Head of Security Strategy, Governance

1 week ago


Sydney, Australia Australian Prudential Regulation Authority (APRA) Full time

**The role**

The Head of Security Strategy, Governance, and Privacy is a pivotal senior leadership role responsible for developing and implementing comprehensive security strategies, ensuring robust governance frameworks, and overseeing privacy compliance.

This role involves planning for future security needs, managing existing risks, and leading compliance efforts to protect APRA’s assets, people and data.

**The team**

The Security team sits within the Data, Technology and Security (DTS) division and with a new CISO recently started, the team is going through uplift.

The Security team manages cyber, information and personnel security aligning with the Protective Security Policy Framework (PSPF). The team works in a highly collaborative manner with a wide range of stakeholders at all levels of the organisation to develop, communicate and implement the security strategy and governance arrangements.

**Key responsibilities**
- Security Plan and Strategy Management: Develop and implement security strategies that align with organisational goals and government requirements
- Cross-Security Team Operational Leadership: Lead operational security team activities including cross-security team process improvement, resourcing management, budget and operational efficiencies
- Security and Privacy Governance: Oversee policies and practices to ensure compliance with relevant laws, government policies and regulations. Lead security governance integration into existing forums and develop and execute governance approaches for identified gaps
- Security Risk Management & Monitoring: work with other Security heads and cross-teams to lead the identification, assessment, tracking, management, exceptions and reporting of security risks, issues and progress, ensuring continuous monitoring and improvement
- Security Metrics and Reporting: Develop and maintain security metrics to measure the effectiveness of security activities and programs and report on security posture to senior management and other key stakeholders
- High Performing Team: Work with the CISO, Executive Director Technology & Data, CDO, CIO and Senior Manager peers to build a cohesive and collaborative high performing leadership and teams.

**About you**
- Proven track record of leading security initiatives and managing compliance requirements
- Experience in risk management, policy development and security metrics
- Experience with cyber risk quantification (e.g. FAIR)
- Experience with cross-security team operational management (e.g. budget, processes, resourcing).

Technical Skills:

- In-depth knowledge of Australian government security frameworks, standards, and best practices (i.e. PSPF, ISM and Essential 8)
- Proficiency in security risk assessment and management tools
- Familiarity with privacy regulations (e.g., Australian Privacy Act) and compliance requirements
- Strong understanding of security technologies and best practices, and ability to develop a cohesive security strategy and plan.

Soft Skills:

- Excellent leadership and team management abilities. Consultative, collaborative and a proactive team player
- Strong analytical and problem-solving skills
- Ability to think strategically and make clear and immediate data-driven decisions
- Exceptional stakeholder engagement and relationship skills, highly adept in managing a diverse group of senior stakeholders and relationships
- Highly developed executive communication, leadership, negotiation, conflict resolution and interpersonal skills and the ability to represent APRA’s view in a highly professional and sensitive manner. The ability to translate complex technical issues into plain language.
- Sees security as a business enabler with a strong ability to take a risk-based approach to security requirements.

To work with us, you need to be an Australian citizen with eligibility to gain NV1 security clearance.

**About APRA**

The Australian Prudential Regulation Authority (APRA) places you at the heart of Australia’s financial services industry. APRA serves the Australian community by helping ensure financial institutions deliver on the financial commitments they make, within a stable, efficient and competitive financial system.

At APRA we’re committed to providing an inclusive workplace where everyone belongs, feels valued and respected. We aspire to attract and foster diversity of background, thought, and experience, recognising that a broad range of perspectives, approaches and ideas makes us stronger, and better enables us to meet our obligation to protect the financial wellbeing of the Australian community. When applying, please inform us of any adjustments you may need during the interview process.



  • Sydney, New South Wales, Australia Australian Prudential Regulation Authority (Apra) Full time

    **The role**The Head of Security Strategy, Governance, and Privacy is a pivotal senior leadership role responsible for developing and implementing comprehensive security strategies, ensuring robust governance frameworks, and overseeing privacy compliance.This role involves planning for future security needs, managing existing risks, and leading compliance...

  • Head of Property

    3 days ago


    Sydney, Australia Westpac Group Full time

    **How will I help?** The Head of Property and Security Governance is responsible for ensuring appropriate governance and compliance in project delivery and services performed by Group’s Property & Security for Westpac. This spans, project management, change and communications management, data management, supplier governance and operational risk...

  • Head of Strategy

    2 weeks ago


    Sydney, Australia Australian Prudential Regulation Authority (APRA) Full time

    **The role** The Head of Strategy will lead a high performing strategy team to shape APRA’s priorities and ensure organisational alignment around these objectives. It reports to the General Manager Strategy and Governance, and sits within APRA’s Chief of Staff & Enterprise Services (CHeS) division. The Head of Strategy is an important enabler of...


  • Sydney, New South Wales, Australia Fortinet Full time

    Location: Australia (Canberra, Sydney)Join Fortinet, a cybersecurity pioneer with over two decades of excellence, as we continue to shape the future of cybersecurity and redefine the intersection of networking and security. At Fortinet, our mission is to safeguard people, devices, and data everywhere. We are currently seeking a dynamic Head of Government...

  • Head Of Strategy

    2 weeks ago


    Sydney, New South Wales, Australia Australian Prudential Regulation Authority (Apra) Full time

    **The role**The Head of Strategy will lead a high performing strategy team to shape APRA's priorities and ensure organisational alignment around these objectives. It reports to the General Manager Strategy and Governance, and sits within APRA's Chief of Staff & Enterprise Services (CHeS) division.The Head of Strategy is an important enabler of APRA's...


  • Sydney, New South Wales, Australia Icare External Full time

    **Head of Cyber Strategy & Advisory** - **Sydney**Accountable the continuous improvement and delivery of cyber and information security strategy and advisory services.- Responsible for alignment of cyber & information security strategy to business objectives- 10 yrs' experience in comparative organisations & support to achieve ISO27001 certification.-...

  • Head of Governance

    7 days ago


    Sydney, Australia Australian Prudential Regulation Authority (APRA) Full time

    **The role** The Head of Governance plays a critical role in overseeing APRA’s governance arrangements and providing strategic advice to senior leadership. This position requires a combination of strategic thinking, strong communication skills and a deep understanding of governance practices. Reporting to the General Manager of Strategy and Governance,...

  • Head of Property

    3 days ago


    Sydney, Australia Westpac Group Full time

    **How will I help?** The Head of Property and Security Strategy is responsible for developing and supporting the execution of the Group’s retail and corporate property portfolio and security strategy. The role will lead the development of property and security transformation initiatives, the development of supporting business cases and tracking of...


  • Sydney, Australia iCare External Full time

    **Head of Cyber Strategy & Advisory** - **Sydney** Accountable the continuous improvement and delivery of cyber and information security strategy and advisory services. - Responsible for alignment of cyber & information security strategy to business objectives - 10 yrs’ experience in comparative organisations & support to achieve ISO27001 certification. -...


  • Sydney, Australia Cuscal Full time

    **Company Description** Cuscal - where curiosity and expertise are rewarded.** Be part of a smaller team taking on a bigger role - a role where your curiosity, your energy, your ambition is rewarded. You’ll grow with us in an unconventional way where sideways develops you as much as up; where voices are heard and ideas are tested, and new things are...