We’re all about helping our members make the most of their money. And while they go after their goals, you can too. As a Senior Risk and Compliance Specialist, Information Security, you'll strengthen how the Information Security function identifies, assesses, manages and reports risk across security operations, projects, governance activities, third-party arrangements and control environments. You'll shape practical risk responses, drive assurance activities and enable strong, sustainable risk outcomes across Technology.
Working closely with Information Security leaders, Technology stakeholders, Risk and Compliance, Internal Audit and project teams, you'll influence risk-informed decisions and strengthen a transparent, evidence-based approach to control effectiveness and remediation. You'll also drive alignment with regulatory obligations, coordinate assurance activities and uplift information security control testing programs.
This role is a permanent opportunity and is based in Melbourne, Brisbane or Sydney.
Day to day, you'll:
• Enable Information Security leaders and teams to consistently apply risk management frameworks, policies, standards and governance requirements.
• Drive information security risk assessments across operations, projects and technology change initiatives, translating findings into clear treatment actions.
• Lead coordination of the independent information security control testing program, shaping plans, mobilising evidence, engaging stakeholders and delivering clear reporting.
• Strengthen risk outcomes by monitoring control testing results, remediation progress and assurance findings, and escalating emerging themes.
• Shape risk management outcomes across cyber uplift programs, information security projects and technology change activities.
• Drive effective issue, incident and remediation management through disciplined monitoring, analysis, action tracking and timely escalation.
• Strengthen third-party and service provider risk management by delivering robust assessments, due diligence and ongoing monitoring.
• Enable compliance with regulatory obligations relating to information security, operational resilience and service provider management.
• Influence risk outcomes by building trusted relationships across Technology, Information Security, Risk and Compliance and Internal Audit.
• Uplift risk culture and capability through practical guidance, targeted awareness initiatives and sustained engagement.
It goes without saying you'll be a great communicator with top notch interpersonal skills. We'll also expect you to pick up problems and come up with quick, creative ways to solve them. It's quite likely you tick some of the following boxes too:
• You have experience in technology risk, operational risk, compliance, assurance, project risk or risk in change environments.
• Your understanding of APRA prudential standards includes technology, information security, operational resilience and service provider management requirements.
• You'll have practical experience supporting risk assessments, control assessments, issue management, incident management and risk reporting activities.
• You're confident working with risk frameworks, controls, governance processes, KRIs and risk appetite concepts.
• You can partner effectively with technology stakeholders, project teams, control owners and senior leaders.
• Your written communication skills enable you to prepare clear papers, reports and governance updates.
• You'll be able to analyse information, identify themes and recommend practical risk treatment actions.
• You're qualified in technology, cyber security, information security, risk management, business or a related discipline, or bring equivalent practical experience.
• You hold, or are working towards, relevant certifications such as CRISC, CISA, CISM, CISSP, ISO 27001, ITIL, PRINCE2 or similar credentials.
• Your experience within financial services, superannuation, banking, insurance or another regulated industry will be highly regarded.