Head of IT Risk and Security

12 hours ago


Sydney, New South Wales, Australia AXE Group Full time $120,000 - $200,000 per year

Job Type: Permanent - Full Time

Location: Sydney

Job Category: Information Technology

As the Head of IT Risk and Security at Axe Group, based in Sydney, Hybrid role, you' will be at the forefront of driving excellence in our Internal IT department. This is a permanent, full-time opportunity for a talented leader to make a significant impact in the realm of Information Technology. If you're passionate about championing risk management and fortifying security measures, we invite you to join our dynamic team and play a pivotal role in shaping the future of our IT landscape.

Job Description
The Head of IT Risk and Security is pivotal in protecting Axe Group's internal IT information assets, promoting a culture of risk and compliance awareness.

The role requires being hands on to implement technical solutions as well as working closely with the senior management and IT teams to ensure that security procedures are followed and the relevant protections are put in place.

Responsibility

  • Developing a security strategy to mitigate potential risks
  • Maintain information security policies, standards and procedures
  • Protect against data loss and fraud
  • Ensuring that systems are maintained to address known vulnerabilities
  • Ensure IT and network implementations or modifications are protected through security best practices
  • Promote a culture of risk and compliance awareness throughout the organisation
  • Ensure that our vendors and IT contractors protect our information assets at a level no less than our own standards
  • Manage our clients and prospects security requirements
  • Real-time analysis of immediate threats, and triage of security risks
  • Maintain regulatory compliance to all relevant and applied standards
  • Ensure that the Principle of Least Privilege (PoLP) is implemented across the organisation
  • Follow security best practices to identify, assess, monitor and escalate as appropriate, vulnerabilities and other cyber security threats, balancing priorities, cost vs benefits.
  • Keep up to date with the latest threats and potential mitigations, available tools and compliance requirements within the finance sector and broader security community.

Work Involves

  • Performing security review and approve changes to systems as part of the change control process
  • Maintaining incident response plans, disaster recovery and business continuity plans and ensuring that they are regularly tested;
  • Reviewing security policies, controls and cyber incident response plans;
  • Spot checks of teams and tests to ensure that procedures are being followed;
  • Managing incidents including reviewing investigations after breaches or incidents, including impact analysis and recommendations for avoiding similar vulnerabilities;
  • Maintaining a current understanding of the IT threat landscape for the industry;
  • Identifying, assessing, monitoring and escalating as appropriate cyber security threats;
  • Schedule periodic security audits;
  • Performing security awareness training as well as ongoing communication to staff of cyber security policies and procedures, with more indepth training for those who are non technical staff;
  • Managing all teams, employees, contractors and vendors involved in IT security;
  • Maintaining regulatory compliance to all relevant and applied standards (e.g. SOC2, CPS234 & PCIDSS);
  • Provide training and mentoring to security team members;
  • Constantly update the cyber security strategy to reflect changing laws and applicable regulations, and to leverage new technology and threat information;
  • Communicate best practices and risks to all parts of the business;
  • Complete external risk and security risk questionnaires;
  • Ensure that our vendors and IT contractors are compliant with their risk and security responsibilities;
  • Running monthly risk forums;
  • Ensuring that systems are regularly patched and hardened;
  • Managed the risk management procedures and maintain an up-to-date risk register;
  • Monitor the internal threat detection and protection system and perform hunts for vulnerabilities;
  • Ensure that any security vulnerabilities that have been raised are mitigated, coordinating between stakeholders and technical resources where needed;
  • Perform general duties required to support the running of Axe Group offices.

Desired Skills And Experience
Skills required are:

  • Current CISSP certification required.
  • Demonstrable leadership and mentoring skills within a Cyber Security function
  • Experience implementing and maintaining compliance to CPS234, SOC2 and PCI DSS.
  • Experience conducting risk assessments to industry standards and dealing with third parties
  • Ability to design, implement and execute Security Controls
  • Encryption/data protection methods (SSL) and technical implementation of Encryption standards
  • Experience engaging with internal and external stakeholders on compliance, security and governance issues
  • A calm and positive demeanor, particularly in times of urgent and competing priorities
  • Experience in writing and imbedding Security Policies and Standards
  • Experience in managing security Incident Responses
  • Hands on technical skills in security technologies are highly desirable – vulnerability management, threat hunting, SIEM, SAML, WAF
  • Good verbal and written communication skills
  • Can work independently, and can positively influence others

