
Cyber Security Risk Manager
23 hours ago
**Job no**: 527962
**Work type**: full time
**Location**: Sydney, NSW
**Categories**: Information Technology, Cyber
- Employment Type: full time continuing role as a Cyber Security Risk Manager
- Excellent salary package including superannuation
- Location: UNSW Kensington Campus (Hybrid Working Opportunities)
**About UNSW**:
UNSW isn’t like other places you’ve worked. Yes, we’re a large organisation with a diverse and talented community, a community doing extraordinary things. Together, we are driven to be thoughtful, practical, and purposeful in all we do. Taking this combined approach is what makes our work matter. If you want a career where you can thrive, be challenged and do meaningful work, you’re in the right place.
The Cyber Security Risk Manager is responsible for providing strategic leadership in developing and continuously improving the University’s cyber security risk management practices, ensuring that risks are continually identified, assessed, prioritised, monitored, and mitigated in line with UNSW’s Enterprise Risk Management framework. Key responsibilities include managing cyber security risk registers, leading risk remediation efforts, and developing risk mitigation strategies with measurable key risk indicators (KRIs) and key performance indicators (KPIs). The role also oversees vendor security risk management and annual threat assessments, while delivering regular risk updates to senior leadership and governance forums. The Cyber Security Risk Manager reports to the Head of Cyber Security Governance & Assurance and has direct reports.
**Accountabilities**:
- Provide strategic leadership in the development, execution and continuous improvement of the cyber security risk management practices in alignment with UNSW’s Enterprise Risk Management framework.
- Manage Cyber Security Risk Registers, ensuring identified risks are documented, assessed, prioritised, and remediated.
- Lead and direct risk remediation efforts, ensuring timely closure of identified risks.
- Develop and implement effective risk mitigation strategies and ensure alignment with business goals.
- Develop key risk indicators (KRIs) and key performance indicators (KPIs) to measure and track the effectiveness of risk management strategies.
- Ensure new risks are promptly registered and managed following assessments, assurance activities, or security incidents.
- Ensure that the threat, risk and control libraries on the GRC platform are up to date.
- Lead the execution, and continuous improvement of the annual threat and risk assessment process, including maturity assessments
- Lead and deliver the end-to-end vendor security risk management lifecycle process, including annual risk assessments for high-risk vendors, periodic scorecard reviews, and continuous monitoring through platforms such as UpGuard, CyberGRX and BitSight.
- Oversee and deliver the security review process for Requests for Information (RFIs) and Requests for Proposals (RFPs), embedding contractual security requirements in vendor agreements.
- Design and optimise operational metrics to drive continuous improvement of the overall cyber security risk management practice, ensuring timely and accurate reporting through the metrics dashboard for inclusion in the quarterly Risk and Safety Committee submissions.
- Lead the development and delivery of quarterly cyber security risk updates and briefings to IT executives, business partners, and relevant stakeholders, providing detailed insights into risks and mitigation action status and trends.
- Lead and manage the Cyber Security Risk Working Group, fostering cross-functional collaboration and driving key security risk management initiatives.
- Monitor internal and external environments for emerging threats, vulnerabilities, and regulatory changes.
**Who you are**:
- Extensive experience (7+years) in cyber security risk management, with demonstrated experience in conducting risk assessments, managing risk registers, and overseeing vendor security risk management programs.
- Proven experience in developing, implementing and operationally running the cyber security risk management practice in large and complex organisations.
- Hands on experience with security tools and platforms for monitoring, managing, and reporting on cyber security risks such as Protecht GRC tool, CyberGRX, UpGuard, and BitSight is highly desirable.
- Certifications such as CISM, CISSP, CRISC, AWS Security Speciality, Azure Security or related certifications are highly desirable.
- Strong knowledge of cyber risk management principles, methodologies, frameworks, such as ISO 27001, ISO 31000, NIST 800-53, FAIR and other industry standards.
- Proven experience in managing vendor security risk and developing operational metrics for risk management.
- Strong project management skills with the ability to balance multiple initiatives and deadlines.
- Excellent communication, negotiation and interpersonal skills, with a proven ability t
-
Lead Cyber Security Consultant
1 week ago
Sydney, New South Wales, Australia Skylight Cyber Security Full time $120,000 - $180,000 per yearAbout Skylight CyberAt Skylight Cyber, we're young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are...
-
Cyber Security Consulting Team Lead
3 days ago
Sydney, Australia Vertex Cyber Security Full time**Core Duties**: The Cyber Security Consulting Team Lead manages the Consulting Team to deliver end-to-end cyber security consulting services, undertaking duties that include, but are not limited to: - Conducting comprehensive cyber security risk assessments and audits of client technical environments (cloud and on-premise) and policies and procedures,...
-
Head of Cyber Security and IT Risk
2 weeks ago
Sydney, Australia LGT Crestone Wealth Management Full timeMin Experience- 10 yearsYour team - Working as a part of the Risk, Legal & Compliance team with overall responsibility to drive all strategic and operational cyber security and IT risk functions. - Working alongside the Head of Technology, senior business and risk executives and project management team within the reporting structure of the Chief Risk...
-
Cyber Security Risk Assurance Lead
1 week ago
Sydney, New South Wales, Australia ALOIS Solutions Full time $150,000 - $250,000 per yearRole: Cyber Security Risk Assurance LeadWork location: Sydney , Melbourne, Canberra - Open for all locationsRole type: ContractRole:The Cyber Security Risk Assurance Lead is hands-on and multi disciplined, assessing complex technical issues and performing cyber security risk assessments across a wide range of initiatives in a fast-paced, complex...
-
Cyber Security Compliance
1 week ago
Sydney, Australia QBE Full timePrimary Details Time Type: Full time Worker Type: Employee- Location: Sydney- Type: Permanent, full time The opportunity The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is a technical and people leader...
-
Cyber Security Manager
22 hours ago
Sydney, Australia Charterhouse Full timeExcellent opportunity for senior Security professionals with aspirations to work towards the executive suite as you will be engaging with C level on a regular basis and operate at a strategic level. The ability to communicate technical terminology into business risks is essential and your communication style should be collaborative to see you successful in...
-
Sydney, New South Wales, Australia Macquarie University Full timeCyber Security Governance, Risk and Compliance ManagerJoin to apply for the Cyber Security Governance, Risk and Compliance Manager role at Macquarie UniversityAbout the RoleMacquarie University is seeking a dynamic and experienced Cyber Security Governance, Risk and Compliance (GRC) Manager to lead the development and implementation of our cyber security GRC...
-
Sydney, New South Wales, Australia Macquarie University Full timeCyber Security Governance, Risk and Compliance Manager Join to apply for the Cyber Security Governance, Risk and Compliance Manager role at Macquarie University About the Role Macquarie University is seeking a dynamic and experienced Cyber Security Governance, Risk and Compliance (GRC) Manager to lead the development and implementation of our cyber...
-
Cyber Security
2 weeks ago
North Sydney, Australia Nine Full timeCompany Description Nine. Australia’s Media Company. Underpinned by our people, our strategic focus is on content, connections and growth. Driven by our purpose - Australia belongs here - and guided by our values - walk the talk, turn over every stone, keep it human - we are the home of Australia’s most loved content and trusted brands across News,...
-
Manager-technology Risk and Cyber
23 hours ago
Sydney, Australia KPMG Australia Full time**Job Description** About the Team** At KPMG Australia, our Consulting Technology Risk and Cyber team is at the forefront of enabling organisations to navigate the complex world of technology, cyber threats, and information security. We deliver impactful and innovative solutions tailored to our clients’ needs, helping them identify and manage technology...