Principal Security Governance and Privacy Specialist

6 days ago


Sydney, New South Wales, Australia Australian Prudential Regulation Authority (APRA) Full time $120,000 - $180,000 per year

The role

The Principal Security Governance & Privacy Specialist is instrumental in developing, managing, and maintaining security policies, standards, and procedures. The role contributes to strategic security analysis and planning while ensuring compliance with security policies and proactively managing security risks. The role will integrate security governance into existing forums and addressing any gaps through strategic governance approaches and take a lead role on ensuring a cohesive security team operationally.

The team

APRA is embarking on an ambitious program of change incorporating cloud, data, digital and security initiatives. This has created the opportunity to join a small but growing Security team which sits within the Technology, Data and Security division. The Security team manages cyber, information and personnel security aligning with the Protective Security Policy Framework (PSPF).

The team works in a highly collaborative manner with a wide range of stakeholders at all levels of the organisation to develop, communicate and implement the security strategy. Key stakeholders within the division include the CIO, CDO, CRO, Enterprise Architecture and IT Governance. Other key stakeholders across the organisation will include the Business Divisions, People and Culture, Procurement and Project Management Office.

Key responsibilities

  • Lead the development, management and maintenance of comprehensive security policies, standards, and procedures across personnel, physical and cyber/information security.
  • Oversee and ensure compliance with security standards and regulatory requirements and work closely with colleagues to gather information for reporting and analysis.
  • Integrate security governance into existing forums and develop governance approaches to address identified gaps.
  • Proactively maintain and manage the security risk register and support the execution of security risk assessments.
  • Support security risk management and reporting processes, including policy exceptions and exemptions.
  • Lead knowledge management across the security team to ensure up-to-date procedures and capabilities.
  • Work with management on proactive team capability planning including skills, RACIs and capability gaps, and team operational activities including cross-security team process improvement, resourcing management, budget and operational efficiencies.
  • Support the CISO by contributing to regular executive-level reporting on security outcomes.

    Contribute to government reporting (e.g., PSPF, E8, response to government directives).
  • Security Plan and Strategy Management: Contribute to strategic security analysis and planning to enhance the overall security framework, execution of security objectives and resolution of gaps.
  • High Performing Team: Proactively contribute to and support broader direct team outcomes.

To work with us, you must be an Australian citizen with eligibility to gain a NV1 clearance through the Australian Government Security Vetting Agency.

About you

  • Proven experience in developing and managing security policies and standards.
  • Experience in strategic security analysis and planning.
  • Strong background in managing security compliance activities.
  • Experience in maintaining security risk registers and conducting security risk assessments.
  • Knowledge and application of security governance frameworks and integration strategies.
  • Proficiency in security policy development and management.
  • Strong analytical skills for conducting strategic security analysis.
  • Expertise in security compliance and regulatory standards.
  • Ability to manage and assess security risks effectively.
  • Familiarity with security governance models and best practices.
  • Knowledge of relevant government reporting requirements and frameworks.

About APRA

Australian Prudential Regulation Authority (APRA) was established in 1998 as an independent statutory authority that supervises almost 1,200 financial institutions that manage $8.6 trillion in assets for Australians across the banking, insurance and superannuation sectors.

In overseeing the safety, competitiveness and stability of the financial system, we seek to recruit, develop and retain highly skilled professionals, who want to help shape financial services and protect the financial wellbeing of the Australian community. Our employee base of almost 900 come predominantly from the commercial financial services industry or other government agencies; as such, we have the feel of a small corporate organisation that can work flexibly and with agility.

Why Work for APRA

We recognise the skills, experience and commitment that our staff bring to their professional lives, and we seek to reward them accordingly. We also recognise that for our staff to be able to perform at their best, we need to ensure that they are able to bring their best selves to work. Our commitment to wellbeing is having engaged people supported by resilient leaders within a values-aligned culture.

At APRA, we're committed to providing an inclusive workplace where everyone belongs, feels valued and respected. We aspire to attract and foster diversity of background, thought, and experience, recognising that a broad range of perspectives, approaches and ideas makes us stronger, and better enables us to meet our obligation to protect the financial wellbeing of the Australian community. If you need any adjustments during the recruitment process, please inform at application stage so we can do our best to accommodate your requirements.



