Skip to main content
AfterDuty

Data & AI Security Lead

Downer · Melbourne, Victoria

Type
Full-time
Posted
10 days ago

Overview

Your experience managing threats and coordinating incident response under pressure directly applies to data and AI security risks.

About this role

This is an exciting opportunity for an experienced cyber security professional who combines strong technical expertise with strategic thinking and stakeholder influence. You will lead the development of data and AI security standards, provide expert guidance on emerging technology risks, and help ensure security is embedded into Downer's rapidly evolving digital landscape.

Reporting to the Cyber Platform Manager (SecOps), this role sits within the Security Engineering & Platforms team and works closely with Cyber Security, Group Technology, Risk, Privacy, Legal and business stakeholders to deliver secure, practical and risk-aligned outcomes.

This role offers the opportunity to influence security strategy and drive meaningful outcomes across some of Downer's most critical operational environments.

The position can be based in Sydney (North Ryde), Melbourne (Collins Street) or Brisbane (Milton).

In this role you will

  • Define and maintain data and AI security standards, controls, policies and governance frameworks aligned to Downer's cyber strategy and risk appetite.
  • Provide security-by-design guidance to support the safe adoption of data platforms, analytics capabilities and AI-enabled solutions.
  • Assess data and AI security risks, including data handling, access controls, model risks, automation risks and third-party dependencies.
  • Partner with Privacy, Legal, Risk, Architecture, Application Security and Technology teams to embed security controls into business and technology initiatives.
  • Support monitoring, incident response activities and remediation planning for data and AI security events.
  • Develop reporting and insights on data and AI security posture, emerging risks, control maturity and remediation activities.
  • Drive awareness and education across the organisation to promote responsible and secure use of data and artificial intelligence.
  • Translate complex technical risks into clear business recommendations and actionable outcomes.
  • Champion the development and implementation of AI solutions within the wider cyber security team.

This is a highly visible role where you will contribute to strategic decision-making while helping shape the future of data and AI security across a large and diverse enterprise environment.

Our Ideal Candidate

You are a collaborative and forward-thinking cyber security professional with strong expertise in data protection, governance and risk management. You are comfortable navigating emerging technologies, influencing stakeholders, and balancing security requirements with business objectives.

You bring a pragmatic approach to problem-solving and enjoy working across technical and non-technical teams to deliver practical, effective security outcomes.

What You Will Bring

  • Bachelor's degree in cyber security, computer science, information technology, management information systems or equivalent practical experience.
  • 7+ years' commercial experience in information technology or cyber security, with relevant experience in the role domain.
  • Demonstrated working knowledge of NIST standards, ISO/IEC 27001, ASD Essential Eight and cyber security controls.
  • Relevant professional certifications such as CISSP, CISM, CISA, CRISC, CompTIA Security+ or equivalent are desirable.
  • ITIL Foundation or equivalent service management experience is desirable.
  • Data governance, privacy, AI governance or data security-related training is desirable.
  • Experience supporting data security, information protection, privacy-aligned risk management or AI governance activities.
  • Strong experience assessing security risks for data platforms, analytics, automation or AI-enabled solutions.
  • Experience working with Privacy, Legal, Risk, Architecture, Data and Technology stakeholders.
  • Experience translating data and AI security risks into business impact and practical controls.
  • Extensive experience preparing guidance, reporting and governance materials for emerging technology risks.

Why Downer?

As a trusted name in infrastructure, transport, facilities management, and construction, Downer is committed to delivering projects that create a lasting, positive legacy.We're committed to building a team that reflects the diverse communities we serve, and we welcome people of all ages, genders, sexual orientations, cultures, abilities, and lived experiences. We especially encourage applications from those whose voices have traditionally been underrepresented in our industry, including women, Aboriginal and Torres Strait Islander Peoples, Māori and Pasifika Peoples, veterans, people with disability, and neurodivergent individuals.

Even if your experience doesn't align perfectly with this role, we'd still like to hear from you. If it feels like the right fit, apply - potential counts, and so do you.

As a WORK180 Endorsed Employer, we support flexibility that works for your life, inclusive leadership that values your voice, and equitable access to opportunity so you can do your best work and bring your whole self to it. c

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Melbourne

Why this fits a police background

  • Incident command & response
  • Security operations

More cyber security & digital forensics jobs for ex-police

  • Control Manager Vulnerability Management

    Commonwealth Bank · Melbourne

    Full-time

    Control Manager, Vulnerability Management Do you thrive at the intersection of cyber security, technology, and stakeholder engagement? Help drive vulnerability remediation, shape governance practices, and make a real impact across the organisation.

    Posted 6 days ago

  • Information Security & Risk Analyst

    The Royal Australian College of General Practitioners (RACGP) · Melbourne

    Full-time

    Your incident command and threat assessment experience maps directly to security risk and resilience work.

    Posted 8 days ago

  • Contract

    Your experience with evidence handling and regulatory compliance maps directly to security assurance and vendor risk assessment.

    Posted 8 days ago

  • Cloud Security Engineer

    IFM Investors · Melbourne

    Full-time

    About Us JOB DESCRIPTION IFM Investors is a global asset manager, founded and owned by pension funds, with capabilities in infrastructure equity and debt, private equity, private credit, real estate and listed equities.

    Posted 13 days ago