Head of Cyber Security and IT Risk

Found in: Talent AU C2 - 2 weeks ago


Sydney, Australia LGT Crestone Full time

Your team

  • Working as a part of the Risk, Legal & Compliance team with overall responsibility to drive all strategic and operational cyber security and IT risk functions.
  • Working alongside the Head of Technology, senior business and risk executives and project management team within the reporting structure of the Chief Risk Officer.

You will be supported by 2 staff members operating in the following roles: Senior Cyber Security Consultant and Cyber Security Analyst. 
 

Your Role

Cyber Security Governance

  • Maintain a lean and effective cyber and technology risk governance structure, ensuring that risk management is deeply embedded into strategic business projects and operational decision-making. 
  • Ensure the business maintains an effective and agile cyber security policy framework that is aligned with LGT Group directives. 
  • Develop and manage the cyber security budget for all operational and strategic spend, ensuring resource allocation prioritises areas of high-risk and strategic importance. 
  • Establish and maintain a detailed cyber assurance program (including targeted reviews, supplier assurance, red teaming, penetration testing, disaster recovery testing, etc.) to identify and prioritise key gaps for remediation. 
  • Produce and present high-quality cyber risk reports to executive committees and board of directors (locally and at Group level), educating senior executives and the board on material risks, regulatory compliance, and strategic risk mitigation initiatives. 
  • Maintain a strong Line-2 assurance framework challenging the design and operations of the technology function, specifically ensuring the business adheres to GS007 control framework. 
  • Actively participate in monthly and quarterly vendor executive governance meetings — ensuring key suppliers meet contractually agreed KPIs and constantly adjust controls to mitigate emerging risks. 
  • Track audit findings and recommendations to ensure appropriate critical and high-rated issues are promptly addressed. Proactively engage internal and external auditors to identify synergies and avoid redundant reviews.

Stakeholder Management 

  • Develop and nurture relationships with key internal stakeholders, specifically executives, technology, risk management, legal, audit and HR management teams to create a shared sense of purpose and positive working culture. 
  • Liaise with external stakeholders, such as law enforcement, external auditors, advisory bodies, institutional clients, and business partners, as necessary, to ensure that the business maintains a resilient posture and promptly adjusts controls in line with emerging threats.

Strategy Execution

  • Develop and deliver a high-impact cyber resilience strategy that is measurable, scalable, and advances strategic business goals. 
  • Ensure the business maintains a robust enterprise security architecture framework, ensuring that new systems are secure by design, fault-tolerant and architected in-line with industry reference standards.
  • Actively collaborate with the Group CISO and their leadership team to identify opportunities to integrate local capabilities with the Group, ensuring consistency and strategic alignment. 
  • Negotiate vendor contracts to ensure the business invests in cost-effective and highly scalable solutions. 
  • Maintain a lean and effective cyber security team through ongoing mentorship, training, and maintaining a fine balance between outsourced and insourced capabilities. 
  • Stay abreast with key cyber security threats and regulatory changes and work with relevant stakeholders to adapt the cyber security strategy accordingly. 

Incident Response

  • Lead incident response, ensuring prompt containment, assessment, and remediation of key incidents. Conduct root cause analysis and implement corrective actions to prevent recurrence. 
  • Lead executive/board cyber crisis response simulations and drive the remediation of key issues identified. 

Security Operations

  • Work with outsourced providers and internal teams to ensure the business maintains a highly tuned and effective 24/7 security operations centre that prioritises threats on the business’s most valuable digital assets. 
  • Ensure the technology team and outsourced vendors maintain effective cyber security operational hygiene, including access management, backups, vulnerability management, patching and systems hardening. 
     

Your skills & experience

  • 10+ years of IT work experience, with at least 6+ years in leadership position overseeing cyber security teams or key projects and influencing decision makers. 
  • Proven leadership skills and the ability to work effectively with stakeholders, financial management, leading teams and executing complex change. 
  • Exceptional communications skills, with the ability to communicate with staff at various levels, both technical and clear business terms, regarding complex strategic projects. 
     

