Help shape how technology risk is governed across one of Australia’s most important consumer-facing organisations.AFCA is building a world-first scams prevention capability designed to benefit all Australians, alongside major transformation across digital services, identity and access management, data and technology. This role offers a rare opportunity to establish the governance, risk and assurance foundations that will help these capabilities operate securely, responsibly and at scale.We’re looking for a Senior Technology Governance & Risk Lead to build and mature AFCA’s technology and cyber risk capability. Reporting directly to the Chief Information Security Officer (CISO), you’ll have the mandate to improve how technology risks are identified, assessed, governed and communicated across major transformation programs and business-as-usual operations.This is a hands-on leadership role for someone who enjoys turning frameworks into practical ways of working. You’ll partner with senior technology, risk, architecture, data, privacy and delivery leaders to strengthen governance without creating unnecessary friction for delivery.In this role you will:Lead and mature AFCA’s technology and cyber risk management framework, operating model and governance practices.Establish clear, actionable technology and cyber risk registers, with meaningful ownership, treatments, indicators and reporting.Facilitate evidence-based risk and control assessments across technology platforms, transformation programs and operational services.Coordinate remediation of audit, assurance and regulatory findings, helping accountable owners convert recommendations into deliverable actions.Mature AFCA’s information security management system and control assurance practices, including evidence collection, control testing and continuous improvement.Lead governance of technology and security policies, standards, exceptions and supporting processes.Oversee and improve third-party technology and security risk assessments, including supply-chain, cloud, data-processing and service resilience risks.Partner with technology, architecture, product and delivery teams to embed proportionate risk management and secure-by-design practices early in delivery.Provide clear technology risk advice and reporting to senior leaders, governance forums and risk committees.Support alignment with ISO 27001, NIST CSF, the Essential Eight, CPS 234, CPS 230, the Australian Privacy Principles and other applicable obligations.Strengthen governance of information protection, classification, access, retention and secure handling in collaboration with Data Governance, Privacy, Records Management and IAM.Identify opportunities to simplify and automate governance, risk assessments, evidence collection and reporting