We’re all about helping our members make the most of their money. And while they go after their goals, you can too. As a Cyber Security Risk Specialist, you’ll play a key role in helping us identify, assess, manage and report cyber security risks across the organisation.
Working within our Risk and Compliance function, you’ll provide independent second-line oversight, challenge and advice across our cyber security domain. You’ll support the Board, Executive and business stakeholders by monitoring the effectiveness of cyber security controls, contributing to assurance activities and helping ensure our approach aligns with our Risk Management Framework and regulatory expectations.
This is an opportunity to bring your cyber security, risk and assurance expertise to a purpose-led organisation where your work helps protect our members, our people and our future. You’ll influence senior stakeholders, provide meaningful insights on emerging risks, and support a robust risk culture across Australian Retirement Trust.
This role is a permanent opportunity and is based in Brisbane, Sydney or Melbourne.
Day to day, you'll:
- Provide independent oversight and challenge of cyber security risk management activities.
- Review and assess cyber security risks to ensure they are identified, articulated and managed within risk appetite.
- Provide guidance on cyber risk treatment strategies and control effectiveness.
- Develop, implement and measure cyber security policies, procedures and guidelines in line with regulatory requirements and industry better practice.
- Provide expert advice, reporting and insights to internal and external stakeholders, including senior leaders.
- Design, coordinate and execute assurance activities across ART’s cyber security domain.
- Design,
coordinate and execute independent control testing over cyber security controls. Support adherence to the Risk Management Framework, policies and standards across cyber security risk management.
- Help monitor the cyber risk profile, including emerging threats, vulnerabilities and systemic issues.
- Provide guidance and training to employees on cyber security awareness, better practice and incident response procedures.
- Review root cause analysis and support sustainable remediation actions.
- Share insights on emerging risks, including AI, cloud security and evolving cyber trends.
It goes without saying you'll be a great communicator with top notch interpersonal skills. We'll also expect you to pick up problems and come up with quick, creative ways to solve them. It's quite likely you tick some of the following boxes too:
- You have relevant tertiary qualifications in risk, commerce, computer science or a related discipline.
- Your experience includes cyber security or information security risk, ideally within financial services.
- You'll bring a strong understanding of cyber security frameworks and standards such as ISO 27001, NIST or CPS 234.
- You're experienced in risk management, assurance or control testing activities.
- You can provide independent challenge and influence senior stakeholders with confidence and care.
- Your analytical, reporting and communication skills help you turn complex information into clear insights.
- You'll have experience embedding new or uplifted change across an organisation.
- You're confident leading constructive conversations and challenging executive stakeholders when needed.
- You may hold certifications such as CISSP, CISM, CRISC or equivalent.
- Your experience in APRA-regulated environments will be highly regarded.
- You'll bring an understanding of AI and cloud security, security operations, identity and access management, or emerging cyber risks.
📌 Cyber Risk Specialist (Brisbane)
🏢 Art
📍 Brisbane