Senior Security Risk Reporting Specialist
7 days ago
The role
The Senior Security Risk & Reporting Specialist is a pivotal role responsible for developing, managing, and maintaining the end-to-end security risk management processes. This includes policy exceptions and exemptions, maintaining the security risk register, and supporting security risk assessments. The specialist will develop and maintain a security risk reporting framework, implement a cyber risk quantification capability, and provide regular executive-level reporting on security outcomes. This role requires cross-collaboration with personnel, physical, and cyber/information security topic areas to ensure a cohesive end-to-end analysis, identification, management, and reporting of security risks and issues.
The team
APRA is embarking on an ambitious program of change incorporating cloud, data, digital and security initiatives. This has created the opportunity to join a small but growing Security team which sits within the Technology, Data and Security division. The Security team manages cyber, information and personnel security aligning with the Protective Security Policy Framework (PSPF).
The team works in a highly collaborative manner with a wide range of stakeholders at all levels of the organisation to develop, communicate and implement the security strategy. Key stakeholders within the division include the CIO, CDO, CRO, Enterprise Architecture and IT Governance. Other key stakeholders across the organisation will include the Business Divisions, People and Culture, Procurement and Project Management Office.
Key responsibilities
- Lead the development, management and maintenance of security risk management and reporting processes, including policy exceptions and exemptions.
- Proactively maintain and manage the security risk register and support security risk assessments.
- Ensure cohesive end-to-end analysis, identification, management, and reporting of security risks and issues through cross-collaboration with personnel, physical, and cyber/information security teams; as well as broader teams in Technology and Data, Project Management Office, People and Culture and Procurement.
- Lead the coordination and management of government reporting (e.g., PSPF, E8, response to government directives).
- Develop and maintain the security risk reporting framework, including the implementation and ongoing management of a cyber risk quantification capability.
- Support the CISO by providing regular executive-level reporting on security outcomes, including development of executive papers and data-driven metrics.
- Security Plan and Strategy Management: Contribute to strategic security analysis and planning to enhance the overall security framework, execution of security objectives and resolution of gaps.
- High Performing Team: Proactively contribute to and support broader direct team outcomes.
To work with us, you must be an Australian citizen with eligibility to gain a NV1 clearance through the Australian Government Security Vetting Agency.
About you
- Proven track record in security risk management and reporting.
- Proven track record in maintaining security risk registers and supporting security risk assessments.
- Experience in developing and maintaining security risk reporting frameworks and implementing cyber risk quantification capabilities.
- Experience in providing executive-level reporting, including executive papers and data-driven metrics.
- Experience in coordinating and managing government reporting, such as PSPF and E8.
- Strong knowledge of security risk management principles and practices.
- Strong understanding of security controls and compensating controls.
- Proficiency in risk assessment methodologies and tools.
- Ability to develop and maintain comprehensive security risk reporting frameworks.
- Familiarity with cyber risk quantification techniques e.g. FAIR
About APRA
Australian Prudential Regulation Authority (APRA) was established in 1998 as an independent statutory authority that supervises almost 1,200 financial institutions that manage $8.6 trillion in assets for Australians across the banking, insurance and superannuation sectors.
In overseeing the safety, competitiveness and stability of the financial system, we seek to recruit, develop and retain highly skilled professionals, who want to help shape financial services and protect the financial wellbeing of the Australian community. Our employee base of almost 900 come predominantly from the commercial financial services industry or other government agencies; as such, we have the feel of a small corporate organisation that can work flexibly and with agility.
Why Work for APRA
We recognise the skills, experience and commitment that our staff bring to their professional lives, and we seek to reward them accordingly. We also recognise that for our staff to be able to perform at their best, we need to ensure that they are able to bring their best selves to work. Our commitment to wellbeing is having engaged people supported by resilient leaders within a values-aligned culture.
At APRA, we're committed to providing an inclusive workplace where everyone belongs, feels valued and respected. We aspire to attract and foster diversity of background, thought, and experience, recognising that a broad range of perspectives, approaches and ideas makes us stronger, and better enables us to meet our obligation to protect the financial wellbeing of the Australian community. If you need any adjustments during the recruitment process, please inform at application stage so we can do our best to accommodate your requirements.
