Regional Cybersecurity Risk Manager

7 days ago


Canberra, ACT, Australia Kbr Full time

**Title**:
Regional Cybersecurity Risk Manager

**The Company**

From individual technologies and services to comprehensive project delivery and mission execution, no other company can match the breadth and depth of KBR. Our strength as an Australian company is demonstrated through more than 60 years of successful project and solution delivery.

Headquartered in Canberra, KBR comprises a diverse team who provide a broad spectrum of capabilities across Australia and the Asia Pacific. Our proven project teams readily address complex and multi-disciplinary activities, providing a low-risk and cost-effective service to our customers.

Our combined experience and expertise delivers the right solutions, technology and equipment at the right time.

**The Role**

The APAC Regional Cybersecurity Risk Manager is a key role responsible for the overall management and implementation of information security programs within KBR's APAC operating locations. The APAC Cybersecurity Risk Manager ensures the confidentiality, integrity, and availability of the organization's information assets and protects against unauthorized access, disclosure, alteration, and destruction. The APAC Cybersecurity Risk Manager reports directly to the Chief Information Security Officer (CISO). This position is based in Australia. **Applicant must be eligible to obtain Australia Government Level Security Clearance.**

Key Responsibilities:
1. Information Security Strategy and Governance: Develop and implement regional information security strategy, in alignment with KBR corporate policy, regional regulations, business objectives and industry best practices. Establish and maintain regional information security policies, standards, and procedures. Collaborate with executive leadership and stakeholders to ensure security goals are integrated into business processes and decision-making.

2. Risk Management and Compliance: Conduct regular risk assessments to identify security vulnerabilities and threats, both internal and external. Develop and implement regional risk mitigation strategies and security controls to reduce identified risks. Monitor compliance with applicable laws, regulations, and contractual obligations related to information security.

3. Incident Response and Management: Conduct post-incident analysis to identify lessons learned and implement improvements to prevent future incidents.

4. Security Awareness and Training: Develop and deliver region-specific security awareness and training programs for employees, contractors, and third-party partners. Promote a culture of security consciousness and ensure employees understand their roles and responsibilities in protecting information assets. Stay updated with emerging security threats and educate stakeholders on security best practices.

5. Vendor and Third-Party Risk Management: Assess and manage security risks associated with third-party vendors and partners. Conduct due diligence on vendors' security practices and contractual obligations. Collaborate with procurement and legal teams to include appropriate security clauses in contracts and agreements.

6. Security Incident Reporting and Metrics: Develop and maintain security metrics and reporting mechanisms to monitor the effectiveness of security controls and identify areas for improvement. Regularly report to CISO, business leadership and stakeholders on the regional security posture, incidents, and key security metrics.

7. Security Audits and Assessments: Coordinate and participate in security audits and assessments conducted by internal or external parties. Address audit findings, implement corrective actions, and ensure ongoing compliance with audit requirements.

**Required Qualifications, Experience and Knowledge**
- Bachelor's degree in computer science, information systems, or a related field (advanced degree preferred).
- Must be eligible to attain Australia Government Level security clearance
- Extensive knowledge of information security principles, practices, technologies, and regulatory requirements.
- Proven experience in information security management, risk assessment, and incident response.
- Strong analytical and problem-solving skills.
- Excellent communication and interpersonal skills to effectively engage with stakeholders at all levels.
- Leadership abilities to drive security initiatives, influence decision-making, and foster a culture of security awareness.
- Up-to-date knowledge of emerging security threats and trends.
- Familiarity with security frameworks and standards such as ISO 27001, NIST Cybersecurity Framework. Must demonstrate understanding of Australia Essential 8 Maturity Model, Information Security Manual, and Australia Defense Information Security Program (DISP).
- Relevant certifications such as CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) or equivalent are desired.

**Benefits of KBR**

KBR is committed to supporting the profession



  • Canberra, ACT, Australia beBeeCybersecurity Full time

    Cybersecurity Risk Advisor RoleWe are seeking a skilled Cybersecurity Risk Advisor to join our team in Canberra.Key Responsibilities:Building Capacity and Staff Development: Provide technical guidance and support to staff within the TSRS section and Risk Assessment Branch to enhance their knowledge and skills.Compliance and Risk Assessment: Contribute to the...


  • Canberra, ACT, Australia beBeeCybersecurity Full time $120,000 - $140,000

    Job Title: Cybersecurity Risk ManagerAbout the RoleThis is a highly specialized position that involves undertaking ICT security assessments of classified systems in accordance with internal requirements.Key Responsibilities:Conduct thorough assessments to evaluate the effectiveness of security controls for a system and its operating environment;Produce...


  • Canberra, ACT, Australia beBeeCybersecurity Full time $80,000 - $150,000

    Cybersecurity Risk SpecialistWe are seeking an experienced Cybersecurity Risk Specialist to join our team in Canberra. The ideal candidate will have expertise in building capacity and supporting staff development of relevant technical knowledge and skills within the Technical Security Risk Section (TSRS) and Risk Assessment Branch.Develop best practice...


  • Canberra, ACT, Australia beBeeCyberSecurity Full time $150,000 - $180,000

    Job SummaryWe are seeking a cybersecurity professional to fill the role of Cyber Security Consultant. The successful candidate will be responsible for conducting risk assessments at the technical or system process level, delivered through the assessment of systems for compliance against defined security control frameworks.Key Responsibilities:Drafts...


  • Canberra, ACT, Australia beBeeCybersecurity Full time $90,000 - $125,000

    Cybersecurity Risk SpecialistWe are seeking a highly skilled Cybersecurity Risk Specialist to join our Federal Government client in Canberra.Develop and maintain the technical knowledge and skills of staff within the Threat and Risk Services section and Risk Assessment Branch.Contribute to the development of best practice guidelines for assessing security...


  • Canberra, ACT, Australia beBeeCybersecurity Full time $95,000 - $125,000

    Cybersecurity Risk Advisor">Job Description:We are seeking a skilled professional to assume the role of Cybersecurity Risk Advisor in Canberra. The selected candidate will be responsible for building capacity and supporting staff development within the Technical Security Risk Section (TSRS) and Risk Assessment Branch.">Key Responsibilities:">Building...


  • Canberra, ACT, Australia beBeeCybersecurity Full time $120,000 - $180,000

    Job Opportunity: Cybersecurity Risk ManagerThe organization seeks a seasoned cybersecurity professional to lead information security programs in the Asia Pacific region.Develop and implement regional information security strategy, aligning with corporate policy, regulatory requirements, business objectives, and industry best practices.Conduct regular risk...


  • Canberra, ACT, Australia IT Alliance Australia Full time

    One of our Federal Government clients is looking for a Cybersecurity Risk Advisor in Canberra.We are seeking candidates with the following Skills/Experience: Building capacity and supporting staff development of relevant technical knowledge and skills within the TSRS section and Risk Assessment Branch.Contributing to the development of best practice...


  • Canberra, ACT, Australia IT Alliance Australia Full time

    One of our Federal Government clients is looking for a Cybersecurity Risk Advisor in Canberra.We are seeking candidates with the following Skills/Experience:Building capacity and supporting staff development of relevant technical knowledge and skills within the TSRS section and Risk Assessment Branch.Contributing to the development of best practice...


  • Canberra, ACT, Australia IT Alliance Australia Full time

    One of our Federal Government clients is looking for a Cybersecurity Risk Advisor in Canberra.We are seeking candidates with the following Skills/Experience:- Building capacity and supporting staff development of relevant technical knowledge and skills within the TSRS section and Risk Assessment Branch.- Contributing to the development of best practice...