IT Controls, Risk
Vor 7 Tagen
IT Controls, Risk & Audit Assurance Manager The IT Controls, Risk & Audit Assurance Manager leads the oversight, development, and execution of organization-level IT control frameworks, risk assurance, and audit engagement activities. Operating independently, the role is responsible for ensuring that IT operations, projects, and systems meet internal control standards, regulatory expectations, and audit readiness across all technology domains. The incumbent serves as the central point of coordination and escalation for all IT-related assurance matters and will actively engage with IT, second-line Risk/Compliance, and third line Internal/External Audit functions. The team IT Controls, Risk and Audit Assurance Manager, reporting to the Head of IT Governance in DTS (Data, Technology & Security) Department, is part of the IT Governance team. This team collaborates with stakeholders across the organisation to establish process and policies for managing IT, ensuring alignment between technology and business, with focus on managing risks and compliance with frameworks. Key stakeholders include the CIO, CTO, Architecture, Enterprise Security, and Product delivery teams, along with the Chief Information Security Officer, Chief Data Officer, Chief Risk Officer, and Project Management Office. Key Responsibilities Build, design, implement and maintain a clearly documented, auditable, and updated IT control framework (e.g., PSPF, ISM, NIST-aligned) that applies across infrastructure, applications, and cloud environments. End‑to‑end ownership of IT‑related audits (internal/external/regulatory); issues addressed with validated evidence and sustained resolution. Create a detailed RCM process and perform periodic RCMs, control testing, and deep dives performed across IT domains with stakeholder engagement and risk‑informed actions. Ensure all IT compliance obligations (e.g., PSPF, ISM) are mapped to controls; periodic assurance performed with documented evidence and reporting. Ensure all policies and processes are in place, up to date, accurate and regularly reviewed. Ensure regular and timely production of executive‑level dashboards (e.g., audit status, risk posture, control effectiveness), used in governance forums. Perform root‑cause analysis and ensure remediation plans for control gaps are defined, tracked, and independently validated. Provide subject‑matter expertise on IT risk identification, assessment and mitigation strategies. Be an active contributor to Risk and Audit Committees; trusted advisor to senior IT leadership. Supports or leads configuration and operation of Governance, Risk and Compliance platforms. Oversee the assessment and management of risks associated with third‑party vendors and service providers including FOCI risks, ensuring they meet the organization's IT control standards and compliance requirements. Lead and drive continuous improvement initiatives within the IT control and audit processes to enhance efficiency and effectiveness. Perform an advisory role in new system designs, major IT projects, and transformation initiatives to embed ‘right‑first‑time’ controls. Develop and deliver training and awareness programs to ensure that all relevant stakeholders are knowledgeable about IT control frameworks, risk management practices, and audit requirements. Maintain regular communication with key stakeholders, providing updates on IT control, risk, and audit activities, and ensuring alignment with business objectives and driving a risk‑aware culture. About you Extensive experience in IT audit, technology risk management, IT control assurance, including direct leadership roles. Strong background in regulated environments, particularly banking, insurance, or capital markets. Proven record of leading audit and regulatory engagements (e.g., PSPF, ISM, NIST etc.). Experience building and managing enterprise‑wide control frameworks and assurance programs across hybrid IT environments. Desirable Professional Certification – CISA, CISM, CRISC or equivalent. To work with us, you must be an Australian citizen with eligibility to gain a NV1 clearance through the Australian Government Security Vetting Agency. About APRA Australian Prudential Regulation Authority (APRA) was established in 1998 as an independent statutory authority that supervises almost 1,200 financial institutions that manage $8.6 trillion in assets for Australians across the banking, insurance and superannuation sectors. In overseeing the safety, competitiveness and stability of the financial system, we seek to recruit, develop and retain highly skilled professionals, who want to help shape financial services and protect the financial wellbeing of the Australian community. Our employee base of almost 900 come predominantly from the commercial financial services industry or other government agencies; as such, we have the feel of a small corporate organisation that can work flexibly and with agility. Why Work for APRA We recognise the skills, experience and commitment that our staff bring to their professional lives, and we seek to reward them accordingly. We also recognise that for our staff to be able to perform at their best, we need to ensure that they are able to bring their best selves to work. Our commitment to wellbeing is having engaged people supported by resilient leaders within a values‑aligned culture. At APRA, we’re committed to providing an inclusive workplace where everyone belongs, feels valued and respected. We aspire to attract and foster diversity of background, thought, and experience, recognising that a broad range of perspectives, approaches and ideas makes us stronger, and better enables us to meet our obligation to protect the financial wellbeing of the Australian community. If you need any adjustments during the recruitment process, please inform at application stage so we can do our best to accommodate your requirements. The Australian Prudential Regulation Authority (APRA) is the prudential regulator of the financial services industry. It oversees banks, credit unions, building societies, general insurance and reinsurance companies, life insurance, private health insurers, friendly societies, and most members of the superannuation industry. APRA currently supervises institutions holding $6 trillion in assets for Australian depositors, policyholders and superannuation fund members. APRA invests in contemporary technologies to enable our employees to achieve work life balance, via flexible working practices. We are dedicated to cultivating a diverse and inclusive workplace that fosters collaboration and continuous improvement. APRA provides ongoing studies support, structured training programs and excellent career progression opportunities all within a highly professional environment. APRA is an affirmative action and equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, age, or disability status. To apply, please visit our Careers Page at For further information or assistance, please Please do not apply to this email address. #J-18808-Ljbffr
-
Senior IT Controls, Risk
Vor 7 Tagen
Council of the City of Sydney, Österreich Australian Prudential Regulation Authority VollzeitA governmental financial authority in Australia is seeking an experienced IT Controls, Risk & Audit Assurance Manager to oversee the execution of IT control frameworks and manage internal audits. The role requires extensive experience in technology risk management and compliance within regulated environments, along with a proven ability to manage complex...
