Principal Advisor Information Security (Governance, Risk & Compliance)
Department of Transport and Main Roads QLD Principal Advisor Information Security (Governance, Risk & Compliance)
Summary
A senior information security governance role at Queensland's Department of Transport and Main Roads: advising on and championing infosec policy, risk management and compliance across the agency, aligned to standards like ISO/IEC 27000, the ASD ISM/Essential Eight and NIST CSF. Permanent, flexible full-time, based in Carseldine, Brisbane.
Salary: $133,603 - $143,125 p.a.
As Principal Advisor Information Security (Governance, Risk & Compliance), you will provide expert advice and strategic direction for information security policy and governance across Transport and Main Roads (TMR). You will champion information security and deliver end-to-end advice and guidance informed by best practice and recognised Australian and international standards and strategies.
In this role, you will champion consistent information security risk management practices across TMR, including through the Information Security Community of Practice and other special interest groups aligned with TMR's risk framework and risk appetite. You will use governance, risk and compliance tools and evidence-based analysis to assess information security risks, prepare reports, and brief senior stakeholders on risk status, trends and treatment priorities.
You will develop, maintain and promote information security controls, policies and standards aligned with Queensland Government requirements and recognised industry practice. You will also lead communication, education, implementation and monitoring activities to improve awareness and adoption of TMR's information security policy framework. Maintaining contemporary information security knowledge and applying agile ways of working will be important in delivering practical governance, risk and compliance outcomes.
To thrive in this role, you will bring demonstrated experience developing, implementing and managing ICT governance frameworks in information security or IT service delivery and management. You will also have working knowledge of relevant standards and frameworks, such as the Queensland Government Information Security Policy, ISO/IEC 27000 series, the ASD Information Security Manual and Essential Eight, or the NIST Cybersecurity Framework.
The role is permanent, flexible full-time and based at Carseldine. A criminal history check will be undertaken before appointment because the role has access to sensitive data. TMR supports an inclusive workplace, career development and healthy work-life balance, and welcomes applicants from all backgrounds.
Applications to remain current for 12 months
Job Ad Reference: QLD/702663/26
Closing Date: Friday, 16 October 2026