute and evaluate solutions for remediating or mitigating risks and assess residual risks
- Work with all stakeholders to educate and identify controls and compliance requirements that are applicable
- Undertake contract and 3rd party security reviews providing guidance, checklists to support business risk decisions
- Generate security metrics and provide regular reports on security compliance performance to technology management and risk and audit committees
- Lead and prepare Crisis management testing and response exercises and relevant reporting
- Respond to information security incidents
- Lead, maintain and develop incident response processes and procedures when new threats to the organisation arise
- Be an active participant in incident management to support controlled and coordinated responses
- Develop security policy, standards and develop processes and procedures for evaluation and exemption where required.
- When necessary, prepare Post Incident Reviews
- Any other security risk and compliance initiatives, as requested.

You will bring:

- 5-10 years experience in IT Security and Risk Management
- Experience with legal and regulatory obligations such as the Australian Privacy Principles.
- Supply chain risk management and assesments including 3rd party security risk assessments
- Experience



  • Melbourne, Victoria, Australia Bupa Australia Full time

    OverviewJoin to apply for the Manager - Technology Risk role at Bupa Australia.This permanent, hybrid role (Melbourne) reports to the Head of Risk & Enablement APAC and involves embedding risk management frameworks across technology teams, driving governance, and ensuring alignment with Bupa's Risk Management Strategy.ResponsibilitiesPartner with the...


  • Melbourne, Australia Bupaoptical Full time

    At Bupa, our purpose is to help people live longer, healthier, happier lives and making a better world. This is at the core of who we are, making us a healthcare provider that strives to deliver meaningful change, contributing to our ambition to be the world’s most customer-centric healthcare company. Opportunity Snapshot Join Bupa as a Digital & Health...


  • Melbourne, Australia Bupa Full time

    At Bupa, our purpose is to help people live longer, healthier, happier lives and making a better world. This is at the core of who we are, making us a healthcare provider that strives to deliver meaningful change. contributing to our ambition to be the world’s most customer-centric healthcare company. **Opportunity Snapshot** Join Bupa as a Digital &...


  • Melbourne, Victoria, Australia Bupa Full time $120,000 - $180,000 per year

    At Bupa, our purpose is to help people live longer, healthier, happier lives and making a better world. This is at the core of who we are, making us a healthcare provider that strives to deliver meaningful change. contributing to our ambition to be the world's most customer-centric healthcare company.Opportunity SnapshotJoin Bupa as a Digital & Health...


  • Melbourne, Victoria, Australia Bupa Australia Full time $120,000 - $180,000 per year

    At Bupa, our purpose is to help people live longer, healthier, happier lives and making a better world. This is at the core of who we are, making us a healthcare provider that strives to deliver meaningful change. contributing to our ambition to be the world's most customer-centric healthcare company.Opportunity SnapshotJoin Bupa as a Digital & Health...


  • Melbourne, Australia Bluefin Resources Full time

    **The Company** You will join a leading Australian financial services organisation that puts its customers first and prides itself on the diversity of people. **A day in the Life of a Technology Risk Manager - Cloud** This second-line role is responsible for reviewing how well the organisation is adhering to the risk management framework, policies and...


  • Melbourne, Australia ANZ Banking Group Full time

    **Req ID**: 78626 **Department**: Risk Technology Risk **Division**: Risk **Location**: Melbourne About Us At ANZ, we're shaping a world where people and communities thrive, driven by a common goal: to improve the financial wellbeing and sustainability of our millions of customers. About the Role Join an innovative, vibrant team of technology risk...


  • Melbourne, Australia Grant Thornton Australia Full time

    9-day fortnight with no salary reduction - Permanent, full-time opportunity - Work alongside collaborative leaders and industry experts Grant Thornton Australia is one of the world's leading independently-owned and managed accounting, advisory and consulting firms. Our culture is underpinned by a commitment to our clients, people and communities, and our...


  • Melbourne, Australia Cbus Full time

    Manager - Technology and Data Risk **About Cbus** Created by workers, for workers, Cbus Super is one of Australia's most successful Superannuation funds. For almost four decades we've proudly represented those who help shape Australia, hard-working individuals who deserve to make the most of their retirement, no matter the industry. As an award-winning fund...


  • Melbourne, Victoria, Australia AustralianSuper Full time $120,000 - $180,000 per year

    At AustralianSuper, we truly care about our colleagues. We know work and life are intertwined. That's why we support the diverse needs of everyone and have policies that enable us all to thrive and be truly flexible. We ensure diversity is celebrated for the opportunity it provides us all to learn and grow and deliver better outcomes for members.Your New...