Cyber risk and governance analyst Sydney CBD · Full-time · Hybrid · Reports to Head of Information Security
About EVT
At EVT we believe in changing the game. Why? Because no one wants ordinary. If you're seeking to be part of the kind of wow-factor moments you can help shape, then you've come to the right place.
As market-leading experience creators, we bring to life some of the best-known brands and properties in entertainment, ventures, and travel. Our portfolio includes over 140 entertainment experiences like Event Cinemas and Moonlight Cinemas, 150 award-winning restaurants and bars, and 80+ hotels, including QT, Rydges, Atura, LyLo, Independent Collection by EVT and Thredbo. Our ventures include a ~$2.3B property portfolio and hotel management, just to name a few.
The role
The Cyber Risk and Governance Analyst will drive EVT's security governance, risk management, and compliance initiatives. This role is critical in shaping and maintaining our security posture across internal operations, projects, and third-party relationships.
You'll support the development of risk frameworks, design and enforce security policies aligned with NIST 2.0 and PCI DSS, and lead insurance and third-party/supplier risk activities, while providing technical assurance through activities such as penetration testing coordination and configuration reviews. This is a hands-on position accountable to the Information Security and Group Business IT functions.
Key responsibilities
- Build and maintain EVT's security governance framework and policies, using Vanta to automate control evidence and compliance monitoring, and reporting on governance maturity to senior leadership.
- Lead EVT's PCI-DSS compliance framework and annual certification lifecycle, including QSA assessments, control matrix maintenance, and cardholder data environment governance.
- Build and maintain the cyber and IT risk management framework and risk register, embedding risk management into project delivery and change initiatives.
- Manage penetration testing and security assurance vendors, and coordinate configuration reviews of critical systems and cloud environments.
- Assess and manage third-party and vendor security risk, maintaining the vendor risk register and enforcing contractual security requirements.
- Collaborate with technology and business teams to deliver information security outcomes and drive continuous improvement across the function.
What you'll bring
- Significant experience in cyber security governance, risk, compliance, or technology risk management.
- Strong working knowledge of recognised frameworks and standards: NIST CSF, PCI-DSS, ISO, and SOC2.
- Demonstrated experience managing third-party and supplier cyber security risk in a corporate environment.
- Experience supporting audits, regulatory engagements, and executive-level reporting.
- Excellent stakeholder engagement, communication, and influencing skills.
- Ability to operate independently and provide strategic guidance in a complex organisational environment.
- Experience in a regulated or highly governed industry is desirable, for example financial services, critical infrastructure, utilities, government, or healthcare.
- Exposure to cloud and outsourced service risk management (AWS, Azure, SaaS providers) is desirable.
- Experience implementing or uplifting third-party risk management frameworks or GRC tooling is desirable.
- Tertiary qualification in information security, IT, risk, law, or a related discipline, or equivalent skilled experience.
- Relevant certifications are highly regarded, for example CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Implementer or Auditor.
How you work
- Hands-on and non-hierarchical: leads from the front, close to the detail.
- Owner's mindset: acts on data and feedback, ships improvements.
- Resilient and solutions-focused: stays calm, moves fast under pressure.
- Growth mindset: learns, shares, and levels up others.
Perks from day one
As part of EVT, you unlock Elevate Perks from your first day. Parity for all levels: no ivory towers.
- 50% off dining and stays across EVT hotels: QT, Rydges, Atura, LyLo and more.
- $2 movie tickets, plus discounts on Gold Class, Moonlight Cinema and Candy Bar.
- Seasonal perks at Thredbo.
- Rapid career growth across our hotel and entertainment network.
- Paid parental leave, community and volunteering opportunities.
Apply now
Join the EVT team and become an EVT experience creator, opportunity taker, the ultimate Daymaker.
Join and make a positive impact on our people, communities, and environment every day.
Send your CV and a short cover letter. We welcome applicants from all backgrounds and review applications as they come in, so don't wait. We can't wait to see the places your career will go with EVT.
When you click apply, you'll be taken to our secure EVT careers portal (powered by Dayforce). This is our official system for managing applications across the EVT Group. You'll simply enter your details and answer a few quick screening questions so we can get to know you better.
📌 Cyber Risk and Governance Analyst - EVT Head Office (Sydney)
🏢 EVT
📍 Sydney