Business Information Security Officer, ANZ

1 week ago


Brisbane, Australia Gallagher Full time

Introduction

Welcome to Gallagher – a global leader in insurance, risk management, and consulting services. With a growing team of more than 52,000 professionals worldwide, we empower businesses, communities, and individuals to thrive. At Gallagher, you can build a career whether it’s with our brokerage division, our benefits and HR consulting division, or our corporate team. Experience The Gallagher Way, a culture fueled by shared values and a collective passion for excellence. Join one of our dynamic teams, where you'll play a pivotal role in shaping Gallagher's future and unlocking unparalleled opportunities for both clients and yourself.

We believe that every candidate brings something special to the table, including you So, even if you feel that you’re close but not an exact match, we encourage you to apply.

Overview

The Business Information Security Officer (BISO) functions as the cyber and information security leader for all Gallagher divisions in Australian and New Zealand (ANZ) The BISO reports to the Global Chief Information Security Officer (CISO) with dotted lines to all Chief Information Officers in ANZ.

This role will manage the APAC GCIS team in supporting both enterprise-level and divisional information security strategies, objectives, and obligations. This includes providing staff as needed to support the Asia BISO and the Asian businesses during the Australian & New Zealand work day and some global support activities outside the Australian & New Zealand business hours.

The ANZ BISO works in close collaboration with Corporate and divisional leaders across all business, legal, central services and technology teams to identify, assess, prioritize and manage information security risk within the region.

Key areas of responsibility include information security risk management, system security, data protection, compliance, training, audits, managing mergers and acquisition risk, and executive-level reporting and communications.

How you'll make an impact

  • Establish strong working relationships and maintain ongoing communication / transparency with divisional leaders, other divisional BISOs, members of the Global Cyber and Information Security team, and other key stakeholders. 
  • Provide guidance to the divisional CIOs and the Global CISO on existing divisional security gaps, associated risks, and prioritization of remediation activities.
  • Coordinate with the Global Cyber and Information Security team, divisional IT Compliance Leads, and other divisional BISOs to ensure a consistent approach is followed during execution of information security processes and procedures. 
  • Raise awareness to technology and business application owners about relevant application security processes and provide oversight and assurance the division’s application inventory is accurately captured and inventoried.
  • Work with the SOC & Incident Response Team to assist in coordinating the overall response and recovery activities for security incidents that impact the division.
  • Verify and distribute divisional cybersecurity metrics to the Global CISO, divisional CIOs, and executive teams around key divisional IT security and performance indicators. 
  • Ensure alignment with and promote the Global IT & Security Policy Manual (GITSPM), and corporate and regional standards, liaising between the divisions, enterprise cyber security team, and technology leads. 
  • Ensure all applicable regulatory, legal, compliance and contractual obligations are properly interpreted and continuously met by the security program.  Stay abreast of external requirements, trends, and best practices. 
  • Support the divisions and global CISO in seeking budget optimization by ensuring program costs and value are properly balanced.
  • Increase security maturity and reduce risk across ANZ divisions by driving implementation of leading cyber security standards, practices and controls (e.g. ISO27K, APRA, PCI-DSS, NZISM),
  • Drive divisional participation in global training and awareness campaigns for information security and data governance requirements.
  • Work with the core business platform teams to help develop secure business requirements and security architecture that will integrate into the enterprise-level and divisional information security strategies and objectives.
  • Provide divisional guidance through the identification, tracking, and remediation of divisional information security risks or other audit / regulatory findings.
  • Counsel divisional IT management on security requirements for acquisitions and mergers and the vetting and procurements of new applications and technology platforms.
  • Maintain an effective IT due diligence vendor risk management assessment program. 
  • Guide divisional IT software development and application teams in the use of GCIS application security tools for tracking and correcting vulnerabilities and code weaknesses.
  • Acting as the CISO in region for satisfying Federal and State Government security requirements, ensuring updates to the ISM are implemented in a timely fashion.
  • Take responsibility for Compliance Operations, including audit preparation and liaison with internal and external auditors, including internal FAIR assessments and external government IRAP assessments as needed.
  • Support the Head of Global ISMS in the adoption of ISO27001 best practices across all ANZ divisions, contributing to the running of Division Cyber Committee meetings in region.

About you

Required:

  • Minimum of 8 years or more year of experience in information security leadership role.
  • Bachelor’s Degree in Business, Information Technology, Computer Science, Engineering, related technical degree, or equivalent experience.
  • Experience with international security and IT control standards and frameworks (e.g. ISO27001, GDPR, PCI-DSS, NIST, COBIT, COSO) and national security standards (APRA, ISM, NZISM etc)
  • CISA, CISM, CISSP or equivalent IT security related certification (or willingness to pursue).
  • Strong understanding of information security risk management methodologies and regulatory requirements pertaining to information security, and/or data security.
  • Ability to manage multiple complex priorities and competing agendas.
  • Ability to interpret and apply policies and regulations across a large, complex business
  • Knowledge in cloud computing platforms and capabilities.
  • Demonstrated leadership of multiple projects or a portfolio of projects with cross-functional stakeholder groups.

