Skip to main content
AfterDuty

Risk Manager

Downer Group · Melbourne, Victoria

Type
Full-time
Posted
Yesterday

Overview

Your experience in operational risk assessment, threat evaluation and multi-agency coordination translates well to the governance and risk management aspects of this role. You are accustomed to making balanced decisions under pressure and advising senior stakeholders, which aligns with the risk advisory and reporting duties. However, the role requires specialised technical knowledge of cyber security frameworks and IT systems, so you would need to demonstrate relevant retraining or experience.

About this role

We are excited to offer an exceptional opportunity for an experienced and strategic Risk Manager*to join Downer's *Governance, Risk & Compliance*team within *Group Technology.

This is a key leadership role suited to a professional who thrives in a complex technology environment and is passionate about strengthening technology and cyber risk management practices across a large and diverse organisation.

Reporting to the Head of Governance, Risk & Compliance, you will lead the technology risk management function across Downer, ensuring technology and cyber security risks are effectively identified, assessed, monitored, treated and reported. You will provide independent risk oversight, advisory support and governance leadership across Group Technology and Business Units, helping drive informed decision-making and improved risk outcomes.

Working closely with Cyber Security, Enterprise Risk, Group Technology leaders and key business stakeholders, you will be instrumental in embedding effective risk management practices, enhancing governance processes and providing meaningful risk insights that support Downer's strategic objectives and risk appetite.

Operating within a product-led DevOps environment, you will partner with teams across the entire technology lifecycle, supporting secure, resilient and risk-informed delivery outcomes.

This role can be based in Sydney (North Ryde), Melbourne (Collins Street), Perth (High Wycombe).

*About the Role

In this role you will

  • Lead technology and cyber security risk assessments across systems, projects, suppliers, operational services, business changes and strategic initiatives.
  • Maintain technology risk registers, treatment plans, risk acceptances, exceptions and governance reporting.
  • Partner with Technology, Cyber Security and business stakeholders to identify, assess and manage technology risks.
  • Translate technical vulnerabilities, control weaknesses and threat intelligence into clear business risk outcomes and treatment recommendations.
  • Support risk governance processes including risk acceptance, exception management, escalation and reporting activities.
  • Monitor remediation and risk treatment activities, ensuring actions are effectively tracked and risks are reduced in a timely manner.
  • Deliver meaningful risk reporting, analytics, key risk indicators (KRIs) and emerging risk insights to technology leadership.
  • Provide trusted risk advisory services to projects, operational teams, suppliers and business stakeholders.
  • Drive continuous improvement of technology risk management frameworks, processes and practices.
  • Lead and develop Risk Analyst capability while promoting a strong risk culture across Group Technology.

This is a highly visible leadership role where you will influence strategic decision-making while strengthening technology resilience, governance and risk maturity across the organisation.

Our Ideal Candidate

You have strong experience managing technology and cyber security risks within complex enterprise environment.

You are comfortable engaging with both technical and non-technical stakeholders, translating complex technical issues into clear business risks and practical remediation strategies. You bring strong governance capability, sound judgement and the ability to influence outcomes at all levels of the organisation.

What You Will Bring

  • Bachelor's degree in cyber security, Information Technology, Computer Science, Management Information Systems or a related discipline.
  • Demonstrated experience in technology risk management, cyber security, governance, risk and compliance environments.
  • Strong understanding of risk management frameworks including NIST, ISO 27001 and ASD Essential Eight.
  • Experience leading technology and cyber risk assessments, maintaining risk registers and driving remediation activities.
  • Ability to translate technical vulnerabilities, threats and control gaps into business-focused risk insights.
  • Strong stakeholder engagement skills with experience facilitating risk workshops and influencing decision-making.
  • Experience preparing executive reporting, dashboards and governance updates.
  • Leadership experience with the ability to coach, mentor and develop team members.
  • Industry certifications such as CRISC, CISA, CISM, CISSP or equivalent will be highly regarded.
  • ITIL Foundation or service management experience will be advantageous.

You are recognised for your ability to build trusted relationships, challenge constructively, influence outcomes and deliver pragmatic risk solutions that support both security and business objectives.

*Benefits Of Working with Downer

  • Work with an ASX-listed company, working with market leaders.
  • Grow your career with us through personal and professional development and continuous learning:
  • Professional development programs
  • Access to professional memberships and industry networks
  • Be part of a team that cares, with support that is flexible around employee wellbeing needs:
  • Flexible work arrangements
  • Parental leave
  • Employee Assistance Program
  • Programs promoting diversity and inclusion

A range of corporate benefits, including

Discounted services (car hire, hotels, insurance, retail stores, gyms)

Why Downer?

As a trusted name in infrastructure, transport, facilities management, and construction, Downer is committed to delivering projects that create a lasting, positive legacy.

We're committed to building a team that reflects the diverse communities we serve, and we welcome people of all ages, genders, sexual orientations, cultures, abilities, and lived experiences. We especially encourage applications from those whose voices have traditionally been underrepresented in our industry, including women, Aboriginal and Torres Strait Islander Peoples, Māori and Pasifika Peoples, veterans, people with disability, and neurodivergent individuals.

Even if your experience doesn't align perfectly with this role, we'd still like to hear from you. If it feels like the right fit, apply — potential counts, and so do you.

As a WORK180 Endorsed Employer, we support flexibility that works for your life, inclusive leadership that values your voice, and equitable access to opportunity so you can do your best work and bring your whole self to it.

About risk & resilience roles for ex-police

Risk management, business continuity and emergency-planning roles. Contingency planning, threat assessment and multi-agency coordination experience from policing is directly transferable.

See all risk & resilience jobs in Melbourne

Why this fits a police background

  • Intelligence & OSINT
  • Risk & threat assessment
  • Working to legislation & regulation
  • Team & shift leadership

More risk & resilience jobs for ex-police

  • Operation Risk Manager

    HCLTech · Melbourne

    Full-time

    This role draws directly on your experience of operational risk assessment, incident management and multi-agency coordination from policing. You have run command-and-control structures, managed critical incidents and maintained risk registers under pressure — all of which map onto the core responsibilities here. Your background in regulatory compliance (PACE, CPIA) and assurance testing gives you a credible foundation for control design and effectiveness reviews, even if you will need to build sector-specific knowledge of APRA and financial-services frameworks.

    Posted 6 days ago

  • Emergency Management Coordinator

    Royal Melbourne Hospital · Melbourne

    Full-time

    Your experience in incident command, multi-agency coordination, and contingency planning during policing maps directly onto this emergency management role. You've run real-time responses under pressure, exercised threat assessment, and maintained operational plans—all core to strengthening a hospital's resilience and preparedness programs.

    Posted 7 days ago

  • Emergency Management Coordinator

    Royal Melbourne Hospital · Melbourne

    Full-time

    Your experience in incident command, multi-agency coordination and contingency planning during major operations and public order events maps directly onto this role's focus on emergency preparedness, exercising and incident management support. You are used to maintaining plans under pressure, conducting debriefs and building relationships with external partners — exactly what this hospital needs to strengthen its resilience and response capability.

    Posted 7 days ago

  • Risk Analyst

    NSW Government · Sydney

    Full-time

    A$133,348 – A$146,945Estimated

    Your operational policing background gives you a strong grounding in risk assessment, contingency planning and multi-agency coordination, which are directly relevant to this risk analyst role. You are used to making defensible decisions under uncertainty, running incident command and thinking through business continuity implications, all of which map onto the core responsibilities here. Your ability to communicate complex risk information to a wide range of stakeholders will help you thrive in this corporate environment, even if you need to pick up specific GRC platform skills.

    Posted 5 days ago