Technology Governance & Risk Lead
- Full-time
Company Description
Fairness feels good
Make a real impact at AFCA. Where fairness drives every decision. Help us deliver world-class, independent complaints resolution for Australians. As a not-for-profit and progressive financial ombudsman, we’re championing positive change. Achieving our purpose takes progressive thinking, accountability and resilience. At AFCA, our inclusive leadership values every voice. We offer our people flexible work options, thoughtful benefits and opportunities to deepen expertise. Flourish in a diverse, caring culture. Feel the difference of belonging to an organisation intentionally designed to put people first.
Job Description
Help shape how technology risk is governed across one of Australia’s most important consumer-facing organisations.
AFCA is building a world-first scams prevention capability designed to benefit all Australians, alongside major transformation across digital services, identity and access management, data and technology. This role offers a rare opportunity to establish the governance, risk and assurance foundations that will help these capabilities operate securely, responsibly and at scale.
We’re looking for a Senior Technology Governance & Risk Lead to build and mature AFCA’s technology and cyber risk capability. Reporting directly to the Chief Information Security Officer (CISO), you’ll have the mandate to improve how technology risks are identified, assessed, governed and communicated across major transformation programs and business-as-usual operations.
This is a hands-on leadership role for someone who enjoys turning frameworks into practical ways of working. You’ll partner with senior technology, risk, architecture, data, privacy and delivery leaders to strengthen governance without creating unnecessary friction for delivery.
In this role you will:
- Lead and mature AFCA’s technology and cyber risk management framework, operating model and governance practices.
- Establish clear, actionable technology and cyber risk registers, with meaningful ownership, treatments, indicators and reporting.
- Facilitate evidence-based risk and control assessments across technology platforms, transformation programs and operational services.
- Coordinate remediation of audit, assurance and regulatory findings, helping accountable owners convert recommendations into deliverable actions.
- Mature AFCA’s information security management system and control assurance practices, including evidence collection, control testing and continuous improvement.
- Lead governance of technology and security policies, standards, exceptions and supporting processes.
- Oversee and improve third-party technology and security risk assessments, including supply-chain, cloud, data-processing and service resilience risks.
- Partner with technology, architecture, product and delivery teams to embed proportionate risk management and secure-by-design practices early in delivery.
- Provide clear technology risk advice and reporting to senior leaders, governance forums and risk committees.
- Support alignment with ISO 27001, NIST CSF, the Essential Eight, CPS 234, CPS 230, the Australian Privacy Principles and other applicable obligations.
- Strengthen governance of information protection, classification, access, retention and secure handling in collaboration with Data Governance, Privacy, Records Management and IAM.
- Identify opportunities to simplify and automate governance, risk assessments, evidence collection and reporting
Qualifications
You’re a strategic and commercially aware cyber risk professional who can translate complexity into clear, actionable insights.
You’ll bring:
- Significant experience in technology risk, cyber risk, governance, assurance or a related discipline.
- Experience building or maturing practical technology risk frameworks, risk registers and control environments.
- Strong working knowledge of recognised frameworks such as ISO 27001, ISO42001, NIST CSF, the Essential Eight, CPS 234 or equivalent.
- Experience coordinating audit and assurance activities and driving remediation through accountable business and technology owners.
- Practical experience with third-party technology or security risk.
- The ability to translate complex risk and control issues into clear decisions, priorities and executive-level reporting.
- Confidence partnering with engineers, architects, product teams, senior leaders, risk specialists and external providers.
- A pragmatic mindset that balances risk, regulatory expectations, customer outcomes and delivery velocity.
- Strong written communication, facilitation and stakeholder-influencing skills.
- Curiosity, sound judgement and a willingness to challenge established ways of working
Additional Information
- Silver AWEI Accreditation 2025 – Recognised for LGBTQ+ workplace inclusion.
- Accredited Family Friendly Workplace – Supporting work-life balance and inclusivity.
- Hybrid working – Flexible arrangements with two days a week in our modern offices designed for collaboration and wellbeing.
- Additional and inclusive leave options – Flexible public holidays, gender affirmation leave, women’s health leave, and bonus paid time off over the end of year holiday period.
To apply
If you’re passionate about fairness and believe your skills align with this role, we encourage you to apply even if you don’t meet every single criterion.
We welcome applications from people of all backgrounds, cultures, abilities, sexual orientations, and gender identities. If you require any accessibility support during the recruitment process, please reach out to our team at [email protected].
We believe fairness starts with people. That’s why we don’t use AI or automated tools to screen candidates. As a result, our processes may take a little longer, and we thank you for your patience.
About AFCA
The Australian Financial Complaints Authority (AFCA) was established in 2018 as a private not-for-profit ombudsman service providing free, fair and independent help with financial disputes. The original team has grown to over 1600 dedicated professionals. Since 2018, AFCA has received more than 634,000 complaints, helping to secure $2.1 billion in compensation for consumers.
AFCA is a 2026 Circle Back Initiative Employer - we are committed to responding to every applicant.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply