Senior Manager Technology Risk & Controls Enablement
Sydney, New South Wales, Australia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About ASX
ASX powers Australia's financial markets, serving as a leading global securities exchange and trusted market operator, renowned for its dynamic data hub. The organization values diversity and inclusiveness, fostering a workplace where employees thrive across various disciplines including technology, operations, financial products, risk, compliance, and more. ASX is dedicated to equality, wellbeing, and community engagement, supporting flexible working arrangements and hosting multiple employee-led inclusion networks.
Key Role Purpose
This position is responsible for leading line 1 technology risk enablement and controls at ASX by translating enterprise risk frameworks into a structured technology risk taxonomy, control environment, and assessment approach. The goal is to support robust, scalable management of risks and meet regulatory and assurance requirements effectively.
Team Context
The role sits within the Technology Risk, Business Management & Strategy team, which helps the ASX Technology division handle technology risk, governance, planning, and operating rhythms. This function supports technology leaders to manage risks, comply with regulations, and maintain governance and performance standards.
Primary Responsibilities
- Lead line 1 technology risk and controls enablement, translating enterprise risk and compliance frameworks into applicable and scalable approaches aligned with ASX Technology and cyber risk specifics.
- Design, maintain, and govern taxonomies, metrics, control frameworks, policies, and assessment methodologies for technology and cyber risk, ensuring coherence, usability, alignment with expectations, and incorporation of best practices.
- Identify and address risk and control gaps by developing new approaches, defining target-state practices, implementation plans, guidance, and transition strategies to advance maturity levels.
- Manage the IT General Controls (ITGC) library, including documentation upkeep, change facilitation, and coordination of controls rollout and assurance procedures.
- Enhance system-level risk reporting by integrating data-driven insights to reflect risk maturity.
- Provide expert line 1 input to enterprise frameworks for risk, compliance, and criticality tiering, ensuring technology and cyber risks are properly represented and grounded in operational realities.
- Develop guidance, playbooks, and educational resources to boost division-wide understanding and embed risk and controls into everyday technology delivery and operations.
- Drive continuous improvements in the technology risk ecosystem through simplification, standardization, automation, and clear ownership allocation.
- Lead and mentor a team of risk professionals, managing competing priorities and elevated risk exposure, fostering autonomy, reducing dependency risks, and elevating risk maturity through pragmatic simplification and standardization.
Experience and Qualifications
- Extensive experience in technology risk and/or compliance functions (Line 1, 2, or 3) with proven ability to independently lead senior line 1 roles.
- Proficient in translating enterprise risk standards into relevant technology risk practices, ensuring consistent operational embedding across complex environments.
- Strong expertise in technology and cyber risk, capable of engaging with technical experts and designing practical risk controls informed by operational context.
- Track record of developing and maintaining risk and control artifacts such as taxonomies, control libraries, and assessment approaches with scalability and usability.
- Sound judgment on system-level risks, adept at defining high-quality scalable standards, managing trade-offs, incorporating feedback, and adapting methods to maintain usability and consistency.
- Leadership skills demonstrated through work in ambiguous and evolving conditions, able to structure tasks, set priorities, and deliver results without relying on predefined frameworks.
- Experience in people leadership—direct, indirect, or matrix—including coaching and developing skilled practitioners to foster autonomous decision-making and sound risk judgment.
Preferred but Not Required
- Background in regulated, critical, or high-reliability settings where technology and cyber risk are under enhanced scrutiny.
- Relevant certifications (CISA, CISSP) or commensurate professional qualifications.
- Familiarity with industry frameworks such as NIST, ITIL, COSO.
- Knowledge of emerging technology risk areas including AI, cloud at scale, and continuous deployment.
Additional Information
ASX is committed to inclusive hiring practices based on skills and experience, encouraging applications from diverse backgrounds. Applicants requiring accommodations during the recruitment process may request assistance. The organization offers hybrid work options and supports flexible arrangements despite roles being advertised as full-time. Background checks and verification will be part of the onboarding process. Candidates must be legally authorized to work in Australia without restrictions to be eligible.
Level
Senior