ISMS Manager at nib Group | Newcastle, AU | Rezi

ISMS Manager at nib Group

ISMS Manager

nib Group · Newcastle, AU

Today

ISMS Manager

nib Group · Newcastle, AU

14 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

As the ISMS Manager, you will lead the ongoing operation and continuous improvement of nib Group’s Information Security Management System (ISMS), ensuring alignment with ISO 27001 standards and evolving business needs. You will act as a subject matter expert, coordinating audits, risk assessments, control frameworks, and compliance activities across the Group, while partnering closely with Cyber, SecOps, Enterprise Risk, technology, and business teams. You will also oversee PCI compliance, contract security obligation management, policy governance, and technology risk initiatives.

Responsibilities

  • Lead the ongoing operation and continuous improvement of nib Group’s Information Security Management System (ISMS).
  • Ensure alignment with ISO 27001 standards and evolving business needs.
  • Coordinate audits, risk assessments, control frameworks, and compliance activities across the Group.
  • Partner closely with Cyber, SecOps, Enterprise Risk, technology, and business teams.
  • Oversee PCI compliance.
  • Manage contract security obligations.
  • Oversee policy governance.
  • Oversee technology risk initiatives.

Requirements

  • Strong experience in technology risk, governance, and assurance within complex enterprise environments.
  • Deep understanding of how effective controls and frameworks support business objectives while managing risk.
  • Confident partnering with stakeholders across technology, risk, and compliance functions to drive governance outcomes and strengthen organizational resilience.
  • Hands-on experience operating and continuously improving a certified ISO 27001 Information Security Management System (ISMS).
  • Solid understanding of regulatory and industry frameworks such as APRA CPS 220, CPS 234, and PCI DSS.
  • Experience developing, implementing, and maintaining control effectiveness measures, including Control Self-Assessments (CSAs), Key Risk Indicators (KRIs), and Key Performance Indicators (KPIs).
  • Experience working with stakeholders to develop, implement, review, and mature governance and assurance controls, with a focus on driving a culture of transparency and IT risk awareness within an enterprise setting.
  • Demonstrated experience in supporting technology audits as a key stakeholder.
  • Excellent verbal and written communication skills.
  • Confidence and competence presenting to a range of technology and business stakeholder cohorts.
  • A hunger for knowledge in the IT Risk and cyber security space.
  • High-level working understanding and familiarity with current cyber security controls and concepts.
  • Working knowledge of relevant cybersecurity frameworks and standards, including NIST CSF, ASD Essential Eight.
  • Knowledge of Australian privacy obligations and their intersection with information security design.
  • Successful applicants will be required to complete a background check (including criminal history and bankruptcy check) prior to commencement of employment.

Skills

  • ISO 27001
  • Information Security Management System (ISMS)
  • APRA CPS 220
  • CPS 234
  • PCI DSS
  • Control Self-Assessments (CSAs)
  • Key Risk Indicators (KRIs)
  • Key Performance Indicators (KPIs)
  • NIST CSF
  • ASD Essential Eight
  • Cybersecurity
  • IT Risk
  • Governance
  • Assurance
  • Risk Management
  • Compliance

Location

  • Hybrid

Work Type

  • Hybrid
  • Full-time

Experience Level

  • Senior

Education Level

  • Information science, computer science, cybersecurity or equivalent computing degree highly regarded
  • Cybersecurity and IT Risk certifications (e.g. CRISC, CGRC, CISSP) are highly regarded

Benefits

  • New starter benefit to help set up a functional home workspace
  • 50% discount on employee health insurance
  • 35% off travel insurance
  • Paid volunteering leave supported by the nib foundation
  • Access to our nib Well Program
  • Corporate fitness discounts
  • Access to employee share plans
  • Short-term incentive program
  • Life and salary continuance insurance benefits
  • 18 weeks paid parental leave for all new parents regardless of carer status
  • 5 days paid cultural leave for First Nations peoples
  • 4 weeks paid gender affirmation leave for trans, gender diverse and intersex employees

About the Company

  • nib is a leader in private health insurance, disability support and health services, reshaping the industry through bold innovation, strategic disruption and trusted partnerships.
  • We deliver great value health insurance and support services to protect, connect and empower you to access healthcare when and where you need.
  • We have a mission and vision of people enjoying better health.
  • Through our success, we aspire to more prosperous and sustainable communities, helping members and travellers make more informed healthcare decisions and generally live healthier lives.

Equal Opportunity

  • We embrace a flexible working environment and welcome candidates who reflect the diversity of the communities in which we operate.
  • We're committed to an environment where everyone has the autonomy and freedom to be their authentic selves, every day.
  • We encourage Aboriginal and Torres Strait Islander peoples, people living with disability, veterans, LGBTQIA+ as well as culturally diverse community members to apply for open roles.
  • We’re committed to creating an accessible recruitment process and employment experience.
  • All your information will be kept confidential according to EEO guidelines.
  • We acknowledge Aboriginal and Torres Strait Islander peoples as the Traditional Custodians of the lands where we live, learn and work.