Global Cyber Security Governance Specialist at QBE providing insights on security posture and control performance. Engage stakeholders and enhance cyber security governance.
Responsibilities
Monitor and analyse cyber control performance metrics and key risk indicators (KRIs) to identify trends, emerging risks, and opportunities for control uplift
Develop and maintain reporting artefacts (e.g. dashboards, briefings, governance packs) that clearly communicate security posture and risk insights to a range of stakeholders, including senior management and governance forums
Translate complex control and risk data into actionable insights, enabling stakeholders to make informed trade-offs aligned with QBE’s risk appetite and strategic priorities
Support cyber scenario modelling activities, including scenario definition, refinement, and alignment with threat intelligence and attack tree structures
Ensure scenarios remain accurate, defensible, and relevant to QBE’s operating environment, drawing on established methods and practices referenced in stakeholder materials and scenario modelling roadmaps
Collaborate with control owners, delivery teams, and second-line functions to improve the quality, clarity, and consistency of control performance data and reporting inputs
Support the integration of control telemetry and other evidence-based measures into reporting processes, with a focus on control immutability and automation where feasible
Contribute to the continuous improvement of governance and reporting frameworks, ensuring alignment with QBE’s cyber strategy, regulatory obligations, and business needs
Participate in targeted, risk-informed assurance activities that validate control effectiveness in high-priority areas, complementing formal audits and RCSA processes
Act as a feedback channel to Strategy & Architecture and other stakeholders, highlighting implementation challenges or systemic issues surfaced through metrics or reporting
Engage stakeholders to support a culture of risk transparency and accountability, encouraging proactive issue identification and evidence-based dialogue
Support audit and regulatory engagement by ensuring reporting artefacts and supporting evidence are accurate, consistent, and audit ready
Requirements
Ability to get deeply technical and apply that skill to the business environment
Exceptionally curious and enquiring mindset with an ability to be fast-paced and agile in meeting business needs
Strong communication, negotiation, and conflict management skills, with an ability to anticipate and flag potential obstacles
Experience with security and risk-based standards, Microsoft Excel, Power BI and ERC tools
Experienced in working across time zones and collaborating in a multi-location environment
Benefits
Hybrid Working – a mix of working from home and in the office to enhance your work/life balance
Senior Security Engineer developing and enhancing security infrastructure for Bank Frick, a pioneer in blockchain banking. Responsible for managing security processes and collaborating with IT teams.
Werkstudent Cyber Security bei Wavestone, Unterstützung im IT - Consulting und Entwicklung im Bereich Cyber - Sicherheit. Analyse von Trends und aktive Teilnahme an Teamaktivitäten.
Project Manager for Security Technology managing complex security projects in MENA region. Involving internal teams and external integrators ensuring project success and client satisfaction.
Cyber Security Manager at British American Tobacco strengthening cyber resilience across Western Europe. Responsible for managing security initiatives and collaborating with regional teams.
Stagiaire responsable de l’accompagnement à la mise en place d’un système SSE pour un bureau d’études en ingénierie. Impliqué dans la structuration, suivi et déploiement de systèmes SSE.
Engineering Intern involved in real work and active projects at Babcock Australasia. Collaborating with experienced professionals to gain real - life experience in a supportive environment.
Graduate Cyber Technician contributing to Babcock Australasia's Defence Industry initiative. Join the 2027 Graduate Program and engage in personal and professional development.
Senior Security Engineer establishing and maintaining cybersecurity measures for a financial services company. Responsible for leading security event responses, documentation of policies, and training.
Senior Corporate Security Investigator at Duke Energy conducting complex investigations in support of Ethics, HR, Legal, Nuclear, and Enterprise Security with field mobility.
AI Enterprise Security Architect focusing on AI Security architectural standards and integrating security measures into AI development lifecycle. Leading a global team in securing AI systems.