Manager, Technology Resilience Risk
Manager, Technology Resilience Risk
About Us
At ANZ, we're shaping a world where people and communities thrive, driven by a common goal: to improve the financial wellbeing and sustainability of our millions of customers.
About the Role
As a Manager, Technology Resilience Risk in our Risk – Group Technology Team, you’ll play a key role in providing independent Line 2 oversight of operational risk management across Group Technology domains with a focus on Infrastructure and Cloud Services, Service Management, Group Services and Strategy & Execution. You will provide high-quality review and challenge, actionable risk opinions and clear insight on control effectiveness, remediation progress, risk-in-change and security and resilience outcomes.
Reporting to the Senior Manager, Technology Resilience Risk, this role operates as part of a team of specialists and takes day-to-day accountability for defined oversight activities within the broader Line 2 plan, working autonomously and escalating material risks and issues as required.
You will partner with fellow Risk managers, Group Technology, and other Risk specialists to strengthen the risk and control environment through independent advice, review and challenge, and to support governance, audit and regulatory engagement with clear, evidence based positions.
Role Type: Permanent
Role Location: Melbourne / Sydney / Brisbane
Work Hours: Full-Time
What will your day look like?
- Execute Line 2 oversight activities, including scoping, scheduling, reviews and independent challenge, to drive measurable NFR uplift and resilience outcomes.
- Provide Line 2 oversight of whether critical technology services are secure, reliable, resilient and recoverable
- Maintain an independent view of material, systemic and emerging technology and cyber risks, leveraging KRIs/KPIs, incidents, assurance outcomes, change activity and external signals to identify trends, root causes, uplift opportunities and escalation requirements.
- Contribute to the evolution of Technology & Cyber risk management by supporting risk appetite statements, Board metrics, material risk themes, oversight priorities, reporting and risk frameworks.
- Perform independent review and challenge of risk identification, assessment, governance, risk culture, control design and operating effectiveness against risk appetite, policies, critical service requirements and the NFR Framework.
- Provide independent challenge and oversight of material technology initiatives and programs, including risk-in-change, remediation plans, risk acceptances, residual risk assessments and control effectiveness.
- Form, document and communicate Line 2 positions on control effectiveness, remediation integrity, residual risk and risk acceptance, supported by robust evidence, traceability and quality assurance standards.
- Lead or contribute to thematic reviews and cross-cutting assessments to identify systemic weaknesses, emerging risks and opportunities for sustainable control uplift.
- Monitor and challenge issue and action management for material findings, including ownership, dependencies, closure criteria, remediation progress and validation of closure evidence.
- Produce executive-ready risk opinions, governance papers, briefings and recommendations that clearly articulate risks, control gaps, implications, trade-offs, options, decisions required and recommended actions.
- Provide effective challenge, insights and representation in governance, risk and cross-functional forums to ensure technology and cyber risks are accurately understood and decision-ready.
- Build strong stakeholder relationships across Group Technology, providing timely, constructive Line 2 advice, guidance and challenge while promoting consistent application of risk frameworks, policies and standards.
- Support regulatory and audit engagements through independent evidence validation, traceability reviews, remediation oversight and timely escalation of material risks and gaps.
- Contribute to the continuous improvement of Line 2 methodologies, playbooks, templates, reporting, quality assurance practices and lessons learned to enhance consistency, efficiency and oversight quality.
- Demonstrate strong Line 2 risk judgement, independent challenge and high-quality risk assessment and reporting, while coaching colleagues, supporting team wellbeing and inclusion, and flexing to meet team priorities and capacity demands.
What will you bring?
- Strong experience in Line 2 Technology or Cyber Risk or Assurance within a complex, APRA-regulated or equivalent environment.
- Solid knowledge of technology, cyber and operational resilience risk domains, and common control practices (eg. identity, vulnerability management, secure configuration, lifecycle, change, resilience).
- Demonstrated ability to complete evidence-based control assessments and articulate clear Line 2 risk positions, including residual risk and risk acceptance considerations.
- Strong understanding of APRA requirements relevant to the role (including CPS230 and CPS234) and the ability to support audit regulatory engagement through clear positions and evidence expectations.
- Experience overseeing third-party/critical service providers.
- Experience reviewing risk-in-change for material initiatives, including assessment of delivery risk, remediation plans, control uplift and residual risk and resilience impacts.
- Proven enterprise leadership across geographies in a matrixed organisation, with strong influencing skills and comfort operating without direct authority.
- Executive communication skills with the ability to produce concise, decision-ready risk papers, briefings and ‘voice of risk’ interventions in senior governance forums.
- Experience planning and leading thematic reviews and synthesising findings (reviews, incidents, assurance outcomes) into systemic risk themes, root causes and clear recommendations.
- Strong stakeholder management skills, with the ability to build trust, obtain evidence and provide constructive challenge across Technology, Cyber, Risk and Assurance stakeholders.
- Strong data-led risk oversight capability, with proven ability to interpret KRIs/KPIs, control maturity, incidents and change signals to target oversight and communicate trends.
- Strong risk governance discipline, including issue/action management, audit-ready evidence standards, escalation, and tracking actions to verified closure.
So why join us?
From the moment you join ANZ, you'll be doing meaningful work that will shape a world where people and communities thrive.
But it's not just our customers who'll feel your impact. You'll feel it too. Because at ANZ, you'll have the resources, opportunities, and support you need to take the next big step in your career.
We're a diverse bunch at ANZ in different roles, different locations, doing different things. That's why we have a range of flexible working arrangements, so our people can 'make work, work for them'. We also provide a range of benefits including access to health and wellbeing services and discounts on selected products and services from ANZ and more.
At ANZ, you'll be part of an organisation where the different backgrounds, perspectives and life experiences of our people are celebrated. That's because we're committed to building a workplace that reflects the diversity of the communities we serve. We welcome applications from everyone and encourage you to talk to us about any adjustments you may require to our recruitment process or the role itself. If you're a candidate with a disability or access requirement, and have an enquiry about the support provided, please let us know on your application or visit ANZ Accessibility and Inclusion Programs for alternate contact methods.
To find out more about working at ANZ, visit https://www.anz.com.au/careers. You can apply for this role by visiting ANZ Careers and searching for reference number 124049 .
Job Posting End Date
30/09/2026, 11.59pm, (Melbourne Australia)