Reagroup

Head of Cyber GRC

RichmondFull timeVpPosted 22 days ago
Apply on Reagroup →

Sign into see who you know at Reagroup.

Lead the next evolution of cyber GRC at REA through platform, automation and smarter risk reportingShape how a product-led technology organisation understands and reduces cyber riskLead a distributed team across Australia and India while partnering closely with senior leadersWe're REAWith bold and ambitious goals, REA Group is changing the way the world experiences property. No matter where you're at on your property journey, we're here to help with every step – whether that's finding or financing your next home. Our people are the key to our success. At the heart of everything we do is a thriving culture centred around high performance and care. We are purpose driven and collaborative, which drives innovation and our ability to make a real impact.As such, we’re proud to have been named one of Australia’s Best Workplaces four times since 2021 — including third place in 2025 — plus Best Workplace for Women in 2023 and Best Workplace in Technology in 2024 and 2025. These listings are testament to every person who helps make REA a great place to work.Where the team fits inOur Cyber Governance, Risk and Compliance team exists to ensure REA has a shared understanding of cybersecurity risk, a practical approach to compliance, and a policy and control environment that is simple to understand and apply.This team is already well established, but the way it works needs to evolve. That evolution is at the heart of this role. You'll be the person our leaders turn to when deciding what to work on next - driving a shared understanding of our cyber risks.What the role is all aboutThis is a rare opportunity to reshape how cyber GRC is done inside a modern product and technology business. Over your first year, you will make the case for and implement a GRC platform, overhaul how we measure and report cyber risk, automate compliance evidence collection, and modernise or replace existing processes so the team’s time is invested where it most reduces risk.You’ll be the clearest voice on cyber risk at REA, helping leaders make better decisions about what to prioritise and why. You’ll sit on the Security leadership team and work closely with peers across Product Security, Enterprise Security, and Detection and Response.Day to day, you can expect to:Drive a shared understanding of cyber risk across the security organisation and broader business so investment is focused on the controls and remediation that most reduce riskEstablish, manage and report on security metrics that make performance, exposure and priorities easy for the business to understandSupport the CISO with regular reporting to senior governance forums and provide confident, constructive challenge when priorities need to shiftLead the Cyber GRC team through a shift from routine process execution to higher-value, risk-focused workDirectly manage the Australian team and provide functional leadership to team members in India, in partnership with their local people managerLead the Business Information Secu...