Skip to main content
AfterDuty

Manager Technology Risk

Bendigo Bank · Melbourne, Victoria

Type
Full-time
Posted
9 days ago

Overview

We’ve never been ‘just a bank’. Just like you should never be ‘just an employee’. We’re united in our belief that in banking, better can be bigger, and together we’re making it happen. It starts here. With Bendigo Bank… and you. Come and be part of our specialist Group Risk team.

About this role

We’ve never been ‘just a bank’. Just like you should never be ‘just an employee’. We’re united in our belief that in banking, better can be bigger, and together we’re making it happen.

It starts here. With Bendigo Bank… and you.

Come and be part of our specialist Group Risk team. As the banking sector rapidly evolves, so do the threats and regulatory landscapes. This is a unique opportunity to provide critical expertise, strategic thinking, and effective challenge to uplift the bank’s resilience against technology, cyber and information security risks.

As a specialist in our Group Operational Risk team, you’ll make an impact by:

  • Shaping our defences against technology risk by supporting the governance, oversight, and continuous improvement of the bank's Technology and Information Security Risk Management Framework.
  • Providing expert advice and data-driven insights on emerging threats and trends, including AI, to inform the identification and management of new risks.
  • Translating complex technology risks into clear, actionable insights that inform strategic decisions and protect the bank, our customers, and the community.
  • Collaborating across the business to provide independent challenge and embed a proactive, intelligent approach to identifying and managing technology and information security risk.

Reporting to the Senior Manager - Information Security Risk, the Manager, Technology Risk is a pivotal specialist role. You will be at the forefront of maturing the bank’s second line-of-accountability (2LoA) oversight and challenge of technology and information security risk.

You won't just be reviewing controls; you will act as a trusted advisor and constructive challenger to the business. You will play a crucial role in ensuring that as the Bank innovates in a dynamic digital environment, our risk appetite, frameworks, and policies remain robust, commercial and highly effective.

Your impact and key accountabilities

  • *Shape our Defences:*Drive the governance, oversight, and continuous improvement of the Technology and Information Security Risk Management Framework, ensuring policies and tools are future ready.
  • Independent Challenge: Provide commercial and effective 2LoA challenge over technology and information security risks, controls, and processes across the bank, influencing stakeholders to deliver superior risk outcomes.
  • Strategic Risk Advisory: Act as a subject matter expert, providing data driven insights and technical risk advisory on complex technology matters and emerging threats (including AI) to inform superior change initiatives.
  • Monitoring & Reporting: Lead the independent monitoring, validation, and reporting of the Bank's technology and information security risk profile against our Board approved Risk Appetite Statement.
  • Deep-Dive Assurance: Perform risk-based control assurance and targeted deep-dive reviews on key technology and information security controls to ensure their effectiveness.

What you’ll bring to the role

We are looking for a pragmatic risk professional who can balance strict regulatory compliance with commercial banking outcomes.

Essential

  • Extensive practical experience (typically 5+ years) in a Second Line (2LoA) Technology Risk, Cyber Governance, or IT Audit function within financial services, professional services, or a specialised risk advisory environment.
  • Proven, hands-on capability to independently execute the groundwork, end-to-end risk reviews, and control testing (fieldwork) within a dynamic, innovative digital environment
  • Deep expertise in interpreting and operationalising APRA prudential standards (specifically CPS 234, CPS 230), alongside a strong working knowledge of technology and information security frameworks (e.g., ISO27001, NIST CSF, COBIT, ITIL).
  • Strong stakeholder management skills, with the ability to provide professional leadership, constructively challenge the status quo, and influence First Line (1LoA) teams to deliver superior risk outcomes.
  • Excellent interpersonal, verbal, and written communication skills, with a proven ability to synthesise complex, technical cyber issues into highly polished, executive-ready risk papers and actionable insights that inform strategic decisions.

Highly desirable

  • Industry recognised certifications (e.g. CISA, CRISC, CISM, CISSP, COBIT Foundations etc.).
  • Exposure to assessing emerging technology risks such as Cloud, Artificial Intelligence (AI) security risk governance.
  • A relevant tertiary or professional qualification in a related field.

This is a permanent full-time position preferrably located in Melbourne or Adelaide.

We offer flexible work options that put our people first, working in a hybrid model with a minimum local Head Office attendance requirement determined by your Leader, to find a rhythm that works best for you and your team.

Internal Applications

Please note, all internal candidates are required to notify their immediate leader when applying for a new career opportunity and you will be asked to acknowledge they have done so upon submission of your application.

For more information, check out the Application Process for Internal Candidates  page.

So, why work for us?

Want big impact that matters? Here, you’ll know your work directly benefits the customers and communities we all serve. You’ll also get access to a great range of benefits, including:

  • Flexibility means different things for different people. Whether it’s hybrid work, flexible hours, a compressed work week, job-sharing or something different, our flexible work options are designed to put people first.
  • Health and wellbeing support, including discounted gym memberships, private health insurance options, and our Employee Assistance Program (EAP) for you and your immediate family members.
  • Opportunities to take your learning to the next level through our corporate university ‘BEN U’ or at an external provider of your choice.

We believe a diverse workforce supported by an inclusive culture is central to our success and we actively encourage applications from those who bring diversity of thought to our business. We support candidate requests for adjustment to accommodate an illness, injury, or disability to equitably participate in the selection process.

Still in two minds?

Research suggests 60% of women and underrepresented groups might stop here, even after getting as far as drafting an application. We believe that diversity makes every team stronger, so even if you don’t tick every box, we still want to see your application!

We’re making better, bigger. And we’ll get there with you.

Now’s the time to set your sights even higher on the future you and the future career you deserve.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Melbourne

Why this fits a police background

  • Working to legislation & regulation

More cyber security & digital forensics jobs for ex-police

  • Control Manager Vulnerability Management

    Commonwealth Bank · Melbourne

    Full-time

    Control Manager, Vulnerability Management Do you thrive at the intersection of cyber security, technology, and stakeholder engagement? Help drive vulnerability remediation, shape governance practices, and make a real impact across the organisation.

    Posted 6 days ago

  • Information Security & Risk Analyst

    The Royal Australian College of General Practitioners (RACGP) · Melbourne

    Full-time

    Your incident command and threat assessment experience maps directly to security risk and resilience work.

    Posted 8 days ago

  • Contract

    Your experience with evidence handling and regulatory compliance maps directly to security assurance and vendor risk assessment.

    Posted 8 days ago

  • Cloud Security Engineer

    IFM Investors · Melbourne

    Full-time

    About Us JOB DESCRIPTION IFM Investors is a global asset manager, founded and owned by pension funds, with capabilities in infrastructure equity and debt, private equity, private credit, real estate and listed equities.

    Posted 13 days ago