Jean-Baptiste Bres
CISO and Director, Enterprise AI & Technology – Security, Risk & Compliance at AMP
Profile
Jean-Baptiste Bres is a French-Australian cyber security executive with more than 20 years of experience in banking and financial services across Europe and Australia. He is Chief Information Security Officer and Director, Enterprise AI & Technology – Security, Risk & Compliance at AMP, where he is responsible for cyber security, technology risk and compliance.
His career has been shaped by regulated, fast-moving environments: building the security function of Xinja, one of Australia's first digital banks, on a cloud-native technology stack; supporting Avenue on its path to a banking licence; leading cyber security for HSBC in Australia and New Zealand; and now protecting the customers of one of the country's best-known financial services groups.
Career
- AMP: Chief Information Security Officer and Director, Enterprise AI & Technology – Security, Risk & Compliance (2024 to present)
- HSBC: Chief Information Security Officer, Australia and New Zealand (2021 to 2024)
- Avenue Bank: Chief Information Security Officer (2021)
- Xinja Bank: led information security (2019 to 2021)
- StatePlus, now part of Aware Super
- BNP Paribas and Société Générale, in Europe
Approach
Jean-Baptiste sees security as the discipline that lets an organisation take the right risks, rather than one that tries to avoid them all. He combines technical grounding with governance and programme leadership: security engineered into delivery instead of added at the end, risk expressed in business terms, and clear, shared accountability between first and second line when trade-offs have to be made under pressure.
He leads with people first, investing in capability, simple processes and collaboration across teams, and champions pragmatic security that enables transformation rather than blocking it.
Speaking and community
- Speaker and panellist at various industry events.
- Co-facilitator of the ISC2 Sydney Chapter's study group for the Certified in Cybersecurity (CC) exam.
- Author of a free, six-part guide to the ISC2 Certified in Cybersecurity certification.
- University lecturer in information technology and mentor to early-career security practitioners.
Certifications
- CISSP, Certified Information Systems Security Professional, ISC2 (2023)
- CGEIT, Certified in the Governance of Enterprise IT, ISACA (2024)
- CSM, Certified ScrumMaster, Scrum Alliance (2025)
- CC, Certified in Cybersecurity, ISC2 (2022)