Clothing, Apparel, Helmet, Hardhat, Person, Hat

Cyber Risk & Compliance Manager

  • 495524
  • Sydney, NSW, Australia
  • Brisbane, QLD, Australia
  • Melbourne, VIC, Australia
  • Perth, WA, Australia

Show More Show Less

  • Information Technology
  • Full time
View favourites

About Laing O'Rourke

Laing O’Rourke is a $6 billion global engineering and manufacturing-led construction leader, delivering state-of-the-art infrastructure and buildings projects. In Australia, we’ve proudly operated under the Laing O’Rourke banner for over 20 years, building on more than 70 years of local expertise.

Driven by our purpose - pushing the boundaries of what’s possible, in service of humanity - we create safer hospitals, cleaner water, secure defence facilities, and better-connected cities. We also build meaningful careers and inclusive workplaces where people thrive. Backed by global strength and deep local roots, our unique operating model combines cutting-edge technology with modern methods of construction to deliver certainty for clients and transform how infrastructure is engineered and built.

We also own two vertically integrated businesses: Select Plant Australia, the nation’s fourth-largest plant hire company, and Laing O’Rourke Rail Operations, supporting major projects and nationwide rail maintenance.

That’s the Power of Experience.

About the role

We are currently seeking a Cyber Security Risk & Compliance Manager to join our global security team. 

The Cyber Security Risk & Compliance Manager will play a leading role in establishing and maintaining ongoing compliance requirements for cyber certifications controls (e.g. ACSC Essential Eight, NCSC Cyber Essentials), managing vendor risk management and supporting the ISO27001 certification.

The role can be a hybrid in office or fully remote role, based anywhere in Australia. This is due to the requirement that the role partially flexes their working week to attend UK Hub meetings 2-3 days a week.

Key responsibilities

  • Manage and maintain the governance framework, processes, and policies supporting the global cyber certification programmes.
  • Assist in managing ISO 27001 risks and controls, including coordinating internal and external audit activities for the Australia business.
  • Support the business stakeholders in developing and maintaining cyber security policies that are appropriate for our business sector.
  • Collaborate with the Cyber Security GRC Team to ensure alignment with global cyber risk frameworks, control standards, and uplift initiatives.
  • Lead engagement with internal stakeholders and relevant governing bodies to coordinate and deliver the annual Cyber Essentials and Essential Eight audit and assessment program.
  • Identify, assess, and continuously monitor cyber security risks across the Australia business.
  • Work with business units and risk functions to assess impacts, define security requirements, and ensure risks are managed in line with global risk frameworks.

About you

  • A minimum of five years of IT experience in an information security role.
  • Three to 5 years’ experience in IT Governance, Risk and Compliance related roles. 
  • Experience of working with multiple stakeholders.
  • Experience with the implementation, governance and compliance of common information security regulations, certifications and management frameworks including ISO 27001, Essential Eight, UK Cyber Essentials, NIST CSF and European GDPR.
  • Strong interpersonal, presenting and management level communication skills, supported by strong problem-solving ability.
  • Ability to obtain Australian Government security clearance.

Benefits

We work hard to create an environment that brings out the best in our people. We believe in building careers through providing a safe, connected and innovative culture that supports ongoing growth and development. We offer industry-leading benefits such as specialised learning and development programs, a mental health and wellbeing program, industry leading paid parental leave policy, an additional purchased leave option and coaching programs for staff on parental leave.

Diversity & Inclusion

We are committed to building a workforce that reflects the diverse society in which we live and work. Laing O’Rourke is recognised as a WGEA Employer of Choice for Gender Equality in 2020, 2022, 2024 and 2026. We know that the right culture and purposeful innovation are key to delivering impact.

Laing O'Rourke actively supports a diverse workforce and strongly encourages applications from Aboriginal and Torres Strait Islander Peoples and people from culturally diverse backgrounds. Download our Stretch Reconciliation Action Plan at https://www.laingorourke.com/company/diversity-and-inclusion

Applications from recruitment agencies will not be considered.

Can’t find the job you’re looking for? We are in the process of migrating our open opportunities to this new site. Click below to visit our former careers site for more vacancies.

Click Here