-
Risk & Controls Analyst - 12MFTC
Vor 7 Tagen
Council of the City of Sydney, Österreich Police Bank Ltd. VollzeitWho are we? Police Bank is one of Australia’s fastest growing Mutual Banks. We are a progressive, purpose-driven financial institution, and we pride ourselves on offering a competitive range of financial products and services, all of which have been created with the needs of our members front of mind. What are we looking for? As a Risk & Advisory Analyst,...
-
Risk & Controls Analyst - 12MFTC
Vor 7 Tagen
Council of the City of Sydney, Österreich Police Bank Ltd. VollzeitPolice Bank is one of Australia’s fastest growing Mutual Banks. We are a progressive, purpose-driven financial institution, and we pride ourselves on offering a competitive range of financial products and services, all of which have been created with the needs of our members front of mind. What we’re looking for? As a Risk & Advisory Analyst, you will...
-
Risk and Controls Specialist
Vor 5 Tagen
Council of the City of Sydney, Österreich DLL Group VollzeitAs Risk and controls Specialist y ou will review and execute the RCF controls and independently verify and challenge the effectiveness of the controls. You will also support the Australia and New Zealand region with design and implementation of risks and controls, based on the Global Risk and Control Framework. You will report to the Integrated Risk Manager...
-
Manager Risk and Controls
vor 2 Wochen
Council of the City of Sydney, Österreich Commonwealth Bank VollzeitBusiness Banking (BB) manages relationships with Commonwealth Bank’s small-medium enterprise customers, mid-market corporate customers, and regional and agribusiness customers, providing a wide range of financial services and solutions. It also services our personal and institutional online trading customers. BB Digital is accountable for delivering a...
-
Manager, Risk, Compliance and Controls
vor 4 Wochen
Council of the City of Sydney, Österreich AMP VollzeitJob Description If you live in Australia or New Zealand, you’ve likely heard of AMP. But at a time when society is changing, we are too. We’re now a nimbler business with new leadership and thinking. For us, these are exciting times. There’s a real potential for big thinkers to help us redefine what financial services could be. And turn our legacy into...
-
Manager Risk and Controls
Vor 3 Tagen
Council of the City of Sydney, Österreich Commonwealth Bank of Australia VollzeitSee yourself in our team : Business Banking (BB) serves the banking needs of Australian businesses. As part of the Small Business Banking (SBB), you will support the distribution of Business Banking and Retail Banking products via our channels. Small Business Banking (SBB) is responsible for managing customers with SBB Line 1 Risk & Control Advisory &...
-
Strategic Risk
Vor 7 Tagen
Council of the City of Sydney, Österreich 12 Month Contract VollzeitA premier entertainment hub in Sydney is seeking a Risk & Controls Analyst to enhance operational risk documentation and perform control assessments. The ideal candidate has strong business analysis skills, excellent communication, and a background in risk management. You will facilitate communication across teams and propose actionable recommendations. The...
-
Controls Assurance Analyst — Elevate Risk
vor 2 Wochen
Council of the City of Sydney, Österreich Avant Mutual VollzeitA leading medical defence organization in New South Wales is seeking a Controls Assurance Analyst to join their Medical Indemnity Risk team. In this role, you will manage the controls assurance plan, test effective controls, and foster a strong controls culture. Ideal candidates will have a strong background in controls assurance methodologies and excellent...
-
Risk and Controls Analyst in Sydney
vor 2 Wochen
Council of the City of Sydney, Österreich Echo Entertainment Group VollzeitFor two decades, The Star Sydney has been a local landmark, deeply ingrained in Pyrmont and Darling Harbour. Committed to our communities, we strive to create fun in trusted destinations as Australia's premier entertainment hub. The Darling, and state-of-the-art venues including The Star Event Centre and The Lyric Theatre have hosted prestigious events and...