Head of Cyber Risk & Governance
- 499129
- All States, Australia
- Norwest, NSW, Australia, 2153
- Permanent Full-Time
- Lead BaptistCare's enterprise cyber risk and governance function across a national organisation
- Partner with Executive leaders and governance committees to influence strategic cyber risk decisions
- Hybrid leadership opportunity driving cyber resilience, governance maturity, and secure digital transformation
Shape the Future of Cyber Risk for One of Australia’s Largest Purpose-Driven Organisations
At BaptistCare, we believe technology should enable better outcomes for the communities we serve. As we continue our transformation as a newly unified national organisation, we're seeking an experienced Head of Cyber Risk & Governance to lead and mature our enterprise cyber risk capability.
Reporting to the GM Cyber & IT Risk, this is a nationally focused leadership role responsible for establishing and strengthening cyber risk governance, policy frameworks, executive reporting, and enterprise-wide risk oversight across a complex and highly regulated environment.
This is a unique opportunity to influence strategic decision-making at the executive level while helping to protect the systems, services, data, and people that support thousands of Australians every day.
About the Role
As Head of Cyber Risk & Governance, you will provide strategic leadership across cyber risk management, governance, policy development, compliance oversight, and executive reporting.
Partnering closely with senior leaders across Information & Digital, Risk, Legal, Privacy, Procurement and the broader business, you'll ensure cyber and technology risks are effectively identified, managed, and reported while supporting innovation and digital transformation initiatives.
- Own and lead BaptistCare's enterprise cyber risk management framework, ensuring cyber and technology risks are identified, assessed, treated, monitored, and reported effectively.
- Lead the day-to-day cyber risk governance function, embedding strong risk management practices across the organisation.
- Chair and facilitate the Cyber Risk Committee, driving effective governance, escalation, and oversight of cyber risk matters.
- Partner closely with Executive leaders, the Chief Risk Officer, and business stakeholders to improve cyber risk awareness, accountability, and decision-making.
- Develop, maintain, and continuously improve cyber security policies, standards, and governance frameworks aligned with regulatory requirements and industry best practice.
- Ensure cyber governance frameworks align with relevant legislation, including the Aged Care Act, privacy obligations, and other regulatory requirements.
- Drive a strong cyber risk culture across BaptistCare through education, engagement, and capability-building initiatives.
- Lead enterprise-wide cyber risk assessments, including technology, operational, strategic, and emerging risks.
- Oversee third-party cyber risk management, including supplier assessments, ongoing monitoring, and governance of outsourced technology services.
- Provide strategic oversight of emerging technology risks, including AI-enabled solutions and digital transformation initiatives.
- Deliver high-quality cyber risk reporting, insights, and recommendations to Executive leadership, governance forums, and Board committees.
- Build and lead a high-performing Cyber Risk & Governance team, consisting of specialist cyber governance, third-party risk, and information management professionals.
- Work collaboratively across Information & Digital, Risk, Legal, Privacy, Procurement, and Compliance functions to strengthen enterprise risk management outcomes.
- Support BaptistCare's ongoing transformation journey by ensuring cyber risk considerations are embedded into strategic initiatives and technology investment decisions.
About You
- Extensive leadership experience in Cyber Risk, Governance, GRC, Technology Risk, Operational Risk, or Information Security within a large and complex environment.
- Proven experience designing and implementing enterprise cyber risk management and governance frameworks.
- Strong understanding of regulatory and compliance obligations within highly regulated industries.
- Experience influencing executives, risk committees, and Board stakeholders.
- Demonstrated experience leading third-party risk management and supplier assurance programs.
- Strong knowledge of NIST CSF, ISO 27001, ASD Essential Eight, and contemporary cyber risk practices.
- Experience gained within aged care, health, banking, financial services, or other highly regulated sectors will be highly regarded.
- Professional certifications such as CISM, CRISC, or equivalent cyber risk/governance certifications are highly desirable.
- Ability to translate complex cyber risks into practical business outcomes and drive organisational risk maturity.
About Us:
We are proud to be part of the merged care organisation that will be known nationally as BaptistCare. As a for purpose, Christian care organisation, we are committed to providing exceptional support and services across Australia. Together with Baptcare (VIC, TAS, SA) and Baptist Care SA we employ over 12,000 dedicated employees and support over 38,000 customers to help people live well with dignity and purpose. From older Australians and their families to people facing significant disadvantage, our passion and our priority are the customers we serve. We strive to deliver care as it should be – with people right at the centre.
We love what we do and the communities we help. With us you can deliver life transforming care, create a career you’ll love, and join a team who make a difference.
If you would like to be considered for this role, please click ‘’Apply’’ and attach your resume.
Applicants are encouraged to apply as soon as possible as applications may be reviewed prior to the closing date. Closing Date is subject to change without notice.
Successful applications will be subject to a variety of background checks including police background check via our online police check system.
BaptistCare – Transforming lives by expressing the love of Christ.
Please note: This position is being managed directly by our internal Talent Acquisition team. We respectfully request that recruitment agencies refrain from contacting any employees directly as all communications must go through the Talent Acquisition. Unsolicited candidate profiles or CVs from recruitment agencies will not be accepted. Thank you.