Cyber Governance

1 day ago


Sydney, New South Wales, Australia ASX Full time $120,000 - $180,000 per year
ASX: Powering Australia's financial marketsWhy join the ASX?

When you join ASX, you're joining a company with a strong purpose – to power a stronger economic future by enabling a fair and dynamic marketplace for all.

In your new role, you'll be part of a leading global securities exchange with a strong brand. We are known for being a trusted market operator and an exciting data hub. 

Want to know why we are a great place to work, click on the link to learn more.

We are more than a securities exchange

The ASX team brings together talented people from a diverse range of disciplines. 

We run critical market infrastructure, with 1 in 3 people employed within technology.  Yet we have a unique complexity of roles across a range of disciplines such as operations, program delivery, financial products, investor engagement, risk and compliance.

We're proud of the diversity of our organisation and the culture of inclusion that all our people help to build every day. Our employee-led groups are known for celebrating cultural and religious events, championing LGBTIQ+ inclusion (recently achieving AWEI Bronze), inspiring giving and volunteering, promoting gender equality, and wellbeing.  We are an Employer of Choice for Gender Equality (WGEA) and a member of the Champions of Change Coalition for the advancement of gender equality in Australia. 

Your responsibilities:

  • Support the uplift and documentation of Cyber Security controls in line with best practice frameworks including NIST, focusing on key domains such as Identity & Access Management, Detection & Monitoring, and Vulnerability Management.

  • Partner with cyber SMEs to assess, plan, remediate and uplift IT General Controls, including strengthening definitions, evidence requirements and reporting.

  • Develop and maintain cyber governance dashboards and metrics to demonstrate compliance to cyber security requirements and obligations against key control domains (e.g. patching, vulnerability management, identity).

  • Consolidate and analyse technical data from sources such as vulnerability scanners, CMDB, and Identity systems to identify compliance gaps and emerging trends.

  • Translate technical data into clear, visual insights for different audiences including IT service owners, senior management and risk committees using tools such as Power BI, Tableau or advanced Excel.

  • Prepare assurance, audit and regulatory artefacts by coordinating high-quality evidence and reporting packs.

  • Support uplift of automated reporting and integration into the risk system, Service Now and other data platforms to enhance transparency of cyber health.

  • Maintain documentation repositories, exception registers and data sources to ensure traceability and version control across governance artefacts.

  • Identify opportunities to automate and streamline cyber reporting, metrics and control-related data flows.

Must have:

  • 5–8 years' experience in cyber or technology governance, risk, compliance or assurance roles, with exposure to data-driven reporting and metrics.

  • Working knowledge of cyber control domains such as identity and access management, detection and monitoring, patching and vulnerability management.

  • Good understanding of frameworks and standards (e.g. NIST CSF, ISO 27001, ASDE8, CPS 234, COBIT).

  • Demonstrated ability to analyse and visualise technical data using tools such as Power BI, Tableau or advanced Excel.

  • Good written and verbal communication skills, including the ability to translate technical or complex data into insights for technical and non-technical audiences.

  • Proven ability to manage multiple governance artefacts (e.g. control registers, pen testing findings, exceptions log, dashboards, evidence) with attention to accuracy and version control.

  • Skilled in coordination, reporting and stakeholder engagement across technical and risk functions.

Nice to have:

  • Experience supporting or reporting on IT General Controls (ITGCs) or control effectiveness outcomes.

  • Familiarity with enterprise risk systems and their data structures.

  • Exposure to data integration or automation between systems such as CMDB, vulnerability management, and reporting tools.

  • Experience developing or enhancing cyber, technology or risk dashboards.

  • Knowledge of data storytelling or visual communication principles to convey risk posture and control effectiveness.

  • Professional certifications such as CISA, CRISC, CISSP, or ITIL.

  • Experience working in a regulated or audited technology environment (e.g. financial services, critical infrastructure)

We make hiring decisions based on your skills, capabilities and experience, and how you'll help us to live our values. We encourage you to apply even if you don't meet all the criteria of this role. If you need any adjustments during the application or interview process to help you present your best self, please let us know.

At ASX Group, our diverse workforce is essential to build and maintain a fair and dynamic marketplace. We support flexible working and offer hybrid working options. Even if our roles are advertised as full-time, we encourage you to apply if you are interested in part-time or other flexible working arrangements.

