Cyber Defence Risk Lead
2 days ago
**Cyber Defence Risk Lead**
**See yourself in our team**:
The Technology and Operations (Tech & Ops) Risk team is responsible for providing specialist Operational Risk and Compliance (OR&C) advice and assurance of decisions made across the Technology, Chief Operating Office, and Business Unit divisions.
**Do work that matters**:
The purpose of this role is to serve as a leader within the Cyber Risk team in the Tech & Ops Risk division, supporting the Group Security function. You will collaborate with the Executive Manager Cyber Defence Risk to provide independent Line 2 advice and assurance regarding the implementation of the Risk Management Approach and the Operational Risk and Compliance Management Framework. Additionally, you will play an active role in enhancing risk capabilities across the Cyber Security functions.
**Key responsibilities for this role include**:
**Technical**:
- Collaborate with and provide SME risk management advice to crews aligned to cyber domains that mainly cover: Security Engineering, Vulnerability Assessment, Cyber Attack (Penetration testing, Red Teaming etc.) and Cyber Defence.
- Working as part of a team of professional SMEs to provide independent, pragmatic and value adding Operational Risk advice and assurance for technology and cyber risks across the Group.
- Supporting the Executive Manager through monitoring and reporting on the three lines of accountability (3LoA) activities, including the Risk Management Approach, the Operational Risk Management Framework, and the Compliance Management Framework in support of CPS 220. This also involves overseeing key security risks, controls, issues, and incidents, as well as risks related to change and licensing obligations, while managing risk acceptance through data-driven BAU monitoring activities as well as periodic assurance reviews
- Contributing to the oversight and monitoring of key technology and cyber risks, controls, issues, incidents, and risk-in-change.
- Supporting the appropriate identification, escalation and reporting of all related technology and cyber risk and compliance matters to the relevant stakeholders, including the relevant NFRCs, your EM/GM and to the Technology and Operations CRO.
**Leadership**:
- Work as part of a cross-skilled team that can support a range of inter-connected risk domains, speaking up and contributing to appropriate Line 2 oversight and challenge.
- Provide ideas for Line 2 risk management and assurance activities, data analytics and stakeholder reporting; contribute to a culture of learning and collaboration.
- Role model behaviours that are consistent with CBA values expectations and leadership principles; provide a safe workplace for all team members, customers and visitors.
- Develop and maintain partnerships with stakeholders; become a trusted advisor using commercial acumen, practical recommendations; and assist the business to understand where prioritised focus on key risks and compliance matters is required.
**We’re interested in hearing from people who have**:
- Extensive experience required in cyber security with sound knowledge of applicable industry standards, frameworks and regulations (e.g. OWASP, MITRE ATT&CK and D3FEND, CPS234, NIST etc.).
- Preference for a recognised information security certification (e.g. CISSP, CISM, SABSA, OCSP etc.).
- Sufficient technical acumen to engage with the cyber teams and have meaningful conversations about risk requirements or prioritisation. For instance, you are able to take a penetration test report and clearly articulate what remediation activities should be prioritised when considering business risk.
- Background in Operational Risk and Compliance with technology and cyber risk management specialties within the Financial Services industry highly regarded.
- High quality written and verbal communication skills, report writing, evidence gathering and data analysis capabilities.
- Stakeholder and influencing skills with the ability to proactively engage Line 1 teams and engender trust with pragmatic, commercially balanced risk advice.
- A curious and humble mindset, understanding of external trends and changes, interest in continuous learning, to build risk management best practice.
**Your Career**:
If you live the values and demonstrate the people capabilities we can offer great opportunities. Whether you want to move across the organisation or up into a leadership role, the way you live the values and demonstrate the people capabilities are key. Use the capabilities required for this role as a guide to the critical skills and behaviours you need for your next move.
- We support our people with the flexibility to balance where work is done with at least half their time each month connecting in office. We also have many other flexible working options available including changing start and finish times, part-time arrangements and job share to name a few. Talk to us about how these arrangements might work in the role you’re inter
-
Cyber Defence Analyst
4 days ago
Sydney, Australia Munich Re Full time**Cyber Defence Analyst - Sydney**: Career Level 3 **Location** Sydney, Australia Our "ITRS Global Security Operations Centre” within the global Information Technology group are looking for a qualified individual as a **Cyber **Defence** Analyst (IT Risk Technical Specialist)**. This unit focuses on the prevention, protection, detection, and response...
