Protect the systems behind every order, every restaurant, every day.
Reporting to the Head of Technology Services, the Information Security Manager owns GYG's information security programme end to end — across our cloud-hosted ordering, loyalty and payment platforms, identity infrastructure and largely franchise-operated restaurant network.
This is a hands-on role as much as it is a leadership one: you'll personally work across the tools to assess and lift GYG's security posture, lead a small team, and take the lead role in responding to security incidents and fraud risk across the business. The role carries a shared on-call roster supporting critical systems.
What You'll Do
- Develop, implement and maintain GYG's information security programme — policies, standards, procedures and guidelines — across corporate systems, cloud platforms, digital products and the restaurant/franchise network
- Conduct regular risk and vulnerability assessments, maintaining a prioritised, business-contextualised view of risk
- Work hands-on across GYG's security tools and platforms — monitoring and operating firewalls, IDS/IPS, antivirus and cloud security tooling
- Own GYG's digital fraud management programme, including monitoring, detection and response across digital and payment platforms
- Build, tune and maintain detection and logging content directly in GYG's SIEM tooling
- Lead cyber security incident response — detection, analysis, containment, eradication and recovery — including runbook maintenance and tabletop testing
- Own the assessment and notification process for eligible data breaches under the Notifiable Data Breaches scheme, working with Legal
- Manage GYG's annual PCI DSS assessment cycle and coordinate ongoing external penetration testing
- Develop and deliver security awareness training, including phishing simulations and role-specific education for engineering teams
- Manage GYG's relationship with its managed security partner, and maintain third-party security assessments in line with PCI DSS requirements
- Lead and develop the Information Security team (1 direct report), working alongside them hands-on
- Drive the development of an AI-informed security practice, including securing GYG's own AI systems and agents
What You'll Bring
- Bachelor's degree in Computer Science, Information Technology or a related field
- Proven experience in information security management — risk assessment, policy development, incident response and security operations
- In-depth knowledge of ACSC Essential Eight, ISO 27001 and the NIST Cybersecurity Framework
- Working knowledge of the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme; familiarity with GDPR and PCI DSS v4.x
- Hands-on experience securing production workloads in a cloud environment (e.g. AWS), including IAM, encryption, logging and cloud security posture management
- Practical experience with enterprise identity platforms (e.g. Microsoft Entra ID, Okta), including conditional access and privileged access management
- Strong stakeholder management skills, with the ability to translate technical risk into commercial terms for executive and franchise audiences
- Excellent leadership and people management skills, with strong project management capability
- Desirable: CISSP, CISM or CRISC certification; AWS security certification; experience in franchised, retail or multi-site environments
What You'll Love
- Join one of Australia's fastest-growing restaurant companies
- Real career growth in a Technology function that's investing heavily in its capability
- Annual short-term incentive scheme
- GYG restricted shares, earned each year through our long-term incentive scheme
- Up to 5 weeks of annual leave each year (ask us how)
- Paid parental leave
- A vibrant Surry Hills office, a short walk from Central Station
- Hybrid work environment: 4 days in office, 1 day WFH
Interested? Apply now to start the conversation.