Senior Manager - Cyber Risk (Sydney)

Senior Manager - Cyber Risk (Sydney)

21 Aug
|
Woolworths Group
|
Sydney

21 Aug

Woolworths Group

Sydney

- Join a customer-obsessed technology business at the heart of Australia’s largest retailer
- Lead the shift from reactive compliance to a proactive, threat-led cyber defense strategy
- Norwest (Sydney) based with a hybrid working model

We are Woolworths Group

We are Woolworths Group. 200,000+ bright minds, passionate hearts and unique perspectives connected by a shared Purpose – ‘to create better experiences together for a better tomorrow.’ It’s that Purpose that fuels our ambition to explore new ideas, make brave commitments and innovate better ways to meet the food and everyday needs of more than 24 million customers every week.

If you’re excited to turn today’s blue sky thinking into a better tomorrow for future generations, you’ll find yourself supported and enriched in a dynamic, inclusive and empowering workplace that reflects the diverse communities we serve. With a culture of genuine care, a adaptable approach to work and opportunities across the group to grow your career and make a meaningful impact, the possibilities for what we can achieve together are endless.

The Opportunity

Drive the evolution of Woolworths Group’s cyber risk capability—the "Trust Engine"—from traditional, qualitative compliance to a proactive, threat-led risk model. As the core 1st Line risk authority within Cyber, this pivotal role bridges the gap between deep technical operations and enterprise risk management. You will operationalise high-level risk appetite into quantifiable thresholds, ensure consistency across solution risk assessments, and champion cyber risk posture within executive and Senior Leadership Team (SLT) forums.

What you’ll do

- Threat-Led Risk Modeling & RACM: Partner directly with Cyber Threat Intelligence (CTI) to execute threat-led risk modeling,



evaluating critical controls against the Risk & Control Assessment Matrix (RACM) to refine technical and operational risk ratings.
- Strategic Risk Reporting: Deliver executive-level risk reporting that translates complex threat intelligence and KRIs into clear, business-focused insights to drive informed governance and investment prioritisation.
- Operationalising Risk Appetite: Translate strategic cyber risk appetite into quantifiable thresholds, establishing clear benchmarks for asset tiering, consistent risk acceptance, and decision-making.
- Governance & Systemic Advisory: Moderate solution-specific and systemic risk assessments to guarantee enterprise-wide consistency, while providing advisory on high-impact capabilities that span multiple technology domains.
- Risk Acceptance & Transparency: Oversee formal risk acceptances across domains, ensuring residual risk is transparent, appropriately owned, and aligned with organisational risk appetite.
- Post-Incident Risk Alignment: Lead risk evaluations following major security incidents to validate control efficacy, calibrate risk ratings, and ensure lessons learned adjust our long-term risk direction.

What you’ll bring

- Core Experience: 10+ years of experience in IT Risk, Cyber Security, or Technology Audit, with demonstrated leadership in a formal Three Lines of Defence (3LoD) risk model and Line 1 capacity.
- Change Leadership: A proven track record of maturing risk functions by partnering across the business to evolve from compliance-heavy,



qualitative foundations toward threat-led, quantified risk maturity.
- Technical & Business Fluency: Expertise in leveraging CTI feeds for control prioritisation and established risk quantification methodologies (e.g., FAIR), combined with the skill to translate complex technical exposure into business-relevant narratives and financial impact.
- Stakeholder Influence: Experience preparing executive and board-level reporting, balancing deep technical engagement with the enterprise consistency required by Group Risk and Audit functions.

What you’ll Experience

- Team Discounts - Team discounts across our range of Woolworths Group brands you know and love and a robust rewards program that celebrates and incentivises purpose-driven work.
- 12 weeks paid parental leave for primary caregivers. Woolworths Group will also continue to pay superannuation for up to 12 months (subject to relevant caps) while the Team Member is on parental leave (paid or unpaid).
- 4 weeks paid leave for secondary caregivers
- Wellness - Access to Sonder. Sonder provides free confidential 24/7 personalised financial, medical safety, psychological or physical support for team members and their families.

Everyone belongs at Woolworths Group

As one of the largest employers in Australia and New Zealand, we aim to create a truly inclusive workplace where everyone feels that they belong, can be their best selves, and reach their full potential.

Diversity, equity, inclusion, and belonging are key to realising our purpose of better together for a better tomorrow. We recognise the value our team’s diversity brings to our business, customers, and communities and that teams with diverse experiences and backgrounds enrich our group and are better able to innovate and solve problems.

📌 Senior Manager - Cyber Risk (Sydney)
🏢 Woolworths Group
📍 Sydney

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior manager - cyber risk (sydney) / sydney

Subscribe to this job alert:

Get the latest job offers by email for: senior manager - cyber risk (sydney) / sydney