Head of IT Risk and Security

1 day ago


Sydney, New South Wales, Australia AXE Group Full time $120,000 - $200,000 per year

Job Type: Permanent - Full Time

Location: Sydney

Job Category: Information Technology

As the Head of IT Risk and Security at Axe Group, based in Sydney, Hybrid role, you' will be at the forefront of driving excellence in our Internal IT department. This is a permanent, full-time opportunity for a talented leader to make a significant impact in the realm of Information Technology. If you're passionate about championing risk management and fortifying security measures, we invite you to join our dynamic team and play a pivotal role in shaping the future of our IT landscape.

Job Description
The Head of IT Risk and Security is pivotal in protecting Axe Group's internal IT information assets, promoting a culture of risk and compliance awareness.

The role requires being hands on to implement technical solutions as well as working closely with the senior management and IT teams to ensure that security procedures are followed and the relevant protections are put in place.

Responsibility

  • Developing a security strategy to mitigate potential risks
  • Maintain information security policies, standards and procedures
  • Protect against data loss and fraud
  • Ensuring that systems are maintained to address known vulnerabilities
  • Ensure IT and network implementations or modifications are protected through security best practices
  • Promote a culture of risk and compliance awareness throughout the organisation
  • Ensure that our vendors and IT contractors protect our information assets at a level no less than our own standards
  • Manage our clients and prospects security requirements
  • Real-time analysis of immediate threats, and triage of security risks
  • Maintain regulatory compliance to all relevant and applied standards
  • Ensure that the Principle of Least Privilege (PoLP) is implemented across the organisation
  • Follow security best practices to identify, assess, monitor and escalate as appropriate, vulnerabilities and other cyber security threats, balancing priorities, cost vs benefits.
  • Keep up to date with the latest threats and potential mitigations, available tools and compliance requirements within the finance sector and broader security community.

Work Involves

  • Performing security review and approve changes to systems as part of the change control process
  • Maintaining incident response plans, disaster recovery and business continuity plans and ensuring that they are regularly tested;
  • Reviewing security policies, controls and cyber incident response plans;
  • Spot checks of teams and tests to ensure that procedures are being followed;
  • Managing incidents including reviewing investigations after breaches or incidents, including impact analysis and recommendations for avoiding similar vulnerabilities;
  • Maintaining a current understanding of the IT threat landscape for the industry;
  • Identifying, assessing, monitoring and escalating as appropriate cyber security threats;
  • Schedule periodic security audits;
  • Performing security awareness training as well as ongoing communication to staff of cyber security policies and procedures, with more indepth training for those who are non technical staff;
  • Managing all teams, employees, contractors and vendors involved in IT security;
  • Maintaining regulatory compliance to all relevant and applied standards (e.g. SOC2, CPS234 & PCIDSS);
  • Provide training and mentoring to security team members;
  • Constantly update the cyber security strategy to reflect changing laws and applicable regulations, and to leverage new technology and threat information;
  • Communicate best practices and risks to all parts of the business;
  • Complete external risk and security risk questionnaires;
  • Ensure that our vendors and IT contractors are compliant with their risk and security responsibilities;
  • Running monthly risk forums;
  • Ensuring that systems are regularly patched and hardened;
  • Managed the risk management procedures and maintain an up-to-date risk register;
  • Monitor the internal threat detection and protection system and perform hunts for vulnerabilities;
  • Ensure that any security vulnerabilities that have been raised are mitigated, coordinating between stakeholders and technical resources where needed;
  • Perform general duties required to support the running of Axe Group offices.

Desired Skills And Experience
Skills required are:

  • Current CISSP certification required.
  • Demonstrable leadership and mentoring skills within a Cyber Security function
  • Experience implementing and maintaining compliance to CPS234, SOC2 and PCI DSS.
  • Experience conducting risk assessments to industry standards and dealing with third parties
  • Ability to design, implement and execute Security Controls
  • Encryption/data protection methods (SSL) and technical implementation of Encryption standards
  • Experience engaging with internal and external stakeholders on compliance, security and governance issues
  • A calm and positive demeanor, particularly in times of urgent and competing priorities
  • Experience in writing and imbedding Security Policies and Standards
  • Experience in managing security Incident Responses
  • Hands on technical skills in security technologies are highly desirable – vulnerability management, threat hunting, SIEM, SAML, WAF
  • Good verbal and written communication skills
  • Can work independently, and can positively influence others