Your role competencies

  • Strong communication skills
  • Resourceful, self-starter/driven
  • Resilient
  • Pragmatic 
  • Good judgment and the highest integrity and ethics
  • Collaborative
  • Good attention to detail
  • Flexible
     

Your qualifications

  • Bachelor or masters degree in Cyber Security, Information Security, or a related field (or equivalent experience).
  • Industry certifications such as CISSP, CISM, CISA, or other relevant certifications.
     


  • Sydney, Australia Nuix Careers Full time

    Nuix creates innovative software that empowers organisations to simply and quickly find the truth from any data in a digital world. We are a passionate and talented team, delighting our customers with software that transforms data into actionable intelligence. We collaborate to provide innovative solutions for more than 2,000 customers in over 75 countries....

  • Cyber Sec Gov

    3 days ago


    Sydney, Australia University of New South Wales Full time

    **Job no**: 523893 **Work type**: full time **Location**: Sydney, NSW **Categories**: Information Technology - Employment: Full time (35 hours per week) - Duration: Continuing - Remuneration: Excellent salary package including leave loading and generous superannuation - Location: Based in Kensington, Sydney (hybrid working available) **About UNSW...

  • Cyber Risk Manager

    21 hours ago


    Sydney, Australia Allianz Australia Full time

    **CYBER RISK MANAGER - RISK AND COMPLIANCE MANAGER | SYDNEY, NSW** At Allianz, we’re proud to be one of the world’s leading insurance and asset management brands, with a workforce as diverse as the world around us. We care about our customers, which is why we hire the very best people to further our commitment to securing the future of our customers,...


  • Sydney, Australia Security Centric Full time

    **Location**: Sydney **Division**: Service Delivery - Advise and shape client cyber security journeys - Reporting to a Managing Director that wants to hear and support your ideas Lead a skilled team delivering services and solutions across projects and long-term managed services clients. About us Not all cybersecurity consultancies are alike. At Security...


  • Sydney, Australia NSW Government -Department of Customer Service Full time

    **Cyber Security Advisor (Training & Resilience Stream)** - ** Role type**: Ongoing, full-time opportunity - ** Salary**: DCS Clerk Grade 7/8, annual base salary starting at $101,947 plus employer’s contribution to superannuation and annual leave loading - ** Location**:Sydney **About Us**: The Department of Customer Service (DCS) is transforming the way...


  • Sydney, Australia NSW Government -Department of Customer Service Full time

    **Role: Cyber Security Analyst Roles** **Grade: Ongoing - Grade 7/8** **Location: Sydney or Bathurst** ***Role Type: Full Time Permanent** **About the Role** Cyber Security NSW is looking for a Cyber Security Analyst, focusing on incident response, to join our Intelligence and Response Team. The Intelligence and Response Team leads and coordinates...


  • Sydney, Australia Association of Independent Schools of NSW Full time

    **Location**: AISNSW Employment Type: FT - Full-Time Temporary Department: Technology Closing Date: 22/02/2023 A wonderful career opportunity for a highly skilled, motivated security professional to become a trusted advisor in cyber security functions to over 500 independent schools across NSW by joining the Association of Independent Schools of NSW...

  • Cyber Security Lead

    2 days ago


    Sydney, Australia Protecht Group Full time

    Protecht is redefining the way the world thinks about risk. Our cloud-based SaaS platform - Protecht.ERM - is what makes us really stand out. It’s one of the most comprehensive, flexible and dynamic risk management solutions available today. **Join us at Protecht!** We are seeking an exceptional Cyber Security professional with a commercial focus with...


  • Sydney Central Business District, Australia Clicks IT Recruitment Full time

    Initial Contract until April of 2024 Payrate - $800-1000 per day Exc Super We are seeking an experienced Cyber Security Analyst to one of our public-sector clients. As a Senior Cyber Security Analyst, you will play a crucial role in our client's Cyber Uplift program, aimed at improving the compliance and maturity of the client and its cluster agencies. This...


