Downer logo

Business Information Security Officer - Operational Technology

Downer

Melbourne, VIC, Australia

Job Description

We are excited to introduce an exceptional opportunity for an experienced and business-focused Business Information Security Officer - Operational Technology (BISO OT) to join Downer’s Group Technology team.

This is a highly influential role suited to a trusted cyber security professional who thrives on building strong stakeholder relationships, translating complex security challenges into practical business outcomes, and driving cyber resilience across operational technology (OT) environments.

Reporting to the Chief Information Security Officer, you will act as the primary cyber security interface between the CISO function and operational technology stakeholders across Downer. You will play a critical role in strengthening OT cyber risk management, security governance, incident readiness, and control uplift while ensuring security outcomes align with business priorities, operational requirements, safety obligations, and Downer’s cyber security strategy.

Operating within a product-led DevOps environment, you will work across the full technology lifecycle, partnering with Cyber Security, Technology Services, Risk, Legal, Privacy, and operational teams to deliver practical, risk-based security outcomes that support business performance and resilience.

This role offers the opportunity to influence security strategy and drive meaningful outcomes across some of Downer’s most critical operational environments.

About the Role

In this role you will:

  • Act as the primary cyber security relationship lead for Operational Technology stakeholders and business units across Downer.
  • Partner with OT leaders, embedded technology teams and business stakeholders to align cyber security requirements with operational priorities.
  • Translate cyber security policies, standards and control frameworks into practical and achievable OT security outcomes.
  • Lead and support OT cyber risk assessments, vulnerability reviews and control gap analysis activities.
  • Coordinate risk treatment plans, remediation initiatives and exception management through established governance forums.
  • Provide cyber security advice for OT projects, technology changes, tenders, contracts and supplier engagements.
  • Partner with Cyber Defence, Security Engineering, Technology Services, Risk and Legal teams to strengthen cyber resilience and security posture.
  • Support incident readiness activities and coordinate cyber security response efforts relating to OT environments.
  • Monitor, report and communicate cyber risks, remediation progress and security posture to both technical and non-technical stakeholders.
  • Promote security awareness and encourage the adoption of practical, sustainable cyber security controls across operational environments.

This is a highly visible role where you will influence strategic cyber security outcomes while ensuring security controls remain practical, operationally effective and aligned with business needs.

Our Ideal Candidate

You are a cyber security professional who understands how to balance security, operational continuity, safety and business objectives. You build trusted relationships, communicate effectively with diverse stakeholders, and are confident influencing decisions in complex environment.

You bring:

  • Bachelor's degree in Cyber Security, Information Technology, Computer Science, Management Information Systems or equivalent practical experience.
  • 7+ year’s commercial experience in information technology or cyber security, with relevant experience in the role domain.
  • Strong experience managing cyber risk and engaging with business, operational and technology stakeholders.
  • Demonstrated experience supporting cyber risk assessments, control uplift initiatives, assurance activities, incident readiness and remediation programs.
  • Working knowledge of cyber security frameworks and standards including NIST, ISO/IEC 27001 and ASD Essential Eight.
  • Experience translating technical cyber risks into meaningful business impacts and executive-level recommendations.
  • Strong stakeholder engagement and relationship management skills with the ability to influence outcomes across all levels of an organisation.
  • Experience coordinating vendors, suppliers and internal teams to deliver cyber security outcomes.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CompTIA Security+ or similar highly regarded.
  • Operational Technology (OT), Industrial Control Systems (ICS) or Critical Infrastructure security experience will be highly regarded.

You are known for your pragmatic approach, strong judgement, effective communication skills and ability to bring people together to solve complex security challenges.

Benefits Of Working with Downer

  • Work with an ASX-listed company, working with market leaders.
  • Grow your career with us through personal and professional development and continuous learning:
    • Professional development programs
    • Access to professional memberships and industry networks
  • Be part of a team that cares, with support that is flexible around employee wellbeing needs:
    • Flexible work arrangements
    • Parental leave
    • Employee Assistance Program
    • Programs promoting diversity and inclusion
  • A range of corporate benefits, including:
    • Discounted services (car hire, hotels, insurance, retail stores, gyms)

Why Downer?

As a trusted name in infrastructure, transport, facilities management, and construction, Downer is committed to delivering projects that create a lasting, positive legacy.

We're committed to building a team that reflects the diverse communities we serve, and we welcome people of all ages, genders, sexual orientations, cultures, abilities, and lived experiences. We especially encourage applications from those whose voices have traditionally been underrepresented in our industry, including women, Aboriginal and Torres Strait Islander Peoples, Māori and Pasifika Peoples, veterans, people with disability, and neurodivergent individuals.

Even if your experience doesn't align perfectly with this role, we'd still like to hear from you. If it feels like the right fit, apply — potential counts, and so do you.

As a WORK180 Endorsed Employer, we support flexibility that works for your life, inclusive leadership that values your voice, and equitable access to opportunity so you can do your best work and bring your whole self to it.

Applies with a resume tailored to this job — proven to land more interviews.

Still Browsing?

The job won't wait.
Your resume shouldn't either.

Whether you're a diesel fitter between contracts, a sparky eyeing FIFO rates, or new to mining — a 3-minute resume is the difference between getting called and getting filtered.

Build Your Resume

Built in Perth, WA · Industry experts