Information Security Consultant (Policy-as-Code & Governance Engineering)

Westpac Group

Sydney

On-site

AUD 120,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Special offers on banking products and
Flexible work arrangements
Learning and development opportunities
Volunteer initiatives

Job summary

Westpac Group in Sydney is hiring an Information Security Consultant focused on Policy-as-Code and governance engineering. The role centers on transforming policy management, maintaining standards, and translating requirements into machine-readable controls.

You'll collaborate with architecture, risk and business teams, embed security into delivery, support audits, and use automation and AI to improve governance. On-site 2 days/week; Sydney-based.

Qualifications

  • Governance, risk and compliance experience in technology environments.
  • Translate regulatory and policy requirements into testable controls.
  • Hands-on GitHub or Bitbucket for version control and governance workflows.
  • Understand Policy-as-Code and control automation.
  • Some Python scripting to support reporting.
  • Experience with ServiceNow IRM/GRC and control mapping.

Responsibilities

  • Develop and maintain Policy-as-Code governance capabilities.
  • Embed cybersecurity requirements into technology solutions and delivery practices.
  • Support audits, assurance and regulatory activities with evidence-based assessments.
  • Monitor control effectiveness and remediation activities to reduce risk.
  • Leverage automation and AI to enhance policy lifecycle management.

Skills

Governance
Policy-as-Code
Regulatory mapping
Python scripting
CI/CD
AI governance
OSCAL
JSON/YAML
GRC tooling

Tools

GitHub
Bitbucket
ServiceNow IRM/GRC
Palantir
OPA/Rego

Job description

Information Security Consultant (Policy-as-Code & Governance Engineering)

Sydney, NSW, Australia

Job Description

Create your best future and join as an Information Security Consultant (Policy-as-Code & Governance Engineering)

  • Location:Sydney-based role only
  • On-site Requirement:2days per week in the office

What’s the role?

As an Information Security Consultant, you will help drive Westpac’s transition from traditional policy management to a modern Policy-as-Code and governance engineering capability. You will maintain and enhance cybersecurity policies, standards and control frameworks, ensuring alignment with regulatory obligations and industry standards while translating policy requirements into machine-readable, testable and enforceable controls.

Additionally, you'll work closely with architecture, engineering, risk and business teams to embed cybersecurity requirements into technology solutions and delivery practices. You will support Secure by Design, architecture and engineering initiatives, managing security exceptions and remediation activities, and maintain traceability across obligations, controls, exceptions and assurance outcomes to strengthen governance and risk management.

You will monitor control effectiveness, compliance and exception trends to drive continuous improvement and reduce risk across the organisation. You will also contribute to audits, assurance and regulatory activities through evidence-based assessments, while leveraging automation and AI to enhance governance processes, policy lifecycle management and compliance outcomes.

What do I need?

  • Cybersecurity governance, risk and compliance experience within technology environments, with the ability to translate regulatory, policy and security requirements into practical, testable controls.
  • Hands‑on experience with GitHub or Bitbucket for version control, collaboration and governance workflows.
  • Understanding of Policy-as-Code, governance engineering, control automation and compliance monitoring concepts.
  • Some experience using Python or similar scripting languages to streamline workflows and support governance reporting.
  • Experience with ServiceNow IRM/GRC, UCF and control mapping frameworks to support governance, risk and compliance activities.
  • Knowledge of OSCAL fundamentals, JSON/YAML and machine‑readable governance concepts.
  • Exposure to CI/CD practices, OPA/Rego, Palantir, AI governance and emerging governance automation technologies.

Note: The internal job title for this position is Information Security Consultant.

We’re obsessed with becoming our customers #1 banking partner for life and we’re looking for people who are passionate about helping us achieve that goal. In return we’re committed to making Westpac the best place to work in the country. Here are just a few of the ways we’re already doing that:

  • Special offers on banking products and discounts from top brands, including generous employee‑only mortgage rates!
  • Flexible work arrangements to help you achieve a greater work life balance, and a variety of leave options including Culture, Lifestyle and Wellbeing leave.
  • Tailored learning and development opportunities to help you grow your career within the bank.
  • Lots of opportunities to give back to the Community by getting involved in our many volunteering initiatives

We’re all about creating a supportive and inclusive community. We welcome everyone no matter your age, gender, background, or abilities. We also provide additional support to welcome our veterans, Indigenous Australians and neurodiverse community.

If you need any adjustments during the recruitment process, you can find more information and contact details on our FAQs and how to contact us page , under the Diversity, sustainability and flexibility section.

#LI - Hybrid

Job Info
  • Job Category Information & Cyber Security
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Policy-as-Code & Governance Security Consultant
Policy-as-Code & Governance Security Consultant

Westpac Group • Sydney

On-site
AUD 120,000 - 160,000
Special offers on banking products and
Flexible work arrangements
Learning and development opportunities
+1
Senior AI Security Engineer: Guardrails for AI Pipelines
Senior AI Security Engineer: Guardrails for AI Pipelines

Westpac Group • Sydney

On-site
AUD 180,000 - 240,000
Flexible work arrangements
Culture, Lifestyle & Wellbeing leave
Learning & development opportunities
+1
Domain Consultant - Security Operations Transformation
Domain Consultant - Security Operations Transformation

Palo Alto Networks • Sydney

On-site
AUD 120,000 - 160,000
Wellbeing support
Growth and development opportunities
Flexible work arrangements
Senior Security Risk Analyst
Senior Security Risk Analyst

Credit Corp • Australia

Hybrid
AUD 150,000 - 190,000
Wellbeing support (EAP)
Gym discounts
Health insurance benefits
+4
Cyber GRC Specialist
Cyber GRC Specialist

Client 1 • Canberra

On-site
AUD 120,000 - 150,000
14% superannuation
6 weeks paid annual leave
Mentoring & professional development
Data Analytics Manager - Financial Crime Intelligence
Data Analytics Manager - Financial Crime Intelligence

Westpac Group • Sydney

On-site
AUD 150,000 - 190,000
Flexible work
Mortgage rates
Training & development
Senior AI Security Engineer
Senior AI Security Engineer

Westpac Group • Sydney

On-site
AUD 180,000 - 240,000
Flexible work arrangements
Culture, Lifestyle & Wellbeing leave
Learning & development opportunities
+1
IT Security Consultant
IT Security Consultant

Catholic Education Diocese of Parramatta • City of Parramatta

Hybrid
AUD 120,000 - 150,000
Competitive remuneration
Salary packaging
Parental leave
+1
Cyber Security Consultant - IDAM / GRC
Cyber Security Consultant - IDAM / GRC

Whizdom • Melbourne

On-site
AUD <1,000
Competitive contracting rates
Expense coverage of up to AUD 30,000
Overtime provisions for extended hours
+2
Project Officer - Security & Compliance
Project Officer - Security & Compliance

Everi Pty • Canberra

Hybrid
AUD 90,000 - 130,000
Work180 accreditation
Rainbow Tick certification