Technology Governance, Risk & Assurance Manager (City of Sydney)

Technology Governance, Risk & Assurance Manager (City of Sydney)

23 Aug
|
National Intermodal
|
City of Sydney

23 Aug

National Intermodal

City of Sydney

Sydney CBD based – close to Circular Quay

High-impact role with an emerging organisation

Reporting to the Head of Architecture, Cyber and Data

National Intermodal is a Government Business Enterprise, wholly owned by the Commonwealth of Australia, building the intermodal precincts that will reshape how goods move along Australia's east coast. It's infrastructure with a purpose: better, more sustainable supply chains that ultimately improve the way communities access the things they need. Behind that mission is a tight-knit team of engineering, rail, infrastructure and logistics specialists who think long-term and execute with precision.

About The Role

National Intermodal is seeking a Technology Governance, Risk & Assurance Manager to join our Technology function based in the Sydney CBD office. Reporting to the Head of Architecture, Cyber and Data, you will establish and operate the governance, risk, assurance and compliance disciplines that underpin our technology environment, ensuring policies, standards, risks, controls, audit findings, security vulnerabilities, supplier obligations and regulatory requirements are properly governed, evidenced, reported and actively tracked through to closure.

This is a governance and control-enablement role spanning cyber security, data, enterprise architecture, cloud services, applications, suppliers and technology operations. While you won't be expected to own technical design or system remediation, you'll bring structure, discipline and visibility to how risk and assurance are managed across the function, working closely with Technology, business and service provider teams to keep governance practical.

What You'll Be Doing

- Developing,



maintaining and continuously improving Technology policies, standards, procedures and governance artefacts, coordinating review, consultation and approval through National Intermodal's controlled document process.
- Operating the Technology assurance process, ensuring actions from audits, assessments, penetration tests and scans are reviewed, prioritised, assigned and tracked to closure.
- Maintaining the consolidated register of audit findings, vulnerabilities and management actions, escalating overdue items and residual risks where required.
- Maintaining Technology risk, issue, exception and control records, including escalation to the Executive Risk Committee and Enterprise Risk Register.
- Coordinating periodic risk and control reviews with business owners, system owners, project teams and service providers.
- Supporting Essential Eight uplift, SOCI/CIRMP obligations and ISO27001 readiness through evidence collection, remediation tracking and maturity reporting.
- Coordinating supplier technology risk assessments and maintaining supplier assurance records, due diligence evidence and remediation obligations.
- Coordinating Technology governance forums, maintaining decision logs, action registers and preparing clear reporting for executive, Audit and Risk Committee, and Board audiences.
- Supporting data governance,



identity and access governance, and resilience governance activities including disaster recovery exercises and cyber simulations.

About You

- Proven experience in technology governance, risk, compliance, assurance, audit, cyber security, enterprise risk, or technology operations.
- Experience drafting, reviewing or maintaining technology, cyber security, data or governance policies, standards and procedures.
- Practical experience maintaining registers, action trackers, risk records, control evidence and compliance artefacts.
- Solid understanding of technology risk and control concepts across cyber security, cloud, identity and access management, data governance, applications and IT operations.
- Familiarity with frameworks such as Essential Eight, ISO27001, NIST CSF, ACSC ISM, SOCI/CIRMP, ITIL or COBIT is desirable.
- Relevant certifications such as CRISC, CISA, CISM, CISSP or ISO27001 are desirable but not mandatory.
- Strong written communication skills, able to translate policy and technical detail into explicit, plain-language reporting.
- Excellent stakeholder management skills, confident engaging with executives, business owners, suppliers and technical specialists.
- High attention to detail, strong follow-through, and a bias for closing actions and clarifying ownership.Comfortable working independently in a small team, with sound judgement on when to elevate.

At National Intermodal, we are committed to our people and their development. If this sounds like the kind of role where you can bring structure, rigour and real impact to how technology risk is managed, we'd love to hear from you.

#J-18808-Ljbffr

📌 Technology Governance, Risk & Assurance Manager (City of Sydney)
🏢 National Intermodal
📍 City of Sydney

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: technology governance, risk & assurance manager (city of sydney) / city of sydney

Subscribe to this job alert:

Get the latest job offers by email for: technology governance, risk & assurance manager (city of sydney) / city of sydney