- Full Time | 9 day fortnight | 36 hours
- Salary: From $111,401 plus Superannuation
- Position Brief - Technology Risk Adviser
About the role
Sitting within the City’s Enterprise Risk team, this role provides an organisation-wide perspective on technology risk and resilience.
You will be a key conduit between the broader business, the Chief Technology Officer and Cyber Security - helping business leaders understand their technology risks and dependencies, while ensuring service impacts and priorities are visible to technology specialists.
You will bring an independent enterprise risk lens to technology and cyber issues, translate technical information into practical business advice and help establish clear ownership of risks, controls and actions.
This is more than a register-management role. You will help shape a developing capability, deliver meaningful assurance and strengthen the resilience of services that directly support the community.
What you’ll be doing
- Facilitate technology and cyber risk assessments across business and technical teams.
- Translate technical issues into clear service, organisational and community impacts.
- Connect business areas with CTO and Cyber Security expertise and support.
- Develop an enterprise view of strategic and critical technology risks.
- Deliver targeted assurance over key technology and cybersecurity controls.
- Strengthen technology disaster recovery and its alignment with business continuity.
- Identify emerging risks, systemic issues and opportunities for improvement.
- Provide independent, practical advice and constructive challenge.
- Deliver clear, decision-focused reporting to senior leaders and governance forums.
What you’ll bring
- Experience in technology risk, cybersecurity risk, IT governance, control assurance, disaster recovery or a related discipline.
- The ability to bridge technical and business perspectives and turn complex information into practical advice.
- Experience facilitating risk assessments, control reviews or assurance activities with technical and business stakeholders.
- A sound understanding of technology controls, system dependencies and operational resilience.
- Strong analytical, stakeholder engagement, influencing and communication skills.
- The confidence to provide independent advice and constructive challenge.
- The ability to work with a high degree of independence and professional judgement.
Highly regarded
- Experience with recognised risk, technology or cybersecurity frameworks, such as ISO 31000, ISO 27001, NIST or COBIT.
- Experience in disaster recovery, business continuity or technology resilience.
- Knowledge of cloud, third-party or technology supply-chain risk.
- Experience in a complex, regulated, public-sector or essential-services environment.
- Relevant qualifications or certifications in risk, cybersecurity, IT governance, audit or business continuity