Jean-Baptiste Bres

Chief Information Security Officer

2026

Building Australia’s Next Cyber Talent

Australia’s future cyber security capability depends on the talent we develop today. That’s why at AMP, we’re proud to sponsor the Australian Schools Cyber Challenge, helping students explore pathways into one of Australia’s fastest-growing industries.

Tune in to hear from some of our cyber graduates and specialists as they share their advice for students considering a career in cyber.

We're hiring: Technology Controls Assurance Senior Analyst

📍 Sydney (Hybrid) | 🏦 Financial Services | 🔐 Technology Risk, Controls & Assurance

We’re hiring a Technology Controls Assurance Senior Analyst to help strengthen confidence across AMP’s technology, cyber, third-party and AI risk environment.

This is a key role within Security, Risk & Compliance, focused on delivering risk-based assurance reviews across AMP’s technology landscape. You’ll work closely with stakeholders across Technology, Risk, Assurance and the broader business to provide independent, practical and insightful assurance over the areas that matter most.

You’ll be involved from planning through to reporting, assessing the design and effectiveness of controls, identifying emerging risks, and translating regulatory and industry developments into meaningful assurance activity. You’ll also help improve our assurance methodologies, workpaper quality and ways of working as the function continues to evolve.

You’ll be a strong fit if you bring:
* Experience in technology risk, cyber assurance, technology audit, internal audit, risk consulting or technology risk management.
* Exposure to cloud security, third-party risk, information security controls or emerging technology risk.
* Familiarity with frameworks such as ISO 27001, NIST CSF, COBIT, SOC reporting and APRA prudential standards.
Strong stakeholder management, communication and influencing skills.

This role offers the opportunity to have real impact in a function that is evolving how assurance is delivered, with the autonomy to help shape a collaborative and high-performing team.

➡️ Apply now: Technology Control Assurance Senior Analyst

We’re hiring: Senior Security Architect

📍 Sydney (Hybrid) | 🏦 Financial Services | 🔐 Security Architecture & Secure by Design

We're hiring a Senior Security Architect to help shape and strengthen AMP's security architecture capability at a pivotal time in our technology transformation journey. You’ll play a key role in ensuring security is embedded into how we design, build and operate technology across the enterprise.

This is a strategic and hands-on role focused on Secure by Design, security architecture, and enabling innovation in a highly regulated environment. You'll work closely with business, technology and risk teams to translate complex requirements into practical security outcomes that support both resilience and growth.

You'll be responsible for delivering security architecture services, influencing technology decisions, and helping maintain AMP's enterprise security architecture standards and patterns. Working across cloud, applications, platforms and emerging technologies, you'll help protect the trust our customers place in us every day.

You'll be a strong fit if you bring:
* Experience in security architecture within financial services or other highly regulated industries
* Strong knowledge of security frameworks and regulatory requirements such as NIST, ISO 27000-series and APRA CPS 234
* Experience embedding Secure by Design principles into technology delivery and transformation initiatives
* The ability to balance security, risk and business outcomes while influencing senior stakeholders across technology and business teams

This role offers the opportunity to influence security outcomes across AMP's technology landscape, work alongside a high-performing team, and help shape the future of a modern financial services organisation.

➡️ Apply now: Senior Security Architect

💡 Personal Access Tokens Have No Place In Modern Development Pipelines

Article


🔑
Personal Access Tokens (PATs) have quietly become the default way we connect systems, and as often, that default deserves a lot more scrutiny than it gets.

They're convenient: no consent screen, no session to manage, a single string that just works. But that same simplicity is exactly what makes them dangerous: long-lived, broadly scoped, and largely invisible to the identity controls we've already invested in. Now, a run of recent breaches all trace back to exactly this credential pattern. 🔓

In this article, I look at why PATs have become the path of least resistance across the industry (often because the platforms we build on make it the easy choice), why that convenience is the vulnerability, and where I land: PATs should be a narrow, governed exception, not the design default in a modern development pipeline.

Read More…

ISACA Sydney Chapter July Forum

It’s always a pleasure hosting the ISACA Sydney Chapter at AMP. A big thank you to Neethu N. and Yashaswini P. for sharing their insights on security, AI, and governance. Great discussions and perspectives from across the community.

20260723-001

Factor CIO Conference

Last week at the Factor CIO Conference in Melbourne, Julia P. and I explored a topic that continues to shape how organisations respond to cyber risk: security is not simply about stronger controls or better detection capabilities. It is about how effectively first and second line teams work together when pressure is high, time is limited, and the trade-offs are real.

Organisations that navigate these moments well do not treat cyber security as a siloed function. They establish clarity early, create shared accountability, and focus on what matters most: maintaining resilience, protecting customers, and enabling better decisions at speed.

Reflecting on that discussion, I captured some of my thoughts in the article Cyber Risk is a Trade-Off Problem.

20260716-001

💡 Cyber Risk is a Trade-Off Problem

Article

Most of our cyber conversations still focus on tools, controls, and patching speed, even though we all know it rarely resonates with our audiences.

In this piece, I explore a different lens: cyber risk as a series of trade-off decisions, not technical fixes.

From incident response to patching, the real question isn’t “what’s the fix?”
It’s “what are we willing to trade off to get the outcome we want?”

If you’re involved in security, risk, or leadership, this shift in thinking matters more than ever.

Read More…

We’re hiring: Principal, Entreprise AI Risk

📍 Sydney (Hybrid) | 🏦 Financial Services | 🤖 AI Risk & Governance

We’re hiring a Principal, Enterprise AI Risk to establish and mature AMP’s approach to AI risk at an important point in our AI adoption journey.

This is a strategic role focused on governance, transparency and accountability. You will own the end‑to‑end AI risk and compliance process, embed the Responsible AI Framework, and provide clear insight to executives on AI risk posture and priorities.

You’ll work across business, technology and risk to ensure AI is used in line with risk appetite and regulatory expectations, while enabling adoption at scale.

You’ll be a strong fit if you bring:
  • Experience in enterprise risk, governance or compliance in regulated environments
  • A track record in AI risk, responsible AI or governance frameworks
  • The ability to translate complex risk into practical decisions and actions
  • Strong executive communication and stakeholder influence

This role offers direct impact on how AI is governed across AMP, with the autonomy to shape a capability that is still evolving.

➡️ Apply now: Principal, Entreprise AI Risk

FS-ISAC Forum in Melbourne

A highly engaging FS-ISAC forum in Melbourne today, hosted by AMP.

The sessions focused on learning from other industries and exploring how those insights can be applied within financial services. It was a valuable reminder that many of the challenges we face are not unique, and cross-industry collaboration can unlock new ways of thinking about resilience and risk.

I also had the opportunity to present on the intersection of geopolitics and cybersecurity. We discussed how global tensions, shifting alliances, and regulatory fragmentation are increasingly shaping the threat landscape, and more importantly, what organisations can do to prepare. Building geopolitical awareness into cybersecurity strategy is no longer optional; it is becoming a core capability.

Thanks Lachlan P., Steve E., Ciara C. and Ashish P. for making it happen!

20260522-001

💡 Claude Mythos and the Next Shift in Cyber Security

Article

Feels like every CISO must have an opinion on Claude Mythos these days… so here’s mine 😄

This article is a quick take on what Mythos means for organisations and what cyber security teams will have to do to respond.

Read More…

We’re hiring: Head of Information Security

📍 Sydney (Hybrid) | 🏦 Financial Services | 🛡️ Information Security Leadership

We’re seeking a Head of Information Security to lead and elevate AMP’s enterprise‑wide cyber capability at a pivotal time for the organisation.
This is a highly strategic and influential role, responsible for shaping AMP’s cyber resilience, strengthening regulatory posture and enabling the secure delivery of digital products and services. You’ll lead an end‑to‑end security function spanning governance, architecture, engineering, operations and incident response, ensuring security is embedded by design and supports business innovation.

Working closely with senior technology, risk and business leaders, you’ll translate complex cyber risk into clear business decisions, guide investment priorities and drive a shift towards a proactive, risk‑based and continuously improving security posture. You’ll also play a critical role in executive decision‑making during cyber incidents and in strengthening AMP’s overall security maturity.

You’ll be a great fit for this role if you have:
  • Proven experience leading enterprise‑scale information security functions in complex, regulated environments
  • Deep expertise across security architecture, cyber defence, operations and incident response
  • Strong capability in domains such as IAM, threat detection, vulnerability management and secure‑by‑design practices across cloud, data and applications
  • Experience translating threat intelligence into actionable strategies and leading during high‑impact cyber incidents
  • A forward‑looking perspective on emerging risks, including AI‑driven threats and post‑quantum security considerations
  • The ability to influence senior stakeholders and communicate cyber risk in clear business terms

At AMP, we operate lean and close to the action. You’ll have direct influence on strategic decisions, the autonomy to lead meaningful change and the opportunity to build and shape a high‑performing security function. If you’re adaptable, resilient and thrive in environments where you can balance strategy with execution, you’ll do well here.

If you’re ready to lead security at scale and help shape the future of cyber resilience at AMP, we’d love to hear from you.

➡️ Apply now: Head of Information Security

Cybersecurity Study Group: (ISC)² Certified in Cybersecurity (CC)

Great to see the ISC2 Sydney Chapter launching its first pilot CC Study Group yesterday!
This initiative is all about helping members prepare for the Certified in Cybersecurity (CC) exam through shared learning and open discussions. During the session, Edward F. and I had the privilege of facilitating conversations around key domains and question strategies, but the real value came from the group’s engagement, curiosity, and collaborative spirit.
A big thank you to everyone who joined and contributed to the conversations. It’s exciting to see how this program can continue to grow and support aspiring cybersecurity professionals in Sydney.

20260317-001

Looking for more?
▶️ A series of articles I published back in 2023 covering all the areas of knowledge required to earn the ISC2 CC certification:

We’re hiring: Senior Cyber Defence and Response Specialist

📍 Sydney (Hybrid) | 🏦 Financial Services | 🛡️ Cyber Defence & Incident Response

We’re continuing to strengthen our Cyber Defence Centre at AMP and are recruiting a Senior Cyber Defence and Response Specialist to help protect an iconic Australian financial institution during a period of genuine transformation.

This is a hands‑on, technical role at the heart of our cyber operations. You’ll be detecting, investigating and responding to sophisticated threats across a complex enterprise environment, while helping us move towards a more proactive, intelligence‑led defence model. Beyond BAU response, you’ll play a key role in improving detection, threat hunting, automation and incident response maturity across AMP.

You’ll be a great fit for this role if you have:
  • Strong, hands‑on experience in incident response, threat hunting and security event analysis
  • Solid capability across SIEM, XDR, endpoint, WAF and cloud security controls
  • Experience working in large, regulated enterprise environments
  • Practical knowledge of frameworks such as MITRE ATT&CK, NIST and cyber kill chains
  • A calm, analytical approach and the ability to perform well in fast‑paced situations

At AMP, we’re intentionally lean, inclusive and outcomes‑focused. You’ll be close to the action, encouraged to challenge the status quo, and supported by leaders who genuinely value strong security thinking. If you enjoy variety, taking ownership, and seeing your work directly improve organisational resilience, you’ll feel at home here.

If you’re keen to protect what matters today and help shape how cyber defence is done tomorrow, we’d love to hear from you.

➡️ Apply now: Senior Cyber Defence and Response Specialist

💡 Geopolitics Is Now a Technology Risk

Article


Geopolitics has become a direct and material technology risk, and it now firmly belongs on the CISO’s agenda. 🌐 Trade disputes, sanctions, cyber espionage, and digital sovereignty are reshaping where data lives, who can access it, and how resilient our platforms really are.