  • Sydney, Australia Genesis IT&T Pty Ltd Full time

    **Permanent Full Time**: - **Global Technology Company**: - **Remote / Hybrid working arrangement** A leading global technology company is currently looking to hire an experienced Information Security Consultant to be responsible for providing risk assessments, security advice and guidance for their key government clients based in Sydney NSW. You will be...


  • Sydney, Australia NSW Government -Department of Customer Service Full time

    **Principal Advisor, Cyber Security (Awareness Stream)** - ** Role type**: On-going, full-time opportunity - ** Salary**:DCS Clerk Grade 11/12, annual base salary starting at $134,411 plus employer’s contribution to superannuation and annual leave loading - ** Location**: Sydney **About Us**: The Department of Customer Service (DCS) is transforming the...


  • Sydney, Australia Aon Full time

    **Job Description**: - Key leadership opportunity for a senior Cyber specialist - Work across an enviable portfolio for our Australian operations - Join one of Australia’s leading Cyber Risk solutions provider **Cyber Risk Consultant** You will be an integral component of the Cyber Solutions Group, working closely with the Cyber Insurance Practice...


  • North Sydney, Australia Soprano Design Full time

    **About the role**: Soprano is seeking a highly experienced and strategic Head of Information Security to lead and manage the Group’s overall Cyber Security program. The role will be responsible for coordinating and overseeing the integration of Cyber Security across our global teams, ensuring the ongoing protection of our information assets and compliance...


  • Sydney, Australia Cuscal Full time

    **Company Description** Cuscal - where curiosity and expertise are rewarded.** Be part of a smaller team taking on a bigger role - a role where your curiosity, your energy, your ambition is rewarded. You’ll grow with us in an unconventional way where sideways develops you as much as up; where voices are heard and ideas are tested, and new things are...

  • Assistant Director Cyber Security Risk

    Found in: Talent AU C2 - 2 weeks ago


    Sydney, Australia Softtest pays pty ltd Full time

    Australian Citizens with ability to obtain NV1 Clearance residing in Australia only respond.Contract start 07 August 2023 to 12 months, 12 months extensions.Australian Citizen, Ability to obtain NV1 Clearance, Canberra, Sydney, Brisbane, Melbourne role.Send your responses to jobs@softtestpays.comOverviewThe EL1 Cyber Security Risk is accountable under broad...

  • Senior Cyber Analyst

    Found in: Talent AU C2 - 2 weeks ago


    Sydney, Australia Tal Services Limited Full time

    Company DescriptionWelcome to This Australian Life. From the millions of Australians we protect, to those that make it happen every day at TAL, people really are what we’re all about. We want to grow with you. Achieve with you. And support you to do your best work. That's why we're focused on developing leadership, promoting diversity, rewarding...


  • Sydney, Australia Bluefin Resources Full time

    A **top-tier insurance firm** is seeking someone who is **passionate about cyber security** to join them and grow into a Technical Underwriter. They're an excellent company & offer **WFH & genuine flexible hours** and have a reputation for being a fantastic place to work, truly valuing their employees. **You are**: This role could suit someone who has come...

  • Cyber Security

    21 hours ago


    Sydney, Australia Firesoft People Full time

    **Cyber Security - Associate Director (GRC)** **Global Professional Services** **$180k - $200k + Super** **Brisbane Based** Our client a renowned organization consistently recognized as one of the best companies to work for. As an Associate Director in Cyber Security Governance, Risk, and Compliance, you will have the opportunity to work on some of the...

  • Head of IT Security/CISO

    Found in: Talent AU C2 - 2 days ago


    Sydney, Australia Cuscal Full time

    Job DescriptionWe are looking for a Head of IT Security/CISO to uplift and drive our IT Security Strategy!What is this role about?The Head of IT Security/CISO is responsible for Cuscal’s information and data security, establishing and maintaining a company-wide information security management strategy and underpinning program to ensure that information...


  • Sydney, Australia OFX Full time

    **Company Description** Hi.** We’re OFX, a global provider of online, international payment services. We solve the complexity of moving money and enable better decisions. Headquartered in Sydney with offices worldwide, we’re a customer-focused business that is all about inspiring customer confidence. At OFX, you’ll have the opportunity to reach beyond...