About the role
We are seeking an experienced Information Security Manager to lead the delivery of cyber security governance, risk, compliance, and assurance activities across our customer and internal environments. In this role, you will partner with business and technology stakeholders to strengthen cyber resilience, manage security risks, ensure compliance with regulatory and industry frameworks, and provide strategic security guidance.
You will play a critical leadership role in protecting information assets, driving continuous improvement initiatives, and fostering a strong security culture while supporting the successful delivery of business objectives.
Australian Citizenship is mandatory. Current or reinstatable AGSVA NV2 Security clearance required.
Location: Canberra or Brisbane location
Responsibilities and Accountabilities
- Lead the delivery of information security governance, risk management, compliance, and assurance services across client and business environments.
- Develop, maintain, and improve security frameworks, policies, standards, procedures, and controls.
- Conduct security risk assessments and provide practical recommendations to mitigate identified risks.
- Partner with business leaders, technology teams, and external stakeholders to embed security-by-design principles into projects and operations.
- Ensure compliance with relevant regulatory, contractual, and industry security requirements.
- Monitor emerging cyber threats, vulnerabilities, and industry trends, providing proactive guidance and recommendations.
- Establish and maintain security reporting, metrics, dashboards, and governance forums to communicate cyber risk posture.
- Lead and coordinate security incident management activities, including escalation, investigation support, and post-incident reviews.
- Manage security audits, compliance assessments, and remediation activities.
- Provide leadership, coaching, and mentoring to security team members and broader business stakeholders.
- Collaborate with clients and internal teams to identify opportunities for security improvement and service enhancement.
- Support business development activities by contributing security expertise to proposals, solution design, and customer engagements.
Requirements and Experience
Essential
- 7+ years of experience in Information Security, Cyber Security, Risk Management, or Governance, Risk & Compliance (GRC).
- Australian Citizenship is mandatory. Current or reinstatable AGSVA NV2 Security clearance required.
- Demonstrated experience leading security programs, teams, or managed security services.
- Strong knowledge of security governance, risk assessment methodologies, and compliance frameworks.
- Experience developing and implementing information security policies, standards, and controls.
- Strong understanding of incident management, vulnerability management, and security assurance practices.
- Experience working within complex enterprise or managed services environments.
- Excellent stakeholder management skills with the ability to influence at senior leadership levels.
- Strong analytical, problem-solving, and decision-making capabilities.
- Excellent written and verbal communication skills, including executive-level reporting and presentations.
Preferred
- Industry certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent.
- Knowledge of security frameworks and standards including:
- ISO 27001 / ISO 27002
- NIST Cyber Security Framework
- Essential Eight
- ISM / PSPF
- CIS Controls
- Experience with cloud security technologies and platforms, including Microsoft Azure, Microsoft Defender, Sentinel, and Microsoft 365 Security.
- Experience supporting security audits, regulatory reviews, and compliance initiatives.
- ITIL Foundation or experience working within IT Service Management environments.