Technology Governance & Risk Lead

Posted 11 Days Ago
Be an Early Applicant
Melbourne, Victoria, AUS
Hybrid
Senior level
Professional Services • Social Impact • Financial Services
The Role
Lead and mature AFCA’s technology and cyber risk framework, governance practices, risk registers, control assurance, audit remediation, policy management, third-party risk assessments, and executive reporting. Partner with technology, architecture, data, privacy, IAM, product, and delivery teams to embed secure-by-design practices and align operations with regulatory and security frameworks. Improve information protection governance and simplify or automate risk assessments, evidence collection, and reporting.
Summary Generated by Built In
Company Description

Fairness feels good

Make a real impact at AFCA. Where fairness drives every decision. Help us deliver world-class, independent complaints resolution for Australians. As a not-for-profit and progressive financial ombudsman, we’re championing positive change. Achieving our purpose takes progressive thinking, accountability and resilience. At AFCA, our inclusive leadership values every voice. We offer our people flexible work options, thoughtful benefits and opportunities to deepen expertise. Flourish in a diverse, caring culture. Feel the difference of belonging to an organisation intentionally designed to put people first.

Job Description

Help shape how technology risk is governed across one of Australia’s most important consumer-facing organisations.

AFCA is building a world-first scams prevention capability designed to benefit all Australians, alongside major transformation across digital services, identity and access management, data and technology. This role offers a rare opportunity to establish the governance, risk and assurance foundations that will help these capabilities operate securely, responsibly and at scale.

We’re looking for a Senior Technology Governance & Risk Lead to build and mature AFCA’s technology and cyber risk capability. Reporting directly to the Chief Information Security Officer (CISO), you’ll have the mandate to improve how technology risks are identified, assessed, governed and communicated across major transformation programs and business-as-usual operations.

This is a hands-on leadership role for someone who enjoys turning frameworks into practical ways of working. You’ll partner with senior technology, risk, architecture, data, privacy and delivery leaders to strengthen governance without creating unnecessary friction for delivery.

In this role you will:

  • Lead and mature AFCA’s technology and cyber risk management framework, operating model and governance practices.
  • Establish clear, actionable technology and cyber risk registers, with meaningful ownership, treatments, indicators and reporting.
  • Facilitate evidence-based risk and control assessments across technology platforms, transformation programs and operational services.
  • Coordinate remediation of audit, assurance and regulatory findings, helping accountable owners convert recommendations into deliverable actions.
  • Mature AFCA’s information security management system and control assurance practices, including evidence collection, control testing and continuous improvement.
  • Lead governance of technology and security policies, standards, exceptions and supporting processes.
  • Oversee and improve third-party technology and security risk assessments, including supply-chain, cloud, data-processing and service resilience risks.
  • Partner with technology, architecture, product and delivery teams to embed proportionate risk management and secure-by-design practices early in delivery.
  • Provide clear technology risk advice and reporting to senior leaders, governance forums and risk committees.
  • Support alignment with ISO 27001, NIST CSF, the Essential Eight, CPS 234, CPS 230, the Australian Privacy Principles and other applicable obligations.
  • Strengthen governance of information protection, classification, access, retention and secure handling in collaboration with Data Governance, Privacy, Records Management and IAM.
  • Identify opportunities to simplify and automate governance, risk assessments, evidence collection and reporting

Qualifications

You’re a strategic and commercially aware cyber risk professional who can translate complexity into clear, actionable insights.

You’ll bring:

  • Significant experience in technology risk, cyber risk, governance, assurance or a related discipline.
  • Experience building or maturing practical technology risk frameworks, risk registers and control environments.
  • Strong working knowledge of recognised frameworks such as ISO 27001, ISO42001, NIST CSF, the Essential Eight, CPS 234 or equivalent.
  • Experience coordinating audit and assurance activities and driving remediation through accountable business and technology owners.
  • Practical experience with third-party technology or security risk.
  • The ability to translate complex risk and control issues into clear decisions, priorities and executive-level reporting.
  • Confidence partnering with engineers, architects, product teams, senior leaders, risk specialists and external providers.
  • A pragmatic mindset that balances risk, regulatory expectations, customer outcomes and delivery velocity.
  • Strong written communication, facilitation and stakeholder-influencing skills.
  • Curiosity, sound judgement and a willingness to challenge established ways of working

Additional Information

  • Silver AWEI Accreditation 2025 – Recognised for LGBTQ+ workplace inclusion.
  • Accredited Family Friendly Workplace – Supporting work-life balance and inclusivity.
  • Hybrid working – Flexible arrangements with two days a week in our modern offices designed for collaboration and wellbeing.
  • Additional and inclusive leave options – Flexible public holidays, gender affirmation leave, women’s health leave, and bonus paid time off over the end of year holiday period.

To apply

If you’re passionate about fairness and believe your skills align with this role, we encourage you to apply even if you don’t meet every single criterion.

We welcome applications from people of all backgrounds, cultures, abilities, sexual orientations, and gender identities. If you require any accessibility support during the recruitment process, please reach out to our team at [email protected].

We believe fairness starts with people. That’s why we don’t use AI or automated tools to screen candidates. As a result, our processes may take a little longer, and we thank you for your patience.

About AFCA

The Australian Financial Complaints Authority (AFCA) was established in 2018 as a private not-for-profit ombudsman service providing free, fair and independent help with financial disputes. The original team has grown to over 1600 dedicated professionals. Since 2018, AFCA has received more than 634,000 complaints, helping to secure $2.1 billion in compensation for consumers. 

AFCA is a 2026 Circle Back Initiative Employer - we are committed to responding to every applicant.

Skills Required

  • Significant experience in technology risk, cyber risk, governance, assurance, or a related discipline
  • Experience building or maturing technology risk frameworks, risk registers, and control environments
  • Strong working knowledge of ISO 27001, ISO 42001, NIST CSF, Essential Eight, CPS 234, or equivalent frameworks
  • Experience coordinating audit and assurance activities and driving remediation
  • Practical experience with third-party technology or security risk
  • Ability to translate complex risk and control issues into executive-level reporting
  • Experience partnering with engineers, architects, product teams, senior leaders, risk specialists, and external providers
  • Strong written communication, facilitation, and stakeholder-influencing skills
  • Pragmatic approach balancing risk, regulatory expectations, customer outcomes, and delivery velocity
  • Curiosity, sound judgment, and willingness to challenge established ways of working
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
1,000 Employees
Year Founded: 2018

What We Do

The Australian Financial Complaints Authority (AFCA) is a private not-for-profit ombudsman service established in 2018 to provide free, fair, and independent help with financial disputes in Australia. As an external dispute resolution (EDR) company, AFCA assists consumers and small businesses who are unable to resolve complaints with member financial services organisations, championing positive change through independent, world-class complaints resolution.

Similar Jobs

Boeing Logo Boeing

Systems Engineer

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Melbourne, Victoria, AUS
170000 Employees

Boeing Logo Boeing

Senior Electronics Engineer

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Melbourne, Victoria, AUS
170000 Employees

Shield AI Logo Shield AI

Sr Director, Simulation - International (R5920)

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
In-Office
3 Locations
1-2 Annually

Xero Logo Xero

Customer Growth Specialist

Cloud • Fintech • Information Technology • Machine Learning • Software
Hybrid
Melbourne, Victoria, AUS
4500 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account