Australian Financial Complaints Authority (AFCA) Logo

Australian Financial Complaints Authority (AFCA)

Technology Governance & Risk Lead

Posted 7 Days Ago
Be an Early Applicant
Hybrid
Melbourne, Victoria, AUS
Senior level
Hybrid
Melbourne, Victoria, AUS
Senior level
Lead and mature AFCA’s technology and cyber risk framework, governance practices, risk registers, control assurance, audit remediation, policy management, third-party risk assessments, and executive reporting. Partner with technology, architecture, data, privacy, IAM, product, and delivery teams to embed secure-by-design practices and align operations with regulatory and security frameworks. Improve information protection governance and simplify or automate risk assessments, evidence collection, and reporting.
The summary above was generated by AI
Company Description

Fairness feels good

Make a real impact at AFCA. Where fairness drives every decision. Help us deliver world-class, independent complaints resolution for Australians. As a not-for-profit and progressive financial ombudsman, we’re championing positive change. Achieving our purpose takes progressive thinking, accountability and resilience. At AFCA, our inclusive leadership values every voice. We offer our people flexible work options, thoughtful benefits and opportunities to deepen expertise. Flourish in a diverse, caring culture. Feel the difference of belonging to an organisation intentionally designed to put people first.

Job Description

Help shape how technology risk is governed across one of Australia’s most important consumer-facing organisations.

AFCA is building a world-first scams prevention capability designed to benefit all Australians, alongside major transformation across digital services, identity and access management, data and technology. This role offers a rare opportunity to establish the governance, risk and assurance foundations that will help these capabilities operate securely, responsibly and at scale.

We’re looking for a Senior Technology Governance & Risk Lead to build and mature AFCA’s technology and cyber risk capability. Reporting directly to the Chief Information Security Officer (CISO), you’ll have the mandate to improve how technology risks are identified, assessed, governed and communicated across major transformation programs and business-as-usual operations.

This is a hands-on leadership role for someone who enjoys turning frameworks into practical ways of working. You’ll partner with senior technology, risk, architecture, data, privacy and delivery leaders to strengthen governance without creating unnecessary friction for delivery.

In this role you will:

  • Lead and mature AFCA’s technology and cyber risk management framework, operating model and governance practices.
  • Establish clear, actionable technology and cyber risk registers, with meaningful ownership, treatments, indicators and reporting.
  • Facilitate evidence-based risk and control assessments across technology platforms, transformation programs and operational services.
  • Coordinate remediation of audit, assurance and regulatory findings, helping accountable owners convert recommendations into deliverable actions.
  • Mature AFCA’s information security management system and control assurance practices, including evidence collection, control testing and continuous improvement.
  • Lead governance of technology and security policies, standards, exceptions and supporting processes.
  • Oversee and improve third-party technology and security risk assessments, including supply-chain, cloud, data-processing and service resilience risks.
  • Partner with technology, architecture, product and delivery teams to embed proportionate risk management and secure-by-design practices early in delivery.
  • Provide clear technology risk advice and reporting to senior leaders, governance forums and risk committees.
  • Support alignment with ISO 27001, NIST CSF, the Essential Eight, CPS 234, CPS 230, the Australian Privacy Principles and other applicable obligations.
  • Strengthen governance of information protection, classification, access, retention and secure handling in collaboration with Data Governance, Privacy, Records Management and IAM.
  • Identify opportunities to simplify and automate governance, risk assessments, evidence collection and reporting

Qualifications

You’re a strategic and commercially aware cyber risk professional who can translate complexity into clear, actionable insights.

You’ll bring:

  • Significant experience in technology risk, cyber risk, governance, assurance or a related discipline.
  • Experience building or maturing practical technology risk frameworks, risk registers and control environments.
  • Strong working knowledge of recognised frameworks such as ISO 27001, ISO42001, NIST CSF, the Essential Eight, CPS 234 or equivalent.
  • Experience coordinating audit and assurance activities and driving remediation through accountable business and technology owners.
  • Practical experience with third-party technology or security risk.
  • The ability to translate complex risk and control issues into clear decisions, priorities and executive-level reporting.
  • Confidence partnering with engineers, architects, product teams, senior leaders, risk specialists and external providers.
  • A pragmatic mindset that balances risk, regulatory expectations, customer outcomes and delivery velocity.
  • Strong written communication, facilitation and stakeholder-influencing skills.
  • Curiosity, sound judgement and a willingness to challenge established ways of working

Additional Information

  • Silver AWEI Accreditation 2025 – Recognised for LGBTQ+ workplace inclusion.
  • Accredited Family Friendly Workplace – Supporting work-life balance and inclusivity.
  • Hybrid working – Flexible arrangements with two days a week in our modern offices designed for collaboration and wellbeing.
  • Additional and inclusive leave options – Flexible public holidays, gender affirmation leave, women’s health leave, and bonus paid time off over the end of year holiday period.

To apply

If you’re passionate about fairness and believe your skills align with this role, we encourage you to apply even if you don’t meet every single criterion.

We welcome applications from people of all backgrounds, cultures, abilities, sexual orientations, and gender identities. If you require any accessibility support during the recruitment process, please reach out to our team at [email protected].

We believe fairness starts with people. That’s why we don’t use AI or automated tools to screen candidates. As a result, our processes may take a little longer, and we thank you for your patience.

About AFCA

The Australian Financial Complaints Authority (AFCA) was established in 2018 as a private not-for-profit ombudsman service providing free, fair and independent help with financial disputes. The original team has grown to over 1600 dedicated professionals. Since 2018, AFCA has received more than 634,000 complaints, helping to secure $2.1 billion in compensation for consumers. 

AFCA is a 2026 Circle Back Initiative Employer - we are committed to responding to every applicant.

Similar Jobs

6 Hours Ago
Hybrid
Melbourne, Victoria, AUS
Entry level
Entry level
Cloud • Fintech • Information Technology • Machine Learning • Software
Drive revenue growth across small and medium-sized business accounts through high-volume outbound campaigns. Promote Stripe, GoCardless, and other financial integrations; manage account pipelines, track conversion metrics, maintain Salesforce records, and optimize messaging. The role requires consultative communication, consistent performance against activity targets, and collaboration with Marketing, Data Science, and Customer Success teams.
Top Skills: GocardlessSalesforceStripe
6 Hours Ago
Hybrid
Melbourne, Victoria, AUS
Entry level
Entry level
Cloud • Fintech • Information Technology • Machine Learning • Software
Drive small-business revenue growth through high-volume outbound campaigns. Promote integrated payment and financial solutions, manage conversion pipelines, track sales activity and metrics, maintain Salesforce records, and optimize messaging based on customer insights. The role requires consultative communication, proactive prospecting, pipeline management, and collaboration with Marketing, Data Science, and Customer Success teams in a hybrid work environment.
Top Skills: GocardlessSalesforceStripe
10 Hours Ago
Remote or Hybrid
Melbourne, Victoria, AUS
Senior level
Senior level
Cloud • Fintech • Information Technology • Machine Learning • Software
Lead development of full-stack customer-facing features and refactor monolithic systems using React, Redux, C#, ASP.NET Core, and SQL Server. Drive architecture improvements on AWS, integrate AI-assisted tools and automated agents, participate in on-call incident response, and mentor engineers while promoting CI/CD and TDD practices.
Top Skills: Ai-Assisted Development ToolsAsp.Net CoreAutomated AgentsAWSC#Ci/CdReactReduxRest ApisSdksSQL ServerTest-Driven DevelopmentWebforms

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account