We will arrange for successful candidates to have background checks, including reference and police checks completed as part of the on-boarding process.



  • Sydney, New South Wales, Australia AI Talent Full time $70,000 - $120,000 per year

    About the RoleWe are seeking an experienced Cyber Governance, Risk, and Compliance (GRC) Specialist to lead the implementation and continuous improvement of our organisation's cybersecurity governance framework. This position is pivotal in ensuring that our systems, data, and infrastructure adhere to internal policies and external regulatory obligations,...


  • Sydney, New South Wales, Australia Department of Creative Industries, Tourism, Hospitality and Sport Full time $149,739 - $173,174 per year

    Join our Technical and Operations, a division within the Department of Creative Industries, Tourism, Hospitality and SportClerk Grade 11/12 with a salary range of $149,739 - $173,174 per annum plus superannuationTemporary, Full-time role until 30 June 2026, based in Sydney, NSWPossibility of extension or becoming permanent for the right candidate.About the...


  • Sydney, New South Wales, Australia Commonwealth Bank Full time $120,000 - $180,000 per year

    Senior Manager Group Cyber Governance and ComplianceYou are a passionate cybersecurity risk professional with strong expertise in governance, risk and complianceWe are one of the best and most advanced Cyber Security teams in AustraliaTogether we can contribute to protecting the Group, its customers and community from current and evolving cyber threats.See...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time $120,000 - $180,000 per year

    Senior Manager Group Cyber Governance and Compliance You are a passionate cybersecurity risk professional with strong expertise in governance, risk and compliance We are one of the best and most advanced Cyber Security teams in Australia Together we can contribute to protecting the Group, its customers and community from current and evolving cyber...


  • Sydney, New South Wales, Australia Commonwealth Bank Full time $100,000 - $150,000 per year

    Manager Cyber Control GovernanceYou are a problem solver with a strong background in Cyber Security risk and governance.We are one of the best and most advanced Cyber Security teams in Australia.Together we can contribute to protecting the Group, its customers and community from current and evolving cyber threats.See yourself in our team:Our Cyber Security...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time $150,000 - $200,000 per year

    Job Description for Cyber Security Specialist in Melbourne/SydneyA minimum of 10 years of experience in cyber security roles within major organizations, focusing on management of governance, risk, and compliance.Relevant industry certification(s) such as CISSP, CISM, CRISC, CISA, ISO/IEC 27001 Lead Implementer/Auditor and/or relevant industry...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time $120,000 - $180,000 per year

    Job Description:A minimum of 10 years of experience in cyber security roles within major organisations, focusing on management of governance, risk, and compliance.Relevant industry certification(s) such as CISSP, CISM, CRISC, CISA, ISO/IEC 27001 Lead Implementer/Auditor and/or relevant industry experienceComprehensive understanding of industry-wide security...

  • Penetration Tester

    2 days ago


    Sydney, New South Wales, Australia Vanguard Cyber Full time $80,000 - $120,000 per year

    Company DescriptionVanguard Cyber is a quality-driven Australian cybersecurity consultancy dedicated to providing technically sound and impactful solutions. Our mission is to make cybersecurity accessible, effective, and uncompromising in quality for businesses of all sizes across diverse industries. With a focus on building confidence, we deliver services...


  • Sydney, New South Wales, Australia NSW Government Full time $113,574 - $125,720 per year

    Role: Cyber Security Data AnalystRole type: 2 years temporary full-time opportunitySalary: DCS Clerk Grade 7/8, annual base salary starting at ($113,574 - $125,720) plus employer's contribution to superannuation and annual leave loadingLocation: Sydney (Hybrid working arrangements may be available)About Us:The Department of Customer Service (DCS) is...


  • Sydney, New South Wales, Australia NSW Department of Customer Service Full time $113,574 - $125,720 per year

    Role:Cyber Security Data AnalystRole type:2 years temporary full-time opportunitySalary:DCS Clerk Grade 7/8, annual base salary starting at ($113,574 - $125,720) plus employer's contribution to superannuation and annual leave loadingLocation:Sydney (Hybrid working arrangements may be available)About Us:The Department of Customer Service (DCS) is transforming...