Job search
Principal Advisor Information Security (Governance, Risk & Compliance)
Performance; Information Technology; Enabling Solutions Group; Carseldine
Lead information security governance, risk and compliance for Transport and Main Roads. In this AO7 role, you will provide expert advice and strategic direction, strengthen consistent risk management practices, develop security controls, policies and standards, and brief senior stakeholders on risks, trends and treatment priorities.
You will also lead initiatives that build awareness and support practical adoption of TMR’s information security policy framework.
Job details
| Position status | Permanent |
|---|---|
| Position type | Flexible full-time |
| Occupational group | IT & Telecommunications |
| Classification | AO7 |
| Workplace Location | Brisbane - North |
| Job ad reference | QLD/702663/26 |
| Closing date | 16-Oct-2026 |
| Job duration | |
| Contact person | Michael Szymanowski |
| Contact details | Phone: 0418 718 456 Access the National Relay Service |
As Principal Advisor Information Security (Governance, Risk & Compliance), you will provide expert advice and strategic direction for information security policy and governance across Transport and Main Roads (TMR). You will champion information security and deliver end-to-end advice and guidance informed by best practice and recognised Australian and international standards and strategies.
In this role, you will champion consistent information security risk management practices across TMR, including through the Information Security Community of Practice and other special interest groups aligned with TMR's risk framework and risk appetite. You will use governance, risk and compliance tools and evidence-based analysis to assess information security risks, prepare reports, and brief senior stakeholders on risk status, trends and treatment priorities.
You will develop, maintain and promote information security controls, policies and standards aligned with Queensland Government requirements and recognised industry practice. You will also lead communication, education, implementation and monitoring activities to improve awareness and adoption of TMR's information security policy framework. Maintaining contemporary information security knowledge and applying agile ways of working will be important in delivering practical governance, risk and compliance outcomes.
To thrive in this role, you will bring demonstrated experience developing, implementing and managing ICT governance frameworks in information security or IT service delivery and management. You will also have working knowledge of relevant standards and frameworks, such as the Queensland Government Information Security Policy, ISO/IEC 27000 series, the ASD Information Security Manual and Essential Eight, or the NIST Cybersecurity Framework.
The role is permanent, flexible full-time and based at Carseldine. A criminal history check will be undertaken before appointment because the role has access to sensitive data. TMR supports an inclusive workplace, career development and healthy work-life balance, and welcomes applicants from all backgrounds.
Applications to remain current for 12 months
Job Ad Reference: QLD/702663/26
Closing Date: Friday, 16 October 2026
Further information
We are committed to building inclusive cultures in the Queensland public sector that respect and promote human rights and diversity.
Please ensure you download all attachments and follow the instructions on how to apply.
Documents
Before applying for this vacancy please ensure you read the documents below.