Other Desirable Skills

  • Experience in the finance industry
  • ITILV3 and security certifications such as CRISC, CCSP and CGEIT
  • Experience with Elastic Stack


  • Sydney, New South Wales, Australia Kinetic IT Full time $120,000 - $250,000 per year

    About The RoleWant to shape the future of security services at Kinetic IT?This is an exciting opportunity to lead, expand, and manage our Cyber Security Practice. We're looking for a forward-thinking leader to design, grow, and deliver a fully functional and scalable security practice that drives innovation, resilience, and measurable outcomes for our...

  • Head of Risk

    1 week ago


    Sydney, New South Wales, Australia Australian Nuclear Science and Technology Organisation Full time $120,000 - $180,000 per year

    Company description: ANSTOJob description: Position OverviewOngoing | Full Time | Salary commensurate with experience | 15.4% superSutherland Shire location I Flexible Work practices I Health & Wellbeing ProgramsOnsite Childcare for Employees | Cafe on site | generous leave provisions | free parkingA unique opportunity to join one of Australia's leading...


  • Sydney, New South Wales, Australia Skylight Cyber Security Full time $120,000 - $180,000 per year

    About Skylight CyberAt Skylight Cyber, we're young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are...

  • Head of Risk

    3 days ago


    Sydney, New South Wales, Australia Altogether Group Pty Ltd Full time $104,000 - $130,878 per year

    Head of Risk & Compliance – Build Resilience. Enable Growth.At Altogether, we're shaping the future of energy and water services — and we need a Head of Risk & Compliance who sees compliance not as a box-tick, but as a driver of trust, resilience, and growth.In this role, you'll own and evolve our risk and compliance frameworks, ensuring we meet...


  • Sydney, New South Wales, Australia Australian Concert and Entertainment Security Full time $60,000 - $90,000 per year

    We are seeking experienced and professional Casual Security Officers to join our team, providing high-end security services for VIP functions, corporate events, and premium venues. This is an exciting opportunity for polished and reliable security professionals who take pride in their presentation, professionalism, and ability to deliver an exceptional...

  • Security Site Manager

    2 weeks ago


    Sydney, New South Wales, Australia MSS Security Full time $120,000 - $150,000 per year

    About the CompanyAs one of Australia's leading security companies, MSS Security is built on teamwork, respect, and integrity. We provide long-term career paths, stability, and a workplace where your professionalism and dedication are genuinely valued. To find out more visit our website at.Great Work-Life Balance: Monday–Friday, 8:00 am– 4:00...

  • Security Operations

    2 weeks ago


    Sydney, New South Wales, Australia Australian Concert and Entertainment Security Full time $90,000 - $120,000 per year

    Affirm Training is a leading Registered Training Organisation (RTO), delivering a wide range of nationally recognised courses and industry-specific training. We support professionals and businesses across the corporate, facilities management, construction, arts, recreation, and entertainment sectors.We're currently seeking a motivated and qualified Security...


  • Sydney, New South Wales, Australia Tech Aalto Full time $150,000 - $200,000 per year

    Security Risk AssuranceRole-The Senior Cyber Security Risk Assurance Lead is hands-on and multi disciplined, assessing complex technical issues and performing cyber security risk assessments across a wide range of initiatives in a fast-paced, complex environment.• Performing cyber security risk assessments across multiple projects.• Collaborating with...


  • Sydney, New South Wales, Australia Cuscal Limited Full time

    Get AI-powered advice on this job and more exclusive features.Company DescriptionEmpower Australia's Payments Future with CuscalAt Cuscal, your skills drive change and make a real impact. Whether you're supporting our clients' customers in our Fraud Operations Contact Centre or delivering innovative solutions in Product Delivery, your contribution helps...

  • Security Guard

    4 days ago


    Sydney, New South Wales, Australia Australian Concert and Entertainment Security Full time $60,000 - $90,000 per year

    Permanent Role: Full-time positions with stability in high-profile Sydney universities or public precincts.Training & Development: Ongoing upskilling through our in-house Registered Training Organisation (RTO).Prime Locations: Work at a single site, either a university campus or a public precinct, providing focus and consistency in your patrol duties.As an...