Manager, Technology, Cyber and Data Risk
Core
Lead risk reviews, assurance activities, and thematic assessments for technology, cyber, and data risks across business operations and transformation programs.
Role type
Manager, Technology, Cyber and Data Risk
Builds
Risk management practices, control effectiveness, and risk-based decision-making for technology, cyber, and data initiatives.
Domain
Financial services (wealth management, superannuation, banking)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Technology/cyber/operational risk management, controls assurance, IT General Controls (ITGC) assessment, risk framework governance, issue management, stakeholder engagement, risk assessment, control design evaluation, remediation planning
Preferred skills
Superannuation/wealth management/banking/insurance experience, APRA requirements knowledge, NIST/ISO 27001/COBIT/CISA/ITIL frameworks, cloud/cyber security/third-party risk/data governance/AI exposure, relevant risk/tech/security/audit certifications
Technologies
NIST, ISO 27001, COBIT, CISA, ITIL, cloud platforms, AI systems
Responsibilities
Partner with stakeholders to identify, assess, manage, and report technology, cyber, and data risks; Support and review risk assessments, control assessments, control design, risk acceptances, and treatment plans; Lead and support control assurance and testing activities, including assessment of IT General Controls (ITGCs) and key technology, cyber, and data controls; Monitor risk appetite measures, key risk indicators, control performance, incidents, and emerging risks; Provide risk input to technology change, cloud, cyber security, data, supplier, resilience, and AI initiatives; Support issue management and remediation activities; Coordinate and support responses to assurance reviews, internal audit, external reviews, and regulatory requests; Conduct targeted and thematic reviews to identify control weaknesses, emerging risks, and opportunities for improvement; Support the ongoing development and practical application of risk frameworks, policies, standards, and controls; Build risk capability across stakeholders through coaching, advice, and collaboration
Seniority
Manager-level, hands-on IC with stakeholder leadership