05 Aug
|
News
|
Melbourne
Lead the next evolution of cyber GRC at REA through platform, automation and smarter risk reportingShape how a product‐led technology organisation understands and reduces cyber riskLead a distributed team across Australia and India while partnering closely with senior leadersWe're REAWith bold and ambitious goals, REA Group is changing the way the world experiences property.
No matter where you're at on your property journey, we're here to help with every step – whether that's finding or financing your next home.
Our people are the key to our success.
At the heart of everything we do is a thriving culture centred around high performance and care.
We are purpose driven and collaborative, which drives innovation and our ability to make a real impact.As such, we're proud to have been named one of Australia's Best Workplaces four times since **** — including third place in **** — plus Best Workplace for Women in **** and Best Workplace in Technology in **** and ****.
These listings are testament to every person who helps make REA a great place to work.Where the team fits inOur Cyber Governance, Risk and Compliance team exists to ensure REA has a shared understanding of cybersecurity risk, a practical approach to compliance, and a policy and control environment that is simple to understand and apply.This team is already well established, but the way it works needs to evolve.
That evolution is at the heart of this role.
You'll be the person our leaders turn to when deciding what to work on next - driving a shared understanding of our cyber risks.What the role is all aboutThis is a rare opportunity to reshape how cyber GRC is done inside a contemporary product and technology business.
Over your first year, you will make the case for and implement a GRC platform, overhaul how we measure and report cyber risk, automate compliance evidence collection, and modernise or replace existing processes so the team's time is invested where it most reduces risk.You'll be the clearest voice on cyber risk at REA, helping leaders make better decisions about what to prioritise and why.
You'll sit on the Security leadership team and work closely with peers across Product Security, Enterprise Security, and Detection and Response.Day to day,
you can expect to:Drive a shared understanding of cyber risk across the security organisation and broader business so investment is focused on the controls and remediation that most reduce riskEstablish, manage and report on security metrics that make performance, exposure and priorities easy for the business to understandSupport the CISO with regular reporting to senior governance forums and provide confident, constructive challenge when priorities need to shiftLead the Cyber GRC team through a shift from routine process execution to higher‐value, risk‐focused workDirectly manage the Australian team and provide functional leadership to team members in India, in partnership with their local people managerLead the Business Information Security Officer capability, including the current BISO supporting Financial ServicesLead the selection, business case creation and implementation of a GRC platformRedesign the third‐party risk process so it delivers more signal with far less effortEstablish automated compliance artefact collection to support efficient certification and assurance activityEnsure the business understands and manages its obligations across standards including ISO *****, PCI‐DSS and SOC 2Oversee the ongoing measurement of cyber maturity using NIST CSFOwn cybersecurity policies and key governance controls, ensuring they are pragmatic, clear and aligned to business needsEstablish REA's approach to supporting minority investments with cyber advice and visibility of cyber riskSupport cyber due diligence on future acquisition targetsWho we're looking forYou're someone who loves technology and enjoys improving the way work gets done.
You understand how product development organisations operate, and you know how to make the right way the simplest way.We're looking for someone with:A track record of delivering technology‐enabled change in GRC, security assurance or risk practices, with clear examples of processes you have automated,
simplified or retiredExperience leading teams through change in ways of workingPeople leadership experience, ideally across distributed or international teamsStrong influencing skills and the ability to work effectively across organisational boundariesDeep experience with security risk assessment and risk management frameworks, and the ability to translate technical security concepts for business audiencesBroad security knowledge, including awareness of current threats and attack techniquesKnowledge of modern product development technologies and ways of workingFamiliarity with security frameworks such as NIST CSF and ISO *****, and the judgement to apply them pragmaticallyHands‐on comfort with modern tooling, including scripting, APIs or AI tools to remove manual work and improve outcomesExceptional communication skills for both technical and non‐technical audiencesThe ability to build trust and credibility quickly with senior stakeholdersComfort operating in ambiguity and navigating competing prioritiesStrong analytical and problem‐solving capabilityThe REA experienceThe physical, mental, emotional and financial health of our people is something we'll never stop caring about.
This is a place to learn and grow.Some of our perks and benefits include:A hybrid and flexible approach to workingFlexible leave options including birthday leave and the option to purchase additional leaveFlexible parental leave offering for primary and secondary carersOur Because We Care program offers employees volunteering leave, community grants, matched payroll giving and our Community Café donates 100% of revenue to charityHackdays so you can bring your big ideas to lifeOur commitment to Diversity, Equity, and InclusionWe are committed to providing a working environment that embraces and values diversity, equity and inclusion.
We believe teams with diverse ideas and experiences are more creative, more effective and fuel disruptive thinking.
If you've got the skills, dedication and enthusiasm to learn but don't necessarily meet every single point on the job description, please still get in touch.Join our Talent NeighbourhoodKeen to be part of REA but didn't find a perfect match with this opportunity?
Perhaps the timing isn't right?
You should join our Talent Neighbourhood!
(careers-talentneighbourhood)
#J-*****-Ljbffr
📌 Head Of Cyber Grc (Melbourne)
🏢 News
📍 Melbourne