Principal - Security Governance

3 days ago


Brisbane, Australia Queensland Treasury Corporation Full time

Purpose of Role

The Principal, Security Governance role is integral to maintaining the organization’s cyber health and resilience against cyber threats. This role is responsible for developing and maintaining robust information security processes, ensuring disaster recovery (DR) readiness, contributing to the cyber security strategy, and managing cyber risk in alignment with business objectives. Additionally, it encompasses enforcing compliance with standards like the ACSC Essential 8 and ISO27001, evolving cyber reporting for management, and supporting security operations. The role also entails assessing third-party vendor risks, updating security training to reflect the current threat landscape, and coordinating audit and penetration testing activities to address vulnerabilities promptly.

Responsibilities & Accountabilities

**Strategy, Policies and Procedures**
- Develop and maintain Information Security processes and operational procedures.
- Ensure technical DR processes are maintained across all services, including those delivered by QTC’s key vendors.
- Provide input into the development and maintenance of QTC’s Cyber Security Strategy.
- Develop and manage Cyber Security Risk Management processes with an understanding of business requirements and alignment with cyber strategy with business objectives.

**Standards, Reporting and Compliance**
- Ensure compliance with agreed targets and cyber security standards (eg. ACSC Essential 8, ISO27001).
- Develop, maintain, and evolve QTC’s cyber reporting for all levels of management.
- Support the broader security operations team in the implementation and management of security controls across QTC’s technology environment.

**Third Party Vendor Risk**
- Work with procurement, legal and business stakeholders across the organization to assess and manage third-party vendor risk.
- Review and assess vendor security certifications to ensure validity and applicability to the service being delivered.

**Cyber Awareness and training**
- Support the delivery of security awareness campaigns.
- Update security training content to ensure it remains relevant to the evolving threat landscape.

**Audit, Vulnerabilities and Penetration findings.**
- Co-ordinate and support the successful completion of cyber audit and penetrations testing activities across QTC.
- Support the remediation of all findings to ensure they are addressed in the agreed timeline.

Competencies

Technical Competencies
- Understanding of Operating Systems: Proficiency in various operating systems like Windows, UNIX, and Linux is crucial for managing security across different platforms.
- Networking Knowledge: A solid grasp of networking concepts, protocols, and security measures is essential for protecting an organization’s network infrastructure.
- Risk Assessment: Understanding of risk assessment activities to identify vulnerabilities and potential threats to the organization’s cyber environment.
- Compliance: Experience in ensuring adherence to relevant cyber security laws, regulations, and standards.
- Threat Modelling: Knowledge of threat modelling tools and techniques to anticipate and mitigate potential attacks.
- Intrusion Detection: Expertise in using intrusion detection systems (IDS) and understanding attack signatures and anomalies that may indicate a security breach.
- Virtualization and Cloud Security: Understanding of virtualization technologies and cloud security principles to secure virtual environments and cloud-based services.
- Cyber Security Frameworks: Familiarity with cyber security frameworks like the NIST Cybersecurity Framework or the ISO/IEC 27001 standard to guide the organization’s security strategy.
- Incident Response Planning: Ability to develop and implement cyber incident response plans to quickly and effectively address security breaches.
- Disaster Recovery: Aligning disaster recovery processes with broader business continuity processes and requirements.
- Input into design processes to ensure alignment with existing security standards and policies.

Behavioural Competencies
- Integrity, including upholding strong professional and ethical standards.
- Has developed a deep understanding of what drives each stakeholder (their needs, desires and motivations) Speaks up early and often and takes initiative regarding opportunities for improvement.
- Actively tries to improve knowledge management systems and processes within their team.
- Establishes a positive environment by always acting with positive intent, and assuming positive intent from others.

Leadership Competencies
- Builds trust and confidence with the team by communicating clearly, following through on commitment, values diverse perspectives.
- Holds themselves to a standard of excellence and takes pride in their work.
- Strong communication skills to effectively convey complex technical information to non-technical stakeholders and to collaborate with other departments.
- Ability to lead and



  • Brisbane, Australia Transport and Main Roads Full time

    Embark on a challenging and transformative journey with the Department of Transport and Main Roads (TMR). As the Principal Adviser Information Security (Governance, Risk & Compliance), you will serve as the guiding light, providing critical advice and steering the strategic direction for our information security policies and governance frameworks. In this...


  • Brisbane, Queensland, Australia Services Australia Full time $120,000 - $180,000 per year

    The Legal Services Division (the division) provides strategic legal advice and assistance to the agency's executive and the Minister. The division is responsible for the delivery of legal services within and on behalf of the agency. As well as Centrelink, Medicare and Child Support programs, Services Australia (the agency) provides services for almost every...


  • Brisbane, Australia Transport and Main Roads Full time

    Key responsibilitiesInformation Security Services within CITEC covers the below a broad range of cyber security domains: - Security governance, risk and compliance - Security architecture, roadmap and risk assessment - Security consultancy and professional services to agencies - Security initiatives to enhance our services or develop new security services...


  • Brisbane, Australia Hudson Australia Full time

    Hudson is proud to be working with a local government agency in the search for a principal cyber security GRC specialist to guide them in the uplift of information security standards across the organisation. A key pillar in this uplift will be achieving ISO 27001 accreditation. The workplace has a flexible hybrid working model (2 days from home). This is a...


  • Brisbane, Queensland, Australia Department of Education Full time $120,000 - $180,000 per year

    About the Department of Education:Working for the Queensland Department of Education means joining an organisation that values its people and promotes leadership and innovation. Be part of an environment that respects professionalism and diversity,  offers training and development opportunities and embraces flexible careers and work-life balance. Find out...


  • Brisbane, Queensland, Australia Queensland Government Full time $120,000 - $180,000 per year

    *About the Department of Education: Working for the Queensland Department of Education means joining an organisation that values its people and promotes leadership and innovation. Be part of an environment that respects professionalism and diversity, offers training and development opportunities and embraces flexible careers and work-life balance. Find out...


  • Brisbane Central Business District, Australia Peoplebank Full time

    **Role - Principal Cyber Security Consultant** Brisbane CBD based, Hybrid working State government client Competitive day rate Initial engagement until April'23 **About the role** The Principal Cyber Security Consultant will provide technical leadership and work closely with key stakeholders to design the cyber security products and solutions through...

  • Principal Advisor

    7 days ago


    Brisbane, Australia Office of Industrial Relations Full time

    As a senior member of the Strategy and Governance team, you will be part of an agile and responsive team that leads the planning, design and delivery of state-wide WHS strategies and prevention programs impacting Queensland industry, business and the community. The role will require you to lead and coordinate the implementation and evaluation of key projects...


  • Brisbane, Queensland, Australia Qld Health Full time $120,000 - $180,000 per year

    As a Principal Governance Officer, you will actively participate in the implementation of governance and compliance improvements through drafting policies and working with stakeholders to embed improvements into processes and controls. You will provide expert advice and support to key stakeholders on development and implementation of organisational...

  • Security Officer

    2 weeks ago


    Brisbane, Queensland, Australia Certis Security Australia Full time $60,000 - $90,000 per year

    Company description: Certis Security Australia is one of Australia's leading security service provider with over 3,000 employees nationwide, providing our clients with industry leading security services with our state-of-the-art technology and highly qualified staff. As part of the Certis Group, SNP Security and BRI Security deliver integrated security...