Desired:

  • Analytical aptitude with an emphasis on investigative, methodical critical questioning and logical thinking; a data-driven decision maker
  • Minimum bachelor's degree or commensurate experience required with emphasis in Computer Science, Engineering, Information Systems Management or Information Security.
  • Australian citizen either holding a AGSVA baseline clearance or the ability to gain this mandatory security clearance.

This position can sit in Sydney, Melbourne, Brisbane, Adelaide, Perth, and Auckland. 

#LI-TG2

Compensation and benefits

On top of a competitive salary, great teams and exciting career opportunities, we also offer a wide range of benefits. 

Below are the minimum core benefits you’ll get, depending on your job level these benefits may improve:

  • 4 weeks annual leave plus up to 2 weeks additional purchased Lifestyle Leave
  • Novated Leasing opportunities
  • Two paid volunteer days annually
  • Health Insurance Discounts with our Group Insurance Plan
  • Employee Stock Purchase Program
  • Paid parental leave

Other benefits include:

  • Flexible and hybrid work arrangements
  • Mental Health and Wellbeing Support for yourself and immediate family members
  • Employee Recognition Awards and Service Milestone Recognitions
  • Peer Support Program
  • Annual flu vaccinations
  • Access to Reward Gateway – discount offers at over 350 retailers
  • And more...

We value inclusion and diversity

Inclusion and diversity (I&D) is a core part of our business, and it’s embedded into the fabric of our organization. For more than 95 years, Gallagher has led with a commitment to sustainability and to support the communities where we live and work.

Gallagher embraces our employees’ diverse identities, experiences and talents, allowing us to better serve our clients and communities. We see inclusion as a conscious commitment and diversity as a vital strength. By embracing diversity in all its forms, we live out The Gallagher Way to its fullest.

Gallagher believes that all persons are entitled to equal employment opportunity and prohibits any form of discrimination by its managers, employees, vendors or customers based on race, color, religion, creed, gender (including pregnancy status), sexual orientation, gender identity (which includes transgender and other gender non-conforming individuals), gender expression, hair expression, marital status, parental status, age, national origin, ancestry, disability, medical condition, genetic information, veteran or military status, citizenship status, or any other characteristic protected (herein referred to as “protected characteristics”) by applicable federal, state, or local laws.

Equal employment opportunity will be extended in all aspects of the employer-employee relationship, including, but not limited to, recruitment, hiring, training, promotion, transfer, demotion, compensation, benefits, layoff, and termination. In addition, Gallagher will make reasonable accommodations to known physical or mental limitations of an otherwise qualified person with a disability, unless the accommodation would impose an undue hardship on the operation of our business.



  • Brisbane, Australia Gallagher Full time

    About Us: Welcome to Gallagher - a global leader in insurance, risk management, and consulting services. With a growing team of more than 45,000 professionals worldwide, we empower businesses, communities, and individuals to thrive. At Gallagher, you can build a career whether it’s with our brokerage division, our benefits and HR consulting division, or...


  • Brisbane, Australia Gallagher Full time

    Overview The Business Information Security Officer (BISO) functions as the cyber and information security leader for all Gallagher divisions in Australian and New Zealand (ANZ) The BISO reports to the Global Chief Information Security Officer (CISO) with dotted lines to all Chief Information Officers in ANZ. This role will manage the APAC GCIS team in...


  • Brisbane, Queensland, Australia Gallagher - Global Full time

    About the RoleGallagher is seeking an experienced Business Information Security Officer to lead our cyber and information security efforts in Australia and New Zealand. As a key member of our global security team, you will be responsible for managing information security risk, developing and implementing security strategies, and ensuring compliance with...


  • Brisbane, Queensland, Australia Gallagher - Global Full time

    About the RoleGallagher is seeking a highly skilled Business Information Security Officer to lead our cyber and information security efforts in Australian and New Zealand. As a key member of our global security team, you will be responsible for managing information security risk, developing and implementing security strategies, and ensuring compliance with...


  • Brisbane, Queensland, Australia Gallagher Full time

    About the RoleGallagher is seeking a highly skilled Business Information Security Officer to lead our cyber and information security efforts in Australian and New Zealand. As a key member of our global security team, you will be responsible for managing information security risk, developing and implementing security strategies, and ensuring compliance with...


  • Brisbane, Australia BOEING Full time

    At Boeing, we innovate and collaborate to make the world a better place. From the seabed to outer space, you can contribute to work that matters with a company where diversity, equity and inclusion are shared values. We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with great opportunity for...


