Warning! Be wary of scams. Read our FAQ page for more information.


Technology Risk Manager

Contract Type

Permanent

Location

New South Wales, Sydney

Industry

Financial Services

Specialisation

Projects & Transformation

Salary

AU$170000 - AU$180000 per annum

Contact Name

Adam Higgins

Contact Email

adam.higgins@talenza.com.au

Date published

14-08-2026

Job Reference

BBBH22279

Description

Technology Risk Manager

We're partnering with a leading Australian organisation to find an experienced Technology Risk Manager to join its Technology Governance & Risk team.

This is a high-impact opportunity for a technology risk professional who enjoys operating across technology, cyber, governance, risk, resilience and transformation and wants to play a meaningful role in strengthening technology risk maturity across a complex enterprise environment.

You'll work closely with senior technology stakeholders, Information Security, Architecture, Platform Operations, Data, Delivery, Risk, Audit and external partners to identify and manage technology risks, strengthen controls and ensure remediation outcomes are delivered and evidenced.

Reporting into the Head of Technology Governance & Risk / Technology Risk Lead, you'll be responsible for leading and supporting technology risk management, control assurance, governance and remediation activities across the technology environment.

This is a role that combines risk management with practical technology delivery. You'll provide constructive challenge to risk and control owners, help teams understand their obligations, ensure remediation is meaningful and sustainable, and provide clear insight into the organisation's technology risk profile.

Your responsibilities will include:

  • Leading and supporting the identification, assessment, monitoring and reporting of technology, cyber, cloud, supplier, data and operational resilience risks.

  • Supporting technology and risk governance forums with clear risk insights, control gaps, remediation updates, exceptions and risk acceptances.

  • Maintaining technology risk registers, issue registers, remediation plans, control evidence and risk dashboards.

  • Supporting control design, control assessments, evidence collection, assurance activities and issue closure verification.

  • Managing technology risk issues, audit findings and remediation actions through to effective and evidenced closure.

  • Providing practical risk advice and constructive challenge across technology projects, transformation, cloud services, applications, infrastructure, data and suppliers.

  • Supporting operational resilience and regulatory requirements, including APRA CPS 230 and CPS 234.

  • Contributing to executive and committee reporting covering technology risk exposure, control maturity, remediation progress, material risks and emerging themes.

  • Supporting third-party technology risk and supplier assurance activities.

  • Identifying opportunities to improve technology risk processes, governance, reporting, control maturity and issue management.

We're looking for an experienced Technology Risk professional who can operate confidently between technical teams, risk functions and senior stakeholders.

You'll ideally bring:

  • 7+ years' experience across technology risk, cyber risk, information security risk, technology governance, IT audit, control assurance, operational resilience or a related discipline.

  • Strong experience identifying, assessing and managing technology and cyber risks across complex enterprise environments.

  • Experience with risk governance, control assurance, remediation, audit actions, risk acceptance and issue management.

  • Strong understanding of technology control environments and evidence-based assurance.

  • Experience producing risk reporting, dashboards, KRIs, KCIs, committee papers and executive management information.

  • Experience providing risk advice and constructive challenge across technology change and delivery.

  • Strong stakeholder management skills, with the ability to communicate complex technology risks to both technical and executive audiences.

  • Excellent analytical skills and the ability to assess control gaps, remediation plans, evidence quality and residual risk.

  • The confidence to challenge constructively and influence outcomes without relying on direct authority.

  • A pragmatic approach to balancing risk, regulatory expectations, business outcomes and delivery timelines.

Experience with one or more of the following will be highly regarded:

  • APRA CPS 230

  • APRA CPS 234

  • ISO 27001

  • NIST CSF

  • COBIT

  • ITIL

  • CIS Controls

  • IT General Controls

  • Technology control assurance

  • Operational resilience

  • Business continuity and disaster recovery

  • Third-party / supplier technology risk

  • Cloud risk and cyber resilience

Experience within insurance, financial services or another highly regulated environment would be advantageous.

You may also have exposure to:

  • Technology risk within an APRA-regulated organisation.

  • Cyber security governance and control remediation.

  • Operational resilience uplift.

  • Internal or external audit and regulatory reviews.

  • Third-party / SaaS technology risk.

  • Cloud risk, particularly Microsoft Azure and Microsoft 365 environments.

  • Identity and access management, privileged access and change controls.

  • Vulnerability management, backup/recovery and logging/monitoring controls.

  • GRC platforms and technology risk management tools.

  • Risk acceptance and evidence-based issue closure.

Relevant certifications such as CRISC, CISA, CISM, CISSP, ISO 27001, ITIL or COBIT are desirable but not essential.

This is an opportunity to join a technology function that is actively investing in risk maturity, operational resilience, cyber security and technology transformation.

You'll have broad exposure across Technology, Security, Architecture, Data, Risk, Audit and business stakeholders, while working on initiatives that have genuine organisational impact.

If you're someone who can understand the technology, challenge the risk, influence stakeholders and make sure remediation actually happens, this role offers an excellent opportunity to step into a highly visible technology risk position.

Apply Now

File types: PDF, Microsoft Word or text