Manager, Cyber Security and AI (Tasmania)

Manager, Cyber Security and AI (Tasmania)

30 Sep
|
Australian Children'S Education & Care Quality Authority
|
Tasmania

30 Sep

Australian Children'S Education & Care Quality Authority

Tasmania

Manager, Cyber Security and AI

· Help children have the best start in life through high quality education & care.

· Improve outcomes for children and families in early education and care.

· Join an expert team working across governments at the national level.

About ACECQA

We want children in Australia to have the best start in life through quality education and care.

We provide national leadership on the implementation of the National Quality Framework (NQF) and collaborate with the Australian and state and territory governments to:

· implement changes that benefit children birth to 13 years-of-age and their families

· monitor and promote the consistent application of the Education and Care Services National Law across all states and territories

· support the early childhood education and care sector to improve quality outcomes for children

We strive for innovation and continuous improvement and are committed to keeping the sector and the community informed with the latest developments in early childhood education and care.

ACECQA is committed to being a child-safe organisation, implementing the National Principles for Child Protected Organisations and actively promoting the safety and wellbeing of children.

The Role The Manager, Cyber Security and AI leads the development, implementation and continuous improvement of ACECQA’s cyber security and AI strategy, policies, systems and governance frameworks. The role ensures compliance with legal, regulatory and risk obligations, provides expert advice to support secure technology decision-making, and drives the delivery of secure systems through effective controls, tools and practices. Working closely with IT, developers, risk and privacy teams, and external vendors, the position oversees security and AI policy, standards and assurance activities, while partnering with IT Operations to ensure security controls are effectively implemented and maintained across the organisation

This role is full-time and ongoing at ACECQA Band 7/8 ($151,513 - $203,841).

Key Accountabilities

· Lead the development, implementation and regular review of ACECQA’s cyber security and AI strategy, plans, systems, policies and standards, proactively assessing ACECQA’s security posture for weaknesses and defensive gaps and ensuring secure-by-design principles reduce risk. This role is accountable for security and AI policy, standards and assurance; while working alongside the Manager IT Operations who is accountable for implementing and operating controls in the corporate environment.

· Lead and manage ACECQA’s security operations (SecOps) function including security event monitoring, advanced analysis of potential incidents and incident response, operating a joint SecOps model with the Manager IT Operations and IT Operations team. The role recommends security standards, priorities, risk tolerances and assurance requirements and IT Operations delivers day-to-day implementation, hardening, patching and remediation.

· Report to and support ACECQA’s cyber security governance forums, including the Cyber Security Governance Committee, and prepare regular reports, risk assessments, metrics and briefings for Executive, the Audit Finance and Risk Committee and the Board, covering compliance with ACECQA policies and the Protective Security Policy Framework (PSPF), Information Security Manual (ISM) and ASD Essential Eight, and driving Essential Eight maturity uplift against target levels and remediation roadmaps.

· Oversee delivery of and reporting against ACECQA’s Cyber Security and AI Strategy and Plan, including secure enablement and ongoing administration of ACECQA’s enterprise AI capability Microsoft 365 Copilot readiness and rollout,



data governance and access boundary controls, sensitivity labelling, data loss prevention and the secure use of AI agents, plug-ins and automation.

· Undertake AI system risk assessments, maintain the approved AI systems list and audit and report on AI use under ACECQA’s Artificial Intelligence Policy and Guidelines.

· Oversee risk and cyber security assessments (penetration tests, vulnerability scans) and phishing simulation exercises, tracking remediation to closure with IT Operations, and act as the escalation point for sensitive and critical incidents, coordinating stakeholder communication on status and impact under ACECQA’s incident response plans, and running response exercises and post-incident reviews.

· Collaborate with the Cyber Security Manager Regulatory Systems to develop and maintain cyber security plans, controls and mitigations that protect the reliability and security of ACECQA’s NQA IT System, including delivery of the NQA ITS IRAP Plan of Action and Milestones and PCI DSS compliance obligations.

· Build cyber security capability across ACECQA through knowledge sharing, mentoring and coaching of IT and cyber professionals, staff awareness training, phishing simulations, security advisories and development plans aligned to ACECQA’s objectives.

· Plan and manage cyber security projects to deliver new capabilities on time and on budget, validate IT infrastructure and reference architectures against security best practice, recommend changes to reduce risk, and contribute with IT Operations to disaster recovery, contingency and business continuity planning.

· Manage ACECQA’s third-party and supply chain security risk framework including vendor security assessments, contract security requirements and ongoing assurance of cloud and SaaS providers to ensure ACECQA and its technology service providers meet ACECQA’s compliance, legal and regulatory obligations, with IT Operations responsible for day-to-day vendor and service management.

· Undertake other related duties as directed from time to time.

Key Selection Criteria

· Demonstrated experience leading cyber security and security operations (SecOps) services and teams within a government or medium-sized corporate environment, including working in close partnership with IT operations teams.

· Demonstrated experience adopting the Protective Security Policy Framework (PSPF), Information Security Manual (ISM) and ASD frameworks, and standards such as ISO 27001, NIST and/or MITRE ATT&CK;, applying cyber security and privacy principles across both corporate and digital service delivery environments.

· Demonstrated experience developing and governing organisational AI strategy and assurance, including AI system risk assessment, approved system registers, secure integrations and controls for AI-specific threats, aligned with ACECQA’s AI policy and relevant frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework.

· Demonstrated experience securely deploying and administering Microsoft 365 Copilot or similar AI platforms, including tenant readiness, permissions remediation, oversharing controls, sensitivity labelling, data loss prevention and search scoping.

· Strong people leadership, analytical and stakeholder influencing skills including staff development,



performance management and the ability to guide technical teams to adopt cyber security practices.

· Proven ability to articulate cyber security risk confidently and concisely to staff, senior management and executive, and to design security awareness, training and phishing simulation campaigns.

· Demonstrated experience in IT risk management, including a solid understanding of frameworks such as ISO 31000, ISO 27005 and/or NIST 800-37.

· Demonstrated experience in security architecture and considerations related to cloud-based services (PaaS, IaaS, SaaS) in a Microsoft Azure/M365 environment.

· Demonstrated experience in the implementation and use of cyber security and AI technologies, such as vulnerability management, authentication and access control, next-gen firewalls, phishing simulators, data loss protection, endpoint protection, SIEM/SOAR, CASB, and AI security tooling (e.g. Microsoft Purview, Defender for Cloud Apps, Copilot audit and DSPM capability).

Highly desirable skills, knowledge, and experience:

· Tertiary qualification in IT and/or equivalent industry certifications within the field of information and cyber security such as CISM, CISA, CRISC, CGEIT, GIAC, CISSP, CEH.

· Experience and/or knowledge of CRM, ERP, ECM and HCM platforms such as Salesforce, Microsoft Dynamics 365, Technology One Finance, HP Content Manager/TRIM and ichris.

· Demonstrated experience with PCI-DSS (Payment Card Industry Data Security Standard) compliance.

· Solid understanding of web application security and secure software development best practices including OWASP, Secure SDLC and DevSecOps.

· Experience in driving and maturing an organisations enterprise security architecture using frameworks such as SABSA, TOGAF and/or COBIT.

· Demonstrated experience in information systems auditing

· Experience or formal qualification in IT project management such as PMP, PRINCE 2, AgilePM.

How to apply The closing date for applications is 6 October 2026 at 11.59pm.

Important Note: Please ensure you follow the recruitment process outlined below, otherwise you may not be considered for the role.

To apply, please register with the ACECQA Recruitment Candidate Portal, navigate to Manager, Cyber Security and AI vacancy and click Apply for Job. The application process will require you to:

· Attach a CV of no more than 5 pages which demonstrates your ability to meet the criteria contained in the position description.

· Provide the details of at least two referees who have directly supervised you within the last five years of employment.

· Attach a written response to the targeted questions below of no more than 2 pages.

Targeted Questions

1. Describe an IT or cyber security and AI strategy or system you have led and describe how it improved support for business operations or its cyber security posture.
2. Outline your approach to the leadership and management of governance, risk and compliance in IT, cyber security and AI.

All complete applications will be acknowledged.

More information

If you have any questions about the role or recruitment process, please contact the Recruitment team at [email protected].

Notice to agencies

ACECQA will not accept applications from any source other than directly from a candidate for this vacancy. Recruitment agencies must have received instructions from ACECQA in relation to a specific vacancy in order to submit applications on behalf of candidates.

ACECQA is collecting the information requested in the advertisement for the purpose of selection, recruitment and engagement of staff. ACECQA is authorised to do so by the Education and Care Services National Law. Please refer to our Privacy Policy which can be accessed at http://www.acecqa.gov.au/privacy-policy.

📌 Manager, Cyber Security and AI (Tasmania)
🏢 Australian Children'S Education & Care Quality Authority
📍 Tasmania

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: manager, cyber security and ai (tasmania) / tasmania

Subscribe to this job alert:

Get the latest job offers by email for: manager, cyber security and ai (tasmania) / tasmania