About the Role
KBR is seeking an experienced and strategic APAC Cybersecurity Compliance Manager to drive and implement cybersecurity and compliance initiatives across KBR's APAC operations. This role ensures the confidentiality, integrity, and availability of information assets while supporting business objectives and fostering a strong security culture.
Responsibilities
- Develop and implement APAC cybersecurity strategies aligned with corporate policies, regional regulations, and business objectives.
- Establish and maintain security policies, standards, and procedures.
- Partner with business leaders to integrate cybersecurity considerations into decision-making and operational processes.
- Provide regional leadership on information security governance and compliance initiatives.
- Conduct regular security risk assessments across APAC operations.
- Identify vulnerabilities, threats, and emerging risks.
- Develop and implement mitigation strategies and security controls.
- Monitor compliance with applicable laws, regulations, customer requirements, and contractual obligations.
- Support regional cybersecurity incident response activities.
- Conduct post-incident reviews and lessons-learned exercises.
- Drive continuous improvement initiatives to strengthen security resilience and reduce future risk.
- Develop and deliver security awareness and education programs for employees, contractors, and third-party partners.
- Foster a culture of security awareness across the organisation.
- Communicate emerging threats, risks, and best practices to stakeholders.
- Assess cybersecurity risks associated with vendors, suppliers, and business partners.
- Perform security due diligence activities.
- Collaborate with Procurement and Legal teams to ensure appropriate security obligations are embedded within contracts and agreements.
- Develop security performance metrics and reporting frameworks.
- Provide regular updates to the CISO organisation and business leadership on security posture, compliance activities, risks, and incidents.
- Identify trends and opportunities for improvement through security reporting and analysis.
- Coordinate and support internal and external security audits.
- Manage remediation activities arising from audit findings.
- Ensure ongoing compliance with regulatory, contractual, and organisational security requirements.
Requirements
- Ability to obtain an Australian Government Security Clearance.
- Significant experience in information security management, cybersecurity compliance, risk assessment, and incident response.
- Strong understanding of cybersecurity governance frameworks, controls, and regulatory requirements.
- Experience engaging with senior stakeholders and influencing business outcomes.
- Excellent analytical, problem-solving, communication, and interpersonal skills.
- Demonstrated ability to lead initiatives and promote a strong security culture.
Skills
- Strong knowledge of information security principles, technologies, and best practices.
- Experience working with recognised security frameworks and standards, including: ISO 27001, NIST Cybersecurity Framework, Australian Essential Eight Maturity Model, Australian Information Security Manual (ISM), Defence Industry Security Program (DISP).
- Understanding of emerging cyber threats, attack vectors, and security trends.
Location
- APAC
Work Type
- Flexible work arrangements
Experience Level
- Experienced
Education Level
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related discipline.
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- Other relevant cybersecurity certifications
Salary/Compensations
- Industry leading salaries reviewed annually.
Benefits
- Flexible work arrangements (start/finish times, WFH, Flex time)
- Salary packaging and novated leases
- Paid professional membership fees
- Life/Health insurance discounts
- Employee stock purchase plans
- Personal career development plans
- Growth and promotion opportunities
About the Company
- At KBR, you'll have the opportunity to work on complex and meaningful projects while helping protect critical business operations across the APAC region.
- You'll be part of a global cybersecurity team, influence strategic security outcomes, and contribute to a culture that values innovation, collaboration, and continuous improvement.
