Director - Cyber & Tech Risk

Director - Cyber & Tech Risk
Permanent Full Time
Financial Services
Sydney - Hybrid
 
We're partnering with a major financial institution to find a Director of Cyber & Tech Risk who can own the full technology risk picture and lead the response when things go wrong.
 
This role suits someone who is equally at home in a board risk paper as they are running a P1 bridge call at 2am, a rare combination that this organisation genuinely needs.


What you'll be doing:
  • Own the end-to-end technology and cyber risk profile across applications, infrastructure, cloud and third parties.
  • Act as incident commander for major production incidents - coordinating response, driving resolution, and owning stakeholder communication throughout.
  • Maintain and mature the technology risk framework, control library, KRIs and risk appetite.
  • Lead APRA regulatory engagement across CPS 234 and CPS 230 obligations.
  • Partner with engineering, security, and SRE teams to embed resilience and drive measurable risk reduction.
What we're looking for:
  • 8+ years in technology risk, cyber risk, or technology audit within banking or regulated financial services.
  • Demonstrated hands-on incident command experience in a complex production environment.
  • Strong APRA regulatory knowledge - CPS 234 and CPS 230 specifically.
  • Ability to translate technical risk into clear, decision-grade narratives for boards and senior leadership.
  • Sound judgement under pressure with the credibility to make the hard calls independently.
Nice to have:
  • CISSP, CISM, CRISC or CISA certification.
  • Background in SRE, platform operations or reliability engineering.
  • Exposure to operational resilience programs including impact tolerances and resilience testing.
Sounds interesting? Apply here!
JobAdder.com