Apply now »

Cybersecurity Risk Director

Cybersecurity Risk Director

Req ID:  123794
Department:  Chief Information Risk Office
Division:  Risk
Location:  Melbourne

About Us

 

At ANZ, we're shaping a world where people and communities thrive, driven by a common goal: to improve the financial wellbeing and sustainability of our millions of customers.

About the Role

In this position in our Risk, Group Technology team, you’ll play a key role as a senior specialist providing Line 2 expert risk advice, oversight and judgement across enterprise information security risk. This is a key leadership role that shapes how material information security risks are understood, challenged and communicated so that the Board, Executive Committee and regulators understand material risk positions against appetite, policy, regulator expectations and service requirements.

 

Operating as part of the Risk, Group Technology leadership team, you will act as a trusted expert and advisor across the team, bringing deep subject matter expertise, independent perspective and executive-ready insight to support material information security risk oversight, high-quality review and challenge, and clear risk-based recommendations across technology domains, cross-cutting disciplines and key programs.

 

While the role may coordinate matrix contributors or specialist resources from time to time, it does not carry primary accountability for people leadership or work allocation across the team; rather, it partners closely with Senior Managers and teams to ensure strong specialist input, consistent risk judgement and effective deployment of expertise against the portfolio’s highest priorities.

 

Banking is changing and we’re changing with it, giving our people great opportunities to try new things, learn and grow. Whatever your role at ANZ, you’ll be building your future, while helping to build ours.

 

Role Type: Permanent
Role Location: Melbourne or Brisbane
Work Hours: Full time

 

What will your day look like?


In this role you will:

 

  • Providing specialist Line 2 expertise across the information security portfolio by forming independent views on material risks, controls, remediation, risk acceptance, helping to translate these into clear priorities, recommendations and escalation paths.
  • Refreshing material risk themes and oversight priorities (annual and in-year), informed by horizon scanning and forward-looking stress/scenario considerations.
  • Maintaining a forward-looking view of emerging and systemic information security risks, including implications for risk appetite, governance focus, regulatory obligations and critical service outcomes.
  • Leading complex Line 2 review and challenge activity across material information security risks, controls, issues and remediation programs, ensuring positions are evidence-based, traceable and aligned to NFR Framework, policy and regulatory expectations.
  • Providing credible independent challenge on risk-in-change for significant initiatives involving technology, cyber, cloud or architecture, including treatment plans, control design, delivery risks, residual risk positions and risk acceptance proposals.
  • Synthesising insights from reviews, cyber events, incidents, thematic work and assurance activity to identify systemic weaknesses, root causes, recurring patterns and opportunities for control uplift or governance intervention.
  • Producing and presenting executive-ready Line 2 opinions, briefings and governance papers that clearly articulate material risks, trade-offs, implications, management actions and decisions required.
  • Acting as a senior specialist across Group Technology, Information Security and Risk stakeholders, helping connect stakeholders to the right expertise and promoting consistent understanding and application of frameworks, policy and oversight expectations.
  • Supporting the broader leadership team with governance readiness by reviewing papers, shaping risk narrative, clarifying decisions required and escalating where material risks or gaps are not being adequately addressed.
  • Representing specialist Line 2 perspectives in cross-functional forums, regulatory or audit interactions and enterprise initiatives, ensuring information security risks are clearly understood and appropriately reflected in broader risk views.
  • Maintaining an insights-led, forward-looking view of the information security portfolio by connecting metrics, incidents, issues, review outcomes and change signals into clear themes, drivers, outlooks and recommended actions.
  • Driving continuous improvement in Line 2 methods, templates, reporting routines and specialist advisory practices to improve consistency, quality, efficiency and auditability of oversight outputs.
  • Providing specialist coaching and guidance, and contributing actively to leadership team discussions on portfolio priorities, ways of working and capability needs, while operating primarily as an individual contributor rather than as the primary people leader for the team.

What will you bring?


To grow and be successful in this role, you will ideally bring the following:

 

  • Extensive experience across senior Information Security operational, risk, compliance and/or assurance roles within a complex, APRA-regulated or equivalently regulated environment.
  • Deep knowledge of information security and cyber risk disciplines and practices and their impact on resilience and customers.
  • Proven ability to form, articulate and defend independent and defensible views on control effectiveness, remediation credibility, residual risk and risk acceptance for complex or material risk matters.
  • Strong understanding of cybersecurity frameworks/practices including NIST, MITRE&TTACK, threat mapping/modelling, etc.
  • Strong understanding of APRA requirements relevant to the role, including CPS 230 and CPS 234, and demonstrated ability to support audit and regulatory engagement through clear positions, evidence expectations and traceability.
  • Demonstrated capability to review and challenge risk-in-change for material initiatives involving technology, cyber, cloud or architecture, including treatment plans, delivery risks, dependencies, residual risk positions and risk acceptance proposals.
  • Proven ability to synthesise diverse risk inputs, including reviews, incidents, issues, metrics, assurance outcomes and change signals, into coherent material themes, root causes, outlooks and recommended actions for Executive and Board-level audiences.
  • Strong data-led risk oversight capability, including the ability to interpret KRIs/KPIs, control maturity indicators, incidents and change signals to identify emerging themes, explain movements and recommend targeted oversight actions.
  • Experience planning and leading complex reviews, thematic assessments or cross-cutting risk deep dives, and translating findings into clear, practical uplift recommendations.
  • Proven engagement and influencing skills with senior stakeholders, with the ability to operate credibly as a specialist advisor who courageously challenges, align peers and drive consistent outcomes across a matrixed organisation without direct authority.
  • Strong governance writing, communication skills and delivery discipline, including management of portfolio priorities, evidence standards, issue and action tracking, escalation and monitoring through to verified closure.
  • Demonstrated ability to provide specialist coaching, quality assurance and capability uplift across peers or matrix contributors to strengthen the consistency and quality of Line 2 challenge, judgement and writing.

So why join us?

 

From the moment you join ANZ, you'll be doing meaningful work that will shape a world where people and communities thrive.

 

But it's not just our customers who'll feel your impact. You'll feel it too. Because at ANZ, you'll have the resources, opportunities, and support you need to take the next big step in your career.

 

We're a diverse bunch at ANZ in different roles, different locations, doing different things. That's why we have a range of flexible working arrangements, so our people can 'make work, work for them'. We also provide a range of benefits including access to health and wellbeing services and discounts on selected products and services from ANZ and more.

 

At ANZ, you'll be part of an organisation where the different backgrounds, perspectives and life experiences of our people are celebrated. That's because we're committed to building a workplace that reflects the diversity of the communities we serve. We welcome applications from everyone and encourage you to talk to us about any adjustments you may require to our recruitment process or the role itself. If you're a candidate with a disability or access requirement, and have an enquiry about the support provided, please let us know on your application or visit ANZ Accessibility and Inclusion Programs for alternate contact methods.

 

To find out more about working at ANZ, visit https://www.anz.com.au/careers. You can apply for this role by visiting ANZ Careers and searching for reference number 123794.
 

Job Posting End Date

02/10/2026, 11.59pm, (Melbourne Australia)

Apply now »