Cyber Security Risk Specialist
Summary
A cyber risk specialist at a major financial services organisation in Sydney, providing independent oversight of cyber security risk: reviewing policies and controls, running risk assessments and control assurance, monitoring APRA compliance (CPS 230/220/234) and reporting to executives across cloud, identity and access management.
Salary: $140k - $180k p.a. + Super
Cyber Security Risk Specialist
Major financial services organisation is seeking an experienced Cyber Risk Specialist.
Join a growing Risk & Compliance team and provide independent oversight of cyber security risks across a complex enterprise environment.
Key Responsibilities
- Review and enhance cyber security policies, processes and controls.
- Conduct cyber risk assessments and provide guidance on remediation strategies.
- Perform control assurance activities and independent control testing.
- Provide oversight and challenge to technology and security teams on cyber risk matters.
- Monitor compliance with APRA regulatory requirements
- Assess the effectiveness of security controls across cloud, identity, access management and broader cyber security domains.
- Support cyber risk reporting for executives and governance committees.
- Identify emerging cyber threats, vulnerabilities and AI-related security risks.
- Review incidents and root cause analyses to ensure sustainable remediation outcomes.
About You
- Experience in Cyber Security Risk, Information Security Risk, Cyber GRC, Security Assurance or IT Audit.
- Strong understanding of cyber security frameworks and regulatory obligation - APRA experience is highly desireable (CPS 230, 220, 234)
- Experience working within the financial services space is a must have!
- Experience in risk assessments, control testing, assurance or governance activities.
- Ability to influence stakeholders and provide independent challenge.
- Certifications such as CISSP, CISM, CRISC or CISA are highly regarded.