Technology Risk Manager

Date: 15 Sept 2026

Location: Docklands, VIC, AU

Company: Wesfarmers Health

At Wesfarmers Health we strive to make health, beauty and wellness experiences simpler, more affordable and easier to access for all Australians.

 

Our portfolio includes well-known names like Priceline, Australian Pharmaceutical Industries, as well as our MediAesthetics brands - Clear Skincare Clinics and SILK Laser Clinics. In the digital space, we’re proud to have SISU Health and InstantScripts—and most recently, we’ve launched our newest retail beauty stores, atomica. 

 

About us:

 

What began in 1910 as a small co-operative of just three pharmacies has grown into Wesfarmers Health—a leading Australian organisation in health, beauty, and wellness.

 

Today, Wesfarmers Health proudly employs over 3,600 team members, all committed to delivering accessible, innovative, and trusted health and beauty services to Australians nationwide, across retail, medi-aesthetics, digital health, and wholesale and supply chain operations.

 

What you’ll do:

 

We are seeking a strategic and capable Technology Risk Manager to join our Cyber Security team. Reporting to the Senior Manager, Cyber Security, you will lead the establishment and ongoing maturity of Wesfarmers Health's technology risk function. This is a unique opportunity to shape risk management practices across a complex technology environment, working closely with senior stakeholders to strengthen governance, assurance and risk oversight capabilities.

 

Key responsibilities include:

 

  • Define and implement the technology risk framework, including risk taxonomy, risk appetite statements and risk registers aligned to the Wesfarmers Health technology environment
  • Establish and maintain technology risk reporting for governance forums, including Cyber Committee, technology leadership teams and Group Risk stakeholders
  • Operationalise technology risk themes by defining ownership, controls, key risk indicators (KRIs) and assurance activities
  • Monitor technology risk posture and drive remediation of material risks and control gaps with accountable stakeholders
  • Design and lead control testing and assurance activities, ensuring clear separation between first-line and second-line responsibilities
  • Define evidence standards for control effectiveness and support self-assessment programs for control owners
  • Lead the implementation and ongoing evolution of GRC tooling, ensuring alignment to risk management and reporting requirements
  • Maintain alignment with industry frameworks and regulatory obligations, including ISO 27001, NIST CSF, PCI DSS and Privacy Act requirements
  • Prepare and present technology risk reporting for executive leadership and governance forums
  • Provide independent challenge and oversight of technology risk decisions, escalating material risks where required

 

What you’ll bring:

 

  • 10+ years' experience in technology or cyber risk management, including establishing or significantly uplifting a risk function
  • Demonstrated experience with risk assessment methodologies across both technology and cyber disciplines, and with GRC tooling implementation
  • Ability to operationalise broad risk themes into assessable scope with clear owners, controls, KRIs and assurance activity
  • Experience designing control testing and assurance programs with clear first-line / second-line separation and defined evidence standards
  • Hands-on experience implementing GRC tooling, including design rather than administration only
  • Working fluency in ISO 27001, NIST CSF, PCI DSS and the Privacy Act / APPs, and the ability to align technology risk practice to a Group risk framework
  • Strong executive reporting skills, able to translate technical risk into language and decisions suited to Board and Audit & Risk Committee audiences
  • Experience in a regulated, retail, health or franchise-network organisation is desirable
  • Experience building or managing a small risk analyst team
  • Exposure to Group-level risk and audit committee reporting cycles
  • Tertiary qualification in Risk Management, Information Technology, Cyber Security or a related discipline (or equivalent demonstrated experience)

 

Why us?  

 

  • Access to employee benefits across Wesfarmers including team member discounts at Bunnings, Kmart, Target, Officeworks, OnePass, Priceline, atomica, Instantscripts and Clear Skincare Clinics
  • Ongoing professional development and career opportunities across the Wesfarmers Health Division and the broader Wesfarmers Group
  • Novated leasing options
  • Access to our Employee Assistance Program (EAP) - available to all team members and their immediate family members, 24/7, 365 days a year
  • Beautiful outdoor terrace for work and recreation
  • Food, coffee and health & wellbeing facilities onsite including a landlord operated gym 
  • Dedicated end of trip facilities (cycle racks, showers, lockers)

 

 

Aboriginal and Torres Strait Islander Applicants

 

Wesfarmers Health aims to become an employer of choice for First Nations Australians, through investments that attract, empower and retain First Nations team members within our stores, distribution centres, clinics and corporate offices. 

 

As part of the Wesfarmers group, we provide authentic support through a diverse range of programs and initiatives, designed to empower you on your journey towards personal achievement and professional advancement.