Control Lead Security Posture Management
3 days ago
**C**ontrol**Lead**Security Posture Management**(**Senior**Manager)**
- _You are _a _cyber _security _risk and control professional with _a _background in _Vulnerability Management _control design and implementation _
- _We are one _of the best and most advanced Cyber Security teams in Australia _
- _Together we can _build the _Cyber Controls _Chapter _Area _and contribute to protecting the Group, its customers and community. _
**See yourself in our team**:
The Cyber Controls Chapter Area plays a crucial function within the Group Security division being responsible for designing and deploying effective cyber control capabilities and overseeing continuous improvement of the Group’s cyber risk p rofile.
As a large, tech‑driven organisation serving millions of customers daily, we must continuously harden our environment against an evolving threat landscape. This role leads the **enterprise‑wide Secure Configuration Management (SCM) control capability**, ensuring **secure baselines are defined, deployed,**monitored**and continuously improved**across all major asset classes. You’ll also provide **rules‑based security posture management oversight**(CSPM/SSPM/KSPM/Network/Posture-as-Code) and drive timely, risk‑informed remediation of baseline exceptions.
We support our people with the flexibility to balance where work is done with at least half your time each month connecting in office. We also have many other flexible working options available including changing start and finish times, part-time arrangements and job share to name a few. Talk to us about how these arrangements might work for you.
**Do work that matters**
Establis hing and maintaining control standards and guidelines to align with changes i n industry standards, technology strategy and threat intelligence.
Governing the Group’s compliance with Security Configuration Management control requirements and supp orting the business in track ing remediation of critical security weaknesses and improvement of overall risk posture.
**You will also**:
- Ensure Security Configuration and Posture Management operation adher es to the Group Operational Risk Management Framework.
- Define the control testing approach to support automated control performance monitoring.
- Carry out annual control effectiveness assessments and drive appropriate risk remediation to address identified control weaknesses.
- Maintain positive stakeholder engagement with product owners, security engineers, and adjacent cyber security teams in relation to the development and lifecycle of secure configuration baselines and posture rulesets
**We are interested in hearing from people who**have**:
**Security Standards & Frameworks**
- Applied knowledge of ASD ISM, NIST, CIS, and Essential Eight mitigation strategies.
- Familiarity with vulnerability prioritisation frameworks like CVSS and EPSS.
- Security certifications such as CISSP, CISM, or CRISC are highly desirable.
**Tools & Technologies**
- Hands-on experience with policy compliance and security posture tools (e.g., Qualys, Wiz, NoName, Obsidian).
- Skilled in hardening endpoints and cloud services.
- Strong understanding of system security principles and automation for continuous compliance and reporting.
**Threat & Vulnerability Management**
- Ability to analyse threat intelligence, identify risks, prioritise vulnerabilities, and recommend mitigations.
- Experience implementing patch management programs and working with enterprise vulnerability management solutions.
We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.
Advertising End Date: 18/09/2025
-
Microsoft Cloud Security Posture Management
7 days ago
Sydney, Australia HAYS Full timeMicrosoft Cloud Security Posture Management SME **Your new company** Hays have partnered with a multi-national consultancy who are looking for an SME in Microsoft Cloud Security Posture Management. **Your new role** This role is working with a client in the insurance space - they want someone who can overlook their Microsoft CPSM. **What you'll need to...
-
Control Lead Cloud Security
7 days ago
Sydney, Australia Commonwealth Bank Full time**C**ontrol Lead**Cloud Security**(**Senior**Manager)** - _Are you _a _cyber _security _risk and control professional with _a _background in _cloud security _control design and implementation _? _ - _We are one _of the best and most advanced Cyber Security teams in _Australia. _ - _Together we can _build the _Cyber Controls _Chapter _Area _and contribute to...
-
▷ 15h Left: Senior Cyber Security Analyst
4 weeks ago
Council of the City of Sydney, Australia Reserve Bank of Australia Full time**More flexibility, less one-size-fits-all**Work that makes a difference. Australians depend on our systems being secure, efficient and highly resilient. Experience the capability-building opportunity to work with Australia’s most critical payments platforms.The RBA’s unique position as Australia’s central bank means that you will gain exposure to an...
-
Lead Security Analyst
2 weeks ago
North Sydney, Australia Open Text Corporation Full time**Lead Security Analyst**: - Req id: 38235- North Sydney, NSW, AU**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management. **Role** - Work in a team...
-
Lead Security Analyst
2 weeks ago
North Sydney, Australia opentext Full time**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management. **Role** - Work in a team that manage and maintain Web Application Firewalls (WAF), Intrusion...
-
Technical Lead
3 days ago
Sydney, Australia Sourced Group Full timeSourced (an Amdocs company) has joined the recently launched Amdocs Cloud division. Amdocs are a leading provider of software and services to over 350+ communications and media companies. Sourced were acquired for their deep expertise in public cloud and highly regulated industries. We are excited to continue the journey and leverage Amdocs scale to further...
-
Information Security Manager
2 weeks ago
Sydney, New South Wales, Australia Rabobank Full timeJob TitleInformation Security ManagerJob DescriptionRabobank is the world's leading specialist in food & agribusiness banking. One of our key strengths lies in our people who have a deep understanding of agriculture & are committed to adding long-term value for clients. Our commitment to our employees & clients is at the heart of everything we...
-
Sydney, New South Wales, Australia Axiom Technologies Full time $120,000 - $180,000 per yearAxiom Technologies is an Australia-based entity with a history of providing Managed IT solutions to medium to large-scale enterprises globally. Please visit our website for more information about what we do at We are looking for an experienced Security Business Analyst to support our Vulnerability Management and Security Posture Programs. The ideal candidate...
-
Security Lead
3 days ago
Sydney, Australia Technology People Australia Full timeOur clients seek an experienced Security Manager/Lead to maintain and enhance the existing Security Posture across the Business. You will be required to ensure the security of all Information Systems and Data. You will manage all PCI-DSS Obligations to make sure all compliance is in line with required regulations. You will develop and maintain all...
-
Data Platform Security Lead
2 weeks ago
Sydney, Australia Ayan Infotech Full timeAyan Infotech has an exciting initial 6-month contract opportunity for a Data Platform Security Lead (Azure) in Sydney, CBD. **Australian citizens can only be considered for this role. It would be ideal if the contractor had a Baseline security clearance.** The Security SME role is to take accountability and responsibility for the security component of the...