-
Senior Security Risk Reporting Specialist
7 days ago
Sydney, New South Wales, Australia Australian Prudential Regulation Authority (APRA) Full time $120,000 - $180,000 per yearThe roleThe Senior Security Risk & Reporting Specialist is a pivotal role responsible for developing, managing, and maintaining the end-to-end security risk management processes. This includes policy exceptions and exemptions, maintaining the security risk register, and supporting security risk assessments. The specialist will develop and maintain a security...
-
Senior Cyber Security Specialist
6 days ago
Sydney, New South Wales, Australia eHealth NSW Full time $147,653 - $175,000 per yearSenior Cyber Security Specialist(Health Manager Level 4)Multiple Opportunities - Temporary Full-Time Exempt for up to 12 monthsOpportunity to work from our modern offices in Chatswood, St Leonards, or CharlestownHybrid flexibility for work-life balanceAttractive salary, $147,653 – $175, % Super and annual leave loadingJoin the team enriching health in...
-
Principal Cyber Security Specialist
20 hours ago
Sydney, New South Wales, Australia Experis Australia Full timeA great opportunity for a Principal Cyber Security Specialist.Location:ACT, QLD and NSWJob type:ContractOrganisation:Federal GovernmentDuties and ResponsibilitiesLeading and conducting risk assessments of agency's internal systems and assessing risk from external connections.Undertaking compliance activities in relation to cyber security standards within the...
-
Senior Security Analyst
23 hours ago
Sydney, New South Wales, Australia Reserve Bank of Australia Full time $100,000 - $140,000 per yearHybrid work environmentPermanent RolePlay an important part shaping the future of our iconic Australian institution.About the RoleThe Reserve Bank of Australia (RBA) is seeking a Senior Security Analyst to join our Cyber Security Delivery team on a permanent basis. This is a unique opportunity to contribute to the Bank's mission by proactively identifying,...
-
Senior Security Analyst
1 day ago
Sydney, New South Wales, Australia Reserve Bank of Australia Full time $120,000 - $180,000 per yearHybrid work environmentPermanent RolePlay an important part shaping the future of our iconic Australian institution.About the RoleThe Reserve Bank of Australia (RBA) is seeking a Senior Security Analyst to join our Cyber Security Delivery team on a permanent basis. This is a unique opportunity to contribute to the Bank's mission by proactively identifying,...
-
Cyber security specialist
6 days ago
Sydney, New South Wales, Australia Pyramid Global Technologies Full time $150,000 - $200,000 per yearJob Description for Cyber Security Specialist in Melbourne/SydneyA minimum of 10 years of experience in cyber security roles within major organizations, focusing on management of governance, risk, and compliance.Relevant industry certification(s) such as CISSP, CISM, CRISC, CISA, ISO/IEC 27001 Lead Implementer/Auditor and/or relevant industry...
-
Senior Reporting Systems Specialist
5 days ago
Sydney, New South Wales, Australia Essential Energy Full time $120,000 - $140,000 per yearJob DescriptionEssential Energy is an organisation that values your voice, empowers your autonomy, recognises the strength in diversity, and prioritises your well-being while offering attractive remuneration and benefits. Take pride in having a meaningful impact on regional, rural and remote communities while being a pivotal player in the energy industry's...
-
Senior Cyber Security Specialist
20 hours ago
Sydney, New South Wales, Australia Helia Full time $120,000 - $180,000 per yearHelia, as Australia's first Lenders Mortgage Insurance (LMI) provider, with over 50 years expertise in the Australian housing market are in the process of re-inventing ourselves.We exist to accelerate financial wellbeing through home ownership, now and for the future. Our mission is to create innovative and tailored solutions in partnership with our...
-
Principal Cyber Security Specialist
22 hours ago
Sydney, New South Wales, Australia Experis AU Full timeA great opportunity for a Principal Cyber Security Specialist.Location: ACT, QLD and NSWJob type: ContractOrganisation: Federal GovernmentDuties and ResponsibilitiesLeading and conducting risk assessments of agency's internal systems and assessing risk from external connections.Undertaking compliance activities in relation to cyber security standards within...
-
Security Risk Manager
22 hours ago
Sydney, New South Wales, Australia Tech Aalto Full time $150,000 - $200,000 per yearSecurity Risk AssuranceRole-The Senior Cyber Security Risk Assurance Lead is hands-on and multi disciplined, assessing complex technical issues and performing cyber security risk assessments across a wide range of initiatives in a fast-paced, complex environment.• Performing cyber security risk assessments across multiple projects.• Collaborating with...