Other Desirable Skills

  • Experience in the finance industry
  • ITILV3 and security certifications such as CRISC, CCSP and CGEIT
  • Experience with Elastic Stack

  • Head of Security

    2 days ago


    Sydney, New South Wales, Australia World Rugby Full time $120,000 - $180,000 per year

    Closing date for applications is Tuesday 11 November 2025Full time Fixed Term Contract until November 2027Location: Sydney (Gadigal), AustraliaThe Rugby World Cup (RWC) Australia is proud to deliver one of the world's most iconic sporting events — the Rugby World Cup 2027 (Men's). More than a tournament, it's a celebration of Rugby's spirit, Australia's...

  • Head of Risk

    2 days ago


    Sydney, New South Wales, Australia Altogether Group Pty Ltd Full time $104,000 - $130,878 per year

    Head of Risk & Compliance – Build Resilience. Enable Growth.At Altogether, we're shaping the future of energy and water services — and we need a Head of Risk & Compliance who sees compliance not as a box-tick, but as a driver of trust, resilience, and growth.In this role, you'll own and evolve our risk and compliance frameworks, ensuring we meet...


  • Sydney, New South Wales, Australia Skylight Cyber Security Full time

    About Skylight CyberAt Skylight Cyber, we're young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are...

  • Head of Credit Risk

    14 hours ago


    Sydney, New South Wales, Australia Taylor Root Full time $150,000 - $250,000 per year

    Head of Credit Risk – Fintech | Non-Banking LenderJoin a high growth fintech reshaping the non-bank lending landscape. Our client is recruiting a strategic Head of Credit Risk to lead its risk function as Chief Risk Officer and drive robust governance across credit, operational, and regulatory domains.This is a pivotal leadership role for someone with deep...


  • Sydney, New South Wales, Australia Tech Aalto Full time $150,000 - $200,000 per year

    Security Risk AssuranceRole-The Senior Cyber Security Risk Assurance Lead is hands-on and multi disciplined, assessing complex technical issues and performing cyber security risk assessments across a wide range of initiatives in a fast-paced, complex environment.• Performing cyber security risk assessments across multiple projects.• Collaborating with...


  • Sydney, New South Wales, Australia Australian Concert and Entertainment Security Full time $60,000 - $90,000 per year

    We are seeking experienced and professional Casual Security Officers to join our team, providing high-end security services for VIP functions, corporate events, and premium venues. This is an exciting opportunity for polished and reliable security professionals who take pride in their presentation, professionalism, and ability to deliver an exceptional...

  • Security Operations

    1 week ago


    Sydney, New South Wales, Australia Australian Concert and Entertainment Security Full time $90,000 - $120,000 per year

    Affirm Training is a leading Registered Training Organisation (RTO), delivering a wide range of nationally recognised courses and industry-specific training. We support professionals and businesses across the corporate, facilities management, construction, arts, recreation, and entertainment sectors.We're currently seeking a motivated and qualified Security...

  • Security Site Manager

    2 weeks ago


    Sydney, New South Wales, Australia MSS Security Full time $120,000 - $150,000 per year

    About the CompanyAs one of Australia's leading security companies, MSS Security is built on teamwork, respect, and integrity. We provide long-term career paths, stability, and a workplace where your professionalism and dedication are genuinely valued. To find out more visit our website at.Great Work-Life Balance: Monday–Friday, 8:00 am– 4:00...

  • Security Patrol

    2 weeks ago


    Sydney, New South Wales, Australia Australian Concert and Entertainment Security Full time $60,000 - $180,000 per year

    What We OfferPermanent Opportunity: Secure a full-time role with room to grow.Training & Upskilling: Advance your career with support from our in-house RTO.Prime Locations: Work at some of Sydney's most exciting venues.Your ResponsibilitiesAs a Security Ranger, your role will combine customer service, public safety, and asset protection. Key duties...

  • Head of Credit Risk

    2 weeks ago


    Sydney, New South Wales, Australia Tyro Payments Full time $120,000 - $180,000 per year

    Why Tyro?At Tyro, we're into business big time. Through our integrated payments, banking and lending solutions, we're here to ensure nothing stands in the way of Australian business success. With over 21 years' experience under our belt, we know what it takes to build something great, which is why we combine the best people, technology, and partners to...