Cyber Governance, Risk and Compliance Lead
Quick Overview
Job Description
Location: Clayton, VIC, AU, 3168
Employment Type: Full Time
Posting Date: 1 Jul 2026
About the Department / ProgramThe Monash Health Cybersecurity team protects the digital systems, information and technologies that support clinical care and business operations. The team works across infrastructure, networks, cloud, digital health, enterprise applications, and other business units to identify, assess and manage cyber risk, support secure service delivery, and improve cyber maturity and technology resilience.
About the RoleAs a Cyber Governance, Risk and Compliance Lead, you report to the Head of Cybersecurity and are responsible for leading cyber governance, risk and compliance activities across Monash Health, based at Clayton.
Key Result Areas- Lead the establishment, maintenance and continuous improvement of Monash Health's cyber risk management framework, aligned with the Enterprise Risk Framework.
- Provide timely, high-quality cyber governance, risk and compliance advice to stakeholders across Monash Health.
- Contribute to the development and continuous improvement of Monash Health's cyber strategy, roadmap, governance and risk management capability, including the identification of capability gaps and improvement initiatives.
- Lead the identification, assessment, treatment and reporting of cyber risks, including appropriate governance, escalation and stakeholder engagement.
- Develop, maintain and periodically review cybersecurity policies, standards, guidelines and related governance artefacts.
- Lead or support cyber compliance and assurance activities against relevant internal, Victorian Government, Commonwealth and sector requirements, including the Security of Critical Infrastructure (SOCI) framework where applicable.
- Lead or coordinate cyber control assessments, compliance reviews and assurance activities to evaluate control effectiveness and support risk-based decision-making.
- Demonstrated experience in cyber governance, risk and compliance within a large, complex or regulated environment, preferably in healthcare, government or critical infrastructure.
- Strong knowledge of cyber risk management, control assurance, compliance and third party risk management, including the operation of governance frameworks, risk registers, control monitoring and assurance activities.
- Strong working knowledge of contemporary cyber security frameworks and standards, including ISO 27001, ISO 31000, NIST Cybersecurity Framework, the Australian Government Information Security Manual (ISM) and the Essential Eight.
- Sound knowledge of legislative, regulatory and policy obligations relevant to Victorian public health services, including the Privacy and Data Protection Act 2014 (Vic), Health Records Act 2001 (Vic) and the Security of Critical Infrastructure (SOCI) framework.
- Demonstrated ability to think strategically and systematically, identify emerging issues, manage competing priorities and support risk based decision making in a complex service delivery environment.
- Tertiary qualification in cybersecurity, information technology, risk, governance, audit, law, business or a related discipline, and/or equivalent relevant experience.
- Relevant industry certification in cybersecurity, risk, audit or governance (e.g., CISM, CISA, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor or equivalent) is highly regarded.
- Qualifications or certifications in governance, assurance, audit, privacy, business continuity, resilience or related disciplines are advantageous.
- Supportive and cohesive sub team within a larger consumer relations team.
- Professional development courses, seminars and mentoring.
- Opportunities to use your experience to inform and drive initiatives across broader units and programs.
- Salary packaging.
- On site gym options and the ability to join Fitness Passport, providing access to a wide range of fitness facilities.
We recognise the value of equal employment opportunity. We are committed to patient safety, promoting fairness, equity and diversity in the workplace and to Child Safe Standards.
Skills
Similar jobs
Desktop Support Analyst
Satwic Inc · Los Angeles, United States
Just nowNetwork Support Analyst (Night Shift)
Morph Enterprise LLC · Harrisburg, United States
Just nowSr. Oracle SQL Analyst
STS Worldwide Inc. · Atlanta, United States
Just nowFraud Analyst
EmployVision · Morristown, United States
Just nowSr. EpicCare Ambulatory / MyChart Analyst ** 100% Remote **
Amerit Consulting · United States
Just nowQuality & Compliance Systems Manager
Octagon Group · Weyhill, United Kingdom
1 minute ago