Our dependence on globally distributed supply chains and a small number of predominantly US-based ☁️ cloud providers has concentrated high‑value data and critical services in a few strategic locations. In a heightened geopolitical environment, cloud data centres are now strategic infrastructure, and disruptions—malicious or not—can quickly become systemic business events.

In this article, I explore why technology is uniquely exposed to geopolitical shocks and what CISOs and technology leaders should be doing now to factor geopolitics into cloud, availability, and resilience planning.

Read More…

Cybersecurity Study Group: (ISC)² Certified in Cybersecurity (CC)

Looking forward to our pilot Cybersecurity Study Group session with Edward F.! 🚀
If you’re interested in the (ISC)² Certified in Cybersecurity (CC) certification, this is your chance to study with peers, ask questions, and learn from industry professionals.

We’re hiring: Senior Security Architect

📍 Melbourne (Hybrid) | 🏦 Financial Services | 🔒 Security Architecture
We’re expanding our security team at AMP and hiring a Senior Security Architect to design and implement robust security architectures in a regulated financial environment.
You’ll lead security strategy, architect secure systems, collaborate with engineering teams, and ensure compliance while protecting customer data and operations.

You’ll be great for this role if you have:
🔹 Proven experience in security architecture and design
🔹 Deep knowledge of cloud security, identity management, and threat modelling
🔹 Background in financial services or regulated industries
🔹 Strong communication skills to influence stakeholders

Join us to shape secure financial services innovation and advance your cybersecurity career.

➡️ Apply now: Senior Security Architect

💡 You Can’t Secure What You Can’t See: The Case for SBOMs

Article


Modern software is assembled from countless third‑party and open‑source components. And if you can’t see them, you can’t secure them. 🔎🔐

This article explains why SBOMs (Software Bills of Materials) are becoming essential for managing supply‑chain risk, strengthening incident response, and meeting rising security and compliance expectations.

If you want faster visibility, better control, and fewer surprises in your software stack, this one’s for you.

Read More…

We’re hiring: Security Services Senior Specialist (AppSec)

📍 Sydney (Hybrid) | 🏦 Financial Services | 🔐 Application & Vulnerability Security
We’re expanding our security team at AMP and hiring a Security Services Senior Specialist to lead application security, penetration testing, and vulnerability management.
You’ll own and uplift our AppSec framework, pen‑testing program, and vulnerability lifecycle, shaping engineering practices and protecting millions of customers.

You’ll be great for this role if you have:
🔹 Strong AppSec, pen testing, and vuln‑management experience
🔹 Confidence owning services and improving processes
🔹 Experience in regulated environments
🔹 Ability to turn technical risks into clear guidance

Join us to make a real impact on the future of financial services while growing your career.

➡️ Apply now: Security Service Senior Specialist

We’re hiring: 2x Enterprise Security Architects

📍 Sydney (Hybrid) | 🏦 Financial Services | 🔐 Enterprise-scale security
We’re expanding our security leadership capability and are recruiting two Enterprise Security Architects to help shape and protect a complex, customer‑centric financial services environment.
If you’re passionate about designing security that enables the business, working at enterprise scale, and influencing outcomes across cloud, data, and core platforms, this could be a great next step.

➡️ Apply now: Entreprise Security Architect

💡Agentic AI's Identity Crisis

Article

Agentic AI — autonomous 🤖 agents that can perceive, decide, and act — are entering business workflows fast. But as these non-human “digital workers” multiply, 🫆 identity has become the hidden challenge.

Most enterprises haven’t extended authentication and access controls to these agents, creating ungoverned digital personas operating at machine speed: a serious security risk.

This article explores why identity is the new frontier of AI security, and how cybersecurity leaders can govern agentic AI safely through strong authentication, lifecycle management, and accountability.

Read More…
Linkedin Icon

Follow Jean-Baptiste Bres on Linkedin