About the Role
Shape how cyber risk is understood, managed, and governed across a complex enterprise. Work at the intersection of cyber security, risk, and business decision making to create safer outcomes for customers, partners, and communities. Partner with stakeholders across technology, risk, legal, and procurement, bringing technical insight and practical thinking to important conversations. This role offers an opportunity to make a meaningful impact by solving complex problems, influencing outcomes, and turning cyber challenges into clear actions.
Responsibilities
- Develop and maintain cyber security policies, standards, and control frameworks that support effective risk management and regulatory compliance.
- Assess cyber risks, exceptions, and threat scenarios, recommending practical mitigation strategies aligned with business objectives.
- Review and test security controls to evaluate effectiveness, identify gaps, and strengthen the overall control environment.
- Provide trusted advice on cyber governance and security requirements in partnership with technology, risk, legal, and procurement teams.
- Manage policy exception processes, ensuring risks, actions, and approvals are documented and tracked to completion.
- Evaluate third-party and supplier cyber risks, including security obligations within contracts and vendor assurance activities.
Requirements
- Experience in cyber governance, risk, compliance, or security assurance environments.
- Ability to translate technical cyber risks into clear, business-focused recommendations.
- Knowledge of security frameworks, controls, and risk assessment methodologies.
- Strong communication and stakeholder engagement skills across diverse audiences.
- Confidence reviewing policies, standards, control effectiveness, or regulatory requirements.
- Curiosity, sound judgment, and a willingness to keep learning and growing.
- Experience in financial services or regulated environments is welcomed but not essential.
Skills
- Cyber security
- Risk management
- Business decision making
- Stakeholder engagement
- Policy development
- Control frameworks
- Risk assessment
- Security controls
- Third-party risk evaluation
- Vendor assurance
Location
- Naarm (Melbourne)
- Gadigal Country (Darling Park 2, Sydney)
- Meanjin (Brisbane)
Work Type
- Permanent
- Full-time
Benefits
- Boosted superannuation with 13% as standard.
- 20 days annual leave + 5 days MyLeave.
- Up to 50% off personal insurance (home and motor).
- Partner discounts on private health insurance, tech & appliances, and more.
- Industry-leading 20 weeks paid parental leave.
- Access to LinkedIn Learning, the IAG Academy, study assistance, and secondment opportunities.
About the Company
- IAG is the largest general insurance group in Australia and New Zealand.
- Our purpose is to make your world a safer place by helping everyday Aussies and New Zealanders, supporting their ambitions, and making insurance accessible.
- As part of IAG, you'll enjoy a world of career opportunities, a purpose-led place focused on creating connection and belonging, and where you can create meaningful impact every day and grow your career beyond the expected.
- We celebrate all viewpoints shaped by life experiences and culture, and are guided by the knowledge and voice of Aboriginal and Torres Strait Islander peoples, businesses, and communities.
- We collaborate on Indigenous-led solutions that enable growth and create meaningful change for our customers and employees.