  • Brisbane, Australia Challenger Security Full time

    **Who are we?** We are people, people. Challenger Security is an ISO accredited industry leader in the provision of security services across Australia. We specialise in high-end luxury retail, commercial, education and government. We have built our brand understanding clients, protecting them, and then doing it better. **Who are we looking...


  • Brisbane, Queensland, Australia Security Bank & Trust Co. Full time

    Security Bank & Trust Co. is seeking a distinguished Associate Professor/Professor in Information Security to lead and make strategic contributions to teaching and research in the field of Information Security. The successful candidate will be expected to foster an inclusive, high-performance, and high-impact research and teaching team that achieves...


  • Brisbane, Australia TE Connectivity Full time

    **Company Information**: TE Connectivity’s Information Security and Compliance Teams execute security controls to prevent hackers from infiltrating company information or jeopardizing e-commerce programs. They research attempted efforts to compromise security protocols, maintain security systems for routers and switches, administer security policies to...


  • Brisbane, Queensland, Australia Flight Centre Travel Group Full time

    About the RoleWe are seeking a highly skilled Business Information Security Advisor to join our team at Flight Centre Travel Group. As a key member of our organization, you will play a critical role in leading Security, Compliance, and Assurance activities globally.Key ResponsibilitiesCollaborate with the Chief Information Security Officer (CISO), Risk, and...


  • Brisbane, Queensland, Australia StudentUniverse Full time

    About the RoleWe are seeking a highly skilled Business Information Security Advisor to join our team at Flight Centre Travel Group. As a key member of our security team, you will play a critical role in leading security, compliance, and assurance activities across our global organization.Key ResponsibilitiesCollaborate with our Chief Information Security...


  • Brisbane, Queensland, Australia Surf Life Saving QLD Full time

    Job Title: Chief Information Security OfficerSurf Life Saving Queensland is seeking a highly skilled and experienced Chief Information Security Officer to join our team. As a senior executive, you will be responsible for establishing and maintaining the enterprise information security strategy and program.Key Responsibilities:Develop and implement a...


  • Brisbane, Australia Challenger Security Full time

    **Join Our Team at Challenger Security: Where Safety Meets Luxury** **About Us**: At Challenger Security, we're more than just a security company - we're a team of dedicated individuals committed to safeguarding our clients across Australia. As an ISO accredited industry leader, we specialise in providing top-tier security services for high-end luxury...


  • Brisbane, Australia Challenger Security Full time

    **Join Our Team at Challenger Security!** **About Us**: At Challenger Security, we're not just a security company; we're a dedicated team committed to protecting our clients across Australia. As an ISO-accredited leader in the industry, we provide top-tier security services to luxury retail, commercial, education, and government sectors. Our success stems...


  • Brisbane, Australia Challenger Security Full time

    **Join Our Team at Challenger Security!** **About Us**: At Challenger Security, we're not just a security company; we're a dedicated team committed to protecting our clients across Australia. As an ISO-accredited leader in the industry, we provide top-tier security services to luxury retail, commercial, education, and government sectors. Our success stems...


  • Brisbane, Australia Challenger Security Full time

    **Join Our Team at Challenger Security!** **About Us**: At Challenger Security, we're not just a security company; we're a dedicated team committed to protecting our clients across Australia. As an ISO-accredited leader in the industry, we provide top-tier security services to luxury retail, commercial, education, and government sectors. Our success stems...


  • Brisbane, Australia Boeing RIV Site Full time

    About us Boeing Defence Australia is shaping the future of aerospace and delivering some of the nation's most important programs for the Australian Defence Force.Joining us is a chance to make your mark, working with a diverse team that is united in pushing the boundaries of imagination and excellence.We currently employ more than 2,500 people across 14...


  • Brisbane, Australia Ashurst LLP Full time

    **The Opportunity**: We have a permanent role available for an experienced Information Security Officer to join our global team in Brisbane. This role will be crucial in ensuring the security of our systems and data by evaluating the risks associated with third party vendors and internal projects and recommending appropriate risk mitigation strategies. You...


  • Brisbane, Queensland, Australia ANZ Full time

    About UsAt ANZ, we're shaping a world where people and communities thrive, driven by a common goal: to improve the financial wellbeing and sustainability of our millions of customers. About the RoleAs a key member of our Business Transformation & Strategy (BTS) Leadership Team, you'll play a critical role in our Workforce Strategy & Transformation (WS&T)...


  • Brisbane, Australia Boeing RIV Site Full time

    The Opportunity The Information Technology Security Officer (ITSO) is a System Administration role with an IT security focus. The ITSO is responsible for designing, implementing and maintaining the secure ICT environments within BDA, including but not limited to network security, gateway security, identity management, system security and media and equipment...