  • Sydney, New South Wales, Australia Australian Prudential Regulation Authority Full time $120,000 - $180,000 per year

    The roleThe Principal Security Governance & Privacy Specialist is instrumental in developing, managing, and maintaining security policies, standards, and procedures. The role contributes to strategic security analysis and planning while ensuring compliance with security policies and proactively managing security risks. The role will integrate security...


  • Sydney, New South Wales, Australia Experis AU Full time

    A great opportunity for a Principal Cyber Security Specialist.Location: ACT, QLD and NSWJob type: ContractOrganisation: Federal GovernmentDuties and ResponsibilitiesLeading and conducting risk assessments of agency's internal systems and assessing risk from external connections.Undertaking compliance activities in relation to cyber security standards within...


  • Sydney, New South Wales, Australia Experis Australia Full time

    A great opportunity for a Principal Cyber Security Specialist.Location:ACT, QLD and NSWJob type:ContractOrganisation:Federal GovernmentDuties and ResponsibilitiesLeading and conducting risk assessments of agency's internal systems and assessing risk from external connections.Undertaking compliance activities in relation to cyber security standards within the...


  • Sydney, New South Wales, Australia myCareer - NSW Government Full time $149,739 - $173,174

    Principal Security Policy and Governance, Ongoing opportunity based in Sydney CBD + hybrid/flexible working options available The Department of Customer Service (DCS) is looking for a Principal SecurityPolicy and Governance to design, develop, implement, andmaintain department-wide security and governance policies, frameworks, andstandards- in line with...


  • Sydney, New South Wales, Australia NSW Government Full time $120,000 - $180,000 per year

    Principal Security Policy and Governance, Ongoing opportunity based in Sydney CBD + hybrid/flexible working options availableThe Department of Customer Service (DCS) is looking for a Principal Security Policy and Governance to design, develop, implement, and maintain department-wide security and governance policies, frameworks, and standards- in line with...


  • Sydney, New South Wales, Australia NSW Department of Customer Service Full time $149,739 - $173,174 per year

    Principal Security Policy and Governance, Ongoing opportunity based in Sydney CBD + hybrid/flexible working options available The Department of Customer Service (DCS) is looking for a Principal Security Policy and Governance to design, develop, implement, and maintain department-wide security and governance policies, frameworks, and standards- in line with...

  • Privacy Specialist

    4 days ago


    Sydney, New South Wales, Australia The Star Entertainment Group Full time $80,000 - $120,000 per year

    Privacy Specialist - ComplianceThe Star Entertainment Group (TSEG) is a publicly listed company on the ASX. Our purpose is to create fun at trusted destinations and our aim is to deliver sustainable outcomes for our guests, our Team Members, the communities in which we exist and our shareholders. We do this by providing entertainment, gaming, and leisure...


  • Sydney, New South Wales, Australia Infosys Full time $120,000 - $180,000 per year

    About Us: Infosys is a global leader in next-generation digital services and consulting. We enable clients in more than 56 countries to navigate their digital transformation. With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer our clients through their digital journey. We do it by enabling the...


  • Sydney, New South Wales, Australia BURGEON IT SERVICES Full time $120,000 - $140,000 per year

    Position: DLP Specialist with Data Privacy Skills / Tech LeadLocation: Sydney, NSWDuration: 6 monthsJob Details:Must Have Skills:Data Classification & Protection : Expertise in identifying, categorizing, and securing sensitive data across systems, ensuring compliance with privacy regulations like GDPR, HIPAA, or CCPA.DLP Policy Configuration & Management :...


  • Sydney, New South Wales, Australia Tech Aalto Full time $80,000 - $120,000 per year

    Job Description: Data Governance SpecialistPrimary Skill:Data GovernanceSecondary Skill:Exposure to Profisee and Talend Metadata Manager toolsKey Responsibilities:Develop and implement a comprehensive Data Governance Framework, including Operating Models, Policies, Processes, and Procedures.Define and periodically refresh Data Governance roles,...