Apply now »

Product Area Lead - Exposure Management

Product Area Lead - Exposure Management

Req ID:  118097
Department:  Group Cyber Security Executive Office
Division:  Technology
Location:  Melbourne

About Us


At ANZ, we're shaping a world where people and communities thrive, driven by a common goal: to improve the financial wellbeing and sustainability of our millions of customers.

About the Role

 

As the Product Area Lead – Exposure Management, you will lead ANZ’s enterprise exposure management capability, ensuring the bank maintains a clear, continuously updated view of its cyber attack surface. This role is critical in identifying, prioritising and driving remediation of cyber exposures before they can be exploited, helping protect ANZ’s customers, assets and reputation.

 

You will operate across a global, complex technology estate spanning on-premises, hybrid and multi-cloud environments, setting standards, leading strategy, and delivering measurable risk reduction outcomes.

 

Banking is changing and we’re changing with it, giving our people great opportunities to try new things, learn and grow. Whatever your role at ANZ, you’ll be building your future, while helping to build ours.

 

Role Type: Permanent
Role Location: Melbourne, Sydney or Brisbane
Work Hours: Full-Time

What will your day look like?

 

In this role, you will:

 

  • Lead ANZ’s exposure management programme, covering attack surface management, vulnerability management and remediation oversight.
  • Define and maintain enterprise-wide visibility of cyber exposures across internal, external and third-party environments.
  • Establish and enforce vulnerability scanning standards, policies and coverage across the technology estate. 
  • Own and continuously improve the end-to-end vulnerability lifecycle, including discovery, triage, prioritisation and closure. 
  • Implement risk-based prioritisation frameworks that incorporate threat intelligence, exploitability and asset criticality. 
  • Define and manage remediation SLAs, including escalation pathways to senior technology and risk stakeholders where required.
  • Deliver reporting and insights tailored to multiple audiences, from engineering teams through to executives and board-level stakeholders. 
  • Ensure compliance with regulatory and audit requirements, supporting examinations and assessments.
  • Lead tooling strategy, integration and vendor management across the exposure management ecosystem.
  • Build, lead and develop a high-performing team of specialists, and define the multi-year roadmap aligned to ANZ’s risk appetite and technology strategy.

What will you bring?


To grow and be successful in this role, you will ideally bring the following:

 

  • Demonstrated experience leading vulnerability or exposure management programmes in large, complex organisations.
  • Deep technical expertise across vulnerability management platforms (e.g. Tenable, Qualys, Rapid7) and scanning methodologies. 
  • Strong understanding of risk-based prioritisation frameworks (e.g. CVSS, EPSS) and ability to contextualise cyber risk. 
  • Proven experience designing and managing remediation frameworks, SLAs and escalation processes at scale. 
  • Experience delivering executive and board-level reporting, translating technical risk into meaningful insights. 
  • Strong stakeholder management skills with the ability to influence senior leaders and regulators.
  • Experience leading and developing specialist technical teams. 

 

Desirable capabilities:

 

  • Familiarity with exposure assessment platforms and attack path analysis tools.
  • Understanding of offensive security concepts and threat-informed defence approaches. 
  • Experience integrating security tooling with enterprise systems such as CMDBs and ITSM platforms. 
  • Knowledge of regulatory frameworks (e.g. APRA CPS 234) and industry standards.

 

Key capabilities:

 

  • Ability to simplify complex cyber risk into clear, actionable insights
  • Strong analytical and data-driven decision-making skills
  • Effective programme leadership and governance discipline
  • Ability to build trusted relationships and drive accountability across stakeholders


You’re not expected to have 100% of these skills. At ANZ a growth mindset is at the heart of our culture, so if you have most of these things in your toolbox, we’d love to hear from you.

So why join us?

 

From the moment you join ANZ, you'll be doing meaningful work that will shape a world where people and communities thrive.

 

But it's not just our customers who'll feel your impact. You'll feel it too. Because at ANZ, you'll have the resources, opportunities, and support you need to take the next big step in your career.

 

We're a diverse bunch at ANZ in different roles, different locations, doing different things. That's why we have a range of flexible working arrangements, so our people can 'make work, work for them'. We also provide a range of benefits including access to health and wellbeing services and discounts on selected products and services from ANZ and more.

 

At ANZ, you'll be part of an organisation where the different backgrounds, perspectives and life experiences of our people are celebrated. That's because we're committed to building a workplace that reflects the diversity of the communities we serve. We welcome applications from everyone and encourage you to talk to us about any adjustments you may require to our recruitment process or the role itself. If you're a candidate with a disability or access requirement, and have an enquiry about the support provided, please let us know on your application or visit ANZ Accessibility and Inclusion Programs for alternate contact methods.

 

To find out more about working at ANZ, visit https://www.anz.com.au/careers. You can apply for this role by visiting ANZ Careers and searching for reference number 118097 .
 

Job Posting End Date

, 11.59pm, (Melbourne Australia)

Apply now »