Cyber Defence Risk Manager

2 weeks ago


Sydney, Australia Commonwealth Bank of Australia Full time

Cyber Defence Risk Manager

**See yourself in our team**:
The Technology and Operations (Tech & Ops) Risk team is responsible for providing specialist Operational Risk and Compliance (OR&C) advice and assurance of decisions made across the Technology, Chief Operating Office, and Business Unit divisions.

**Do work that matters**:
You will play a key role within the **Cyber Defence Risk **team as part of the Security Operational Risk function that supports Group Security. You will partner with the Executive Manager Cyber Risk to provide independent Line 2 advice and assurance and actively uplift capability across the Cyber Security SOC and App Security functions.

**Key responsibilities for this role includes**:
**Technical**:

- Provide SME risk management advice to cybersecurity teams aligned to the following cyber risk management domains: Application & Service Protection, Vulnerability Management, Data Security, Cloud Security, Third Party Security, Identity & Access Management, and Cyber Defence.
- Working as part of a team of professional SMEs to provide independent, pragmatic and value adding Operational Risk advice and assurance for technology and cyber risks across the Group.
- Monitoring and reporting of three lines of accountability (3LoA) activities to the Executive Manager, including BAU management of the Risk Management Approach, the Operational Risk Management Framework and Compliance Management Framework in support of CPS 220.
- Contributing to the oversight and monitoring of key technology and cyber risks, controls, issues, incidents, and risk-in-change.
- Supporting the appropriate identification, escalation and reporting of all related technology and cyber risk and compliance matters to the relevant stakeholders, including the relevant NFRCs, your EM/GM and to the Technology and Operations CRO.

**Leadership**:

- Work as part of a cross-skilled team that can support a range of inter-connected risk domains; speaking up and contributing to appropriate Line 2 oversight and challenge.
- Provide ideas for Line 2 risk management and assurance activities, data analytics and stakeholder reporting; contribute to a culture of learning and collaboration.
- Role model behaviours that are consistent with CBA values expectations and leadership principles; provide a safe workplace for all team members, customers and visitors.
- Develop and maintain partnerships with stakeholders; become a trusted advisor using commercial acumen, practical recommendations; and assist the business to understand where prioritised focus on key risks and compliance matters is required.

**We're interested in hearing from people who have**:

- Cyber Security experience required with sound knowledge of applicable industry standards, frameworks and regulations (e.g. CPS234, NIST, ISO27001, Information Security Manual, Essential 8, OWASP, MITRE).
- Preference for information security certification (e.g. CISM, CRISC, CISSP, GSEC, CompTIA, Security+, CEH).
- Background in Operational Risk and Compliance with technology and cyber risk management specialties within the Financial Services industry highly regarded.
- High quality written and verbal communication skills, report writing, evidence gathering and data analysis capabilities.
- Stakeholder and influencing skills with the ability to proactively engage Line 1 teams and engender trust with pragmatic, commercially balanced risk advice.
- A curious and humble mindset, understanding of external trends and changes, interest in continuous learning, to build risk management best practice.

**Your Career**:
If you live the values and demonstrate the people capabilities we can offer great opportunities. Whether you want to move across the organisation or up into a leadership role, the way you live the values and demonstrate the people capabilities are key. Use the capabilities required for this role as a guide to the critical skills and behaviours you need for your next move.

We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.

Advertising End Date: 17/11/2024

Job ID REQ218629



  • Sydney, New South Wales, Australia Commonwealth Bank Full time

    **Cyber Defence Risk Lead****See yourself in our team**:The Technology and Operations (Tech & Ops) Risk team is responsible for providing specialist Operational Risk and Compliance (OR&C) advice and assurance of decisions made across the Technology, Chief Operating Office, and Business Unit divisions.**Do work that matters**:The purpose of this role is to...


  • Sydney, Australia Commonwealth Bank Full time

    **Cyber Defence Analytics Researcher** **See yourself in our team**: Cyber Security protects the bank and our customers from theft, loss and risk events, through effective and proactive management of cyber security, privacy and operational risk. This role sits within Cyber Defence Analytics—a specialist research and analytics team supporting the bank’s...

  • Cyber Defence Analyst

    2 weeks ago


    Sydney, New South Wales, Australia Munich Re Full time

    **Cyber Defence Analyst**:Career Level 3**Location**Sydney, AustraliaOur "ITRS Global Security Operations Centre" within the global Information Technology group are looking for a qualified individual as a **Cyber **Defence** Analyst (IT Risk Technical Specialist)**. This unit focuses on the prevention, protection, detection, and response capabilities against...

  • Cyber Defence Analyst

    2 weeks ago


    Sydney, New South Wales, Australia Munich Re Full time

    **Cyber Defence Analyst - Sydney**:Career Level 3**Location**Sydney, AustraliaOur "ITRS Global Security Operations Centre" within the global Information Technology group are looking for a qualified individual as a **Cyber **Defence** Analyst (IT Risk Technical Specialist)**. This unit focuses on the prevention, protection, detection, and response...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time $90,000 - $120,000 per year

    Cyber Defence Analytics ResearcherSee yourself in our team:Cyber Security protects the bank and our customers from theft, loss and risk events, through effective and proactive management of cyber security, privacy and operational risk.This role sits within Cyber Defence Analytics—a specialist research and analytics team supporting the bank's broader Cyber...


  • Sydney, New South Wales, Australia Commonwealth Bank Full time

    Cyber Defence Analytics ResearcherSee yourself in our team:Cyber Security protects the bank and our customers from theft, loss and risk events, through effective and proactive management of cyber security, privacy and operational risk.This role sits within Cyber Defence Analytics—a specialist research and analytics team supporting the bank's broader Cyber...


  • Sydney, New South Wales, Australia Commonwealth Bank Full time

    Cyber Defence Analytics ResearcherSee yourself in our team:Cyber Security protects the bank and our customers from theft, loss and risk events, through effective and proactive management of cyber security, privacy and operational risk.This role sits within Cyber Defence Analytics—a specialist research and analytics team supporting the bank's broader Cyber...


  • Sydney, New South Wales, Australia beBeeCybersecurity Full time $150,000 - $180,000

    Job Description:We are seeking an expert in security strategy, GRC, and architecture to provide advisory services to our clients. The ideal candidate will have experience in the Defence environment and knowledge of Defence-specific risk management frameworks and methodologies.The successful candidate will lead client cyber security practices, providing cyber...


  • Sydney, New South Wales, Australia beBeeCyber Full time $200,000 - $250,000

    Cyber Defence Risk LeadThe Cyber Defence Risk Lead will serve as a leader within the cyber risk team, supporting the group security function.Key responsibilities for this role include:TechnicalCollaborate with and provide SME risk management advice to crews aligned to cyber domains that mainly cover: Security Engineering, Vulnerability Assessment, Cyber...


  • Sydney, New South Wales, Australia beBeeCyber Full time $150,000 - $160,000

    Key Role in Cyber Defence Transformation.This is an exciting opportunity to deliver a comprehensive cyber defence transformation, acting as the representative to organisational stakeholders for ongoing engagement on the threat profile.Develop and refine technical processes, tools, procedures, and techniques used by the team to continually improve operational...