-
Sydney, Australia KPMG Full time**About the Role** As a Federal Government Accreditation Specialist in our Tech Risk and Cyber team, you will lead engagements into Fed Gov, Defence and Defence Industry to conduct security assessments, technology risk advisory, and cyber assurance services. You will work closely with government and private sector clients to help them navigate complex...
-
Product Owner
2 days ago
Sydney, Australia Commonwealth Bank Full time**Product Owner - Cyber Risk Quantification** **Overview** The Product Owner - Cyber Risk Quantification (CRQ) within Group Security, Chief Information Risk Officer (CIRO) portfolio, is responsible for defining and leading the vision, strategy, and roadmap for CBA’s cyber risk quantification capability. This role translates complex cyber threats and...
-
Cyber Security Risk Assurance Lead
2 weeks ago
Sydney, New South Wales, Australia ALOIS Solutions Full time $150,000 - $250,000 per yearRole: Cyber Security Risk Assurance LeadWork location: Sydney , Melbourne, Canberra - Open for all locationsRole type: ContractRole:The Cyber Security Risk Assurance Lead is hands-on and multi disciplined, assessing complex technical issues and performing cyber security risk assessments across a wide range of initiatives in a fast-paced, complex...
-
Director of Cyber Defence and Operations
2 weeks ago
Sydney, New South Wales, Australia QBE Full time $104,000 - $250,000 per yearPrimary DetailsTime Type: Full timeWorker Type: EmployeeLocation: Sydney or MelbourneType: Permanent, full timeHybrid role, Happy to talk flexible workingThe opportunityInfluential senior cyber role; shape and deliver high-impact security initiativesInternational remit supporting QBE's global operationsIt's Our Moment and Yours TooYour new roleAs Director of...
-
Director of Cyber Defence and Operations
6 days ago
Sydney, New South Wales, Australia QBE Insurance Full time $120,000 - $180,000 per yearPrimary DetailsTime Type: Full timeWorker Type: EmployeeLocation: Sydney or MelbourneType: Permanent, full timeHybrid role, Happy to talk flexible workingThe opportunityInfluential senior cyber role; shape and deliver high-impact security initiativesInternational remit supporting QBE's global operationsIt's Our Moment and Yours TooYour new roleAs Director of...
-
Program Lead Cyber Risk
2 weeks ago
Sydney, Australia Macquarie Group Limited Full timeJoin our Cybersecurity Transformation and Change Delivery team as Program Lead for the Information and Cyber Security (ICS) Risk Management Program to drive proactive transformation and maximise value from our investments.At Macquarie, our advantage is bringing together diverse people and empowering them to shape all kinds of possibilities. We are a global...
-
Cyber Security Risk Advisor
2 weeks ago
Sydney, Australia University of New South Wales Full time**Job no**: 527915 **Work type**: Full Time **Location**: Sydney, NSW **Categories**: Information Technology, Cyber - Employment Type: full time continuing role as a Cyber Security Risk Advisor - Exceptional salary package including generous superannuation - Location: UNSW Kensington Campus (Hybrid Working Opportunities) **About UNSW**: UNSW isn’t like...
-
Cyber Risk Consultant
1 week ago
Sydney, Australia Aon Corporation Full timePosting Description: - Opportunity for a risk management professional to join our Cyber Consulting team - Full time, permanent opportunity based in Sydney **Cyber Risk Consultant** This role is responsible for helping to set the strategy in relation to Aon’s Cyber Risk endeavours. In the role you will be executing the provision of Cyber Risk consulting...
-
Manager, Group Cyber Risk
4 days ago
Sydney, Australia Qantas Airways Limited Full timeFantastic opportunity to join our Airline IT business and to join our Group Cyber Assurance Risk & Compliance - Be part of super-collaborative, passionate team that values cyber safe practicePermanent opportunity based at our Head Office in Mascot The Manager, Group Cyber Risk & Assurance will be responsible for managing and delivering strategic risk...