General Manager – Cyber Maturity Improvement Plan
- Lead the delivery and execution of ANZ's Cyber Maturity Improvement Plan (CMIP).
- Ensure alignment with enterprise risk appetite and regulatory obligations.
- Build a high-performing delivery culture across the organisation.
Role purpose
The GM Cyber Maturity Improvement Plan leads the end-to-end delivery and strategic execution of ANZ's enterprise Cyber Maturity Improvement Plan (CMIP). The role is accountable for converting ANZ's threat-led cyber risk posture into a coherent, prioritised and measurable multi-year program that reduces material cyber risk, uplifts control effectiveness and strengthens operational resilience.
Reporting to the Group Chief Information Security Officer, the role integrates delivery across Group Cyber Security, Technology, Risk and business domains, and provides clear accountability for scope, sequencing, investment, dependencies, benefits and delivery outcomes. The role ensures CMIP remains aligned to enterprise risk appetite, Board expectations, regulatory obligations and the NIST Cyber Security Framework, while establishing the governance, transparency and delivery discipline needed to achieve sustainable risk reduction.
Role accountabilities
- Own and execute the integrated CMIP delivery strategy and roadmap, translating the approved cyber risk posture and maturity objectives into sequenced, achievable initiatives and measurable enterprise outcomes.
- Provide end-to-end accountability for program scope, schedule, cost, quality, benefits and risk, including establishment of clear definitions of done, milestones, delivery tolerances and intervention triggers across all CMIP themes.
- Lead integrated execution across cyber, infrastructure, cloud, architecture, engineering, data, risk and business domains, ensuring cross-domain dependencies, capacity constraints and implementation risks are actively managed and resolved.
- Establish and operate fit-for-purpose program governance, decision rights and change control, supporting the CMIP Steering Committee and ensuring timely escalation of material risks, issues, investment trade-offs and regulatory impacts.
- Maintain a single, evidence-based view of CMIP performance, including delivery progress, financial position, control uplift, maturity improvement, benefits realisation and residual cyber risk reduction.
- Drive risk-based prioritisation and investment decisions, using threat intelligence, control effectiveness, maturity assessments, cyber risk quantification and delivery feasibility to focus resources on the greatest risk reduction outcomes.
- Ensure CMIP initiatives are mapped to ANZ's control environment, risk appetite, regulatory obligations and assurance requirements, including APRA CPS 234 and CPS 230, with clear ownership and defensible evidence of design and operating effectiveness.
- Coordinate independent validation, assurance and post-implementation reviews, and ensure recommendations from Line 2 Risk, Internal Audit, external assessors and regulators are assessed, governed and incorporated where appropriate.
- Provide clear, concise and decision-oriented reporting to the CISO, CIO, CRO, Executive Committees, Board committees and other governance forums on progress, material risks, dependencies, investment and realised risk reduction.
- Lead program mobilisation, workforce planning, vendor strategy and financial management, ensuring the program has the capability, capacity and commercial discipline required for sustainable delivery.
- Build a high-performing, enterprise-wide delivery culture that reinforces accountability, constructive challenge, transparency, collaboration and security-by-design.
- Maintain CMIP as a living, risk-led roadmap by incorporating material changes in the threat landscape, technology environment, control posture, regulatory expectations and enterprise strategy without losing delivery discipline or strategic coherence.
‘Must have’ knowledge, skills and experiences
- Extensive senior leadership experience delivering large, complex, enterprise-wide technology, cyber security, risk or regulatory transformation programs in a highly regulated organisation.
- Proven accountability for multi-year program outcomes across scope, schedule, investment, quality, benefits and risk, with a track record of recovering or reshaping complex delivery where required.
- Strong knowledge of cyber security risk, control frameworks and resilience, with the ability to connect technical delivery to material risk reduction, control effectiveness and business outcomes.
- Demonstrated experience establishing enterprise governance, integrated planning, benefits management, financial control, change control, dependency management and executive reporting.
- Proven ability to lead delivery across organisational boundaries where outcomes depend on multiple technology domains, business units, control owners, vendors and assurance functions.
- Exceptional executive and Board-level communication skills, including the ability to turn complex delivery, risk and financial information into clear decisions, trade-offs and actions.
- Strong commercial and financial acumen, including portfolio prioritisation, investment planning, vendor management, workforce allocation and value realisation.
- Demonstrated ability to engage constructively with regulators, auditors and risk functions, and to maintain a transparent and defensible evidence base for program outcomes.
- Strong analytical and data-driven decision-making capability, including the design and use of outcome metrics, risk reduction measures, delivery dashboards and leading indicators.
- Proven experience building and leading high-performing, multidisciplinary teams through ambiguity, organisational change and sustained delivery pressure
Capabilities
- Enterprise Program Leadership: Sets a clear delivery strategy and provides end-to-end accountability for complex, multi-year transformation outcomes.
- Cyber Risk and Control Leadership: Applies sound cyber risk judgement to prioritise work, strengthen controls and deliver measurable reduction in material cyber exposure.
- Strategic Integration: Connects enterprise strategy, risk appetite, regulatory obligations, architecture and investment into one coherent roadmap.
- Governance, Assurance and Accountability: Establishes clear decision rights, transparent reporting, disciplined change control and defensible assurance over outcomes.
- Planning and Execution: Translates strategy into integrated plans, milestones, dependencies and definitions of done, and intervenes early when delivery is at risk.
- Data-Driven Decision Making: Uses delivery, financial, maturity, control and risk data to support prioritisation, escalation and evidence-based decisions.
- Stakeholder Influence and Communication: Builds alignment across senior leaders, risk, audit, regulators, delivery teams and business stakeholders.
- Business and Financial Management: Leads investment, resources, vendors and financial performance to maximise risk reduction and enterprise value.
- People Leadership and Culture: Builds an inclusive, accountable and collaborative culture that enables teams to perform through complexity and change.
- Change and Benefits Realisation: Ensures delivered capabilities are adopted, embedded, assured and sustained so that investment translates into lasting risk reduction.
Qualifications
- Bachelor's degree in Information Technology, Cyber Security, Engineering, Business, Risk Management or a related discipline; postgraduate qualifications are desirable.
- Relevant program, portfolio, change, risk or cyber security qualifications such as MSP, PgMP, PMP, SAFe, CISSP, CISM, CISA or equivalent are desirable.
- Additional qualifications in financial management, governance, operational resilience or executive leadership are advantageous
We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.