Expertise
Focus regions
Offering
Factor Team
Sanja Petrovic
Expert Advisor
Career
Sanja Petrovic is a senior technology, cybersecurity and data governance executive with more than 20 years of experience spanning software engineering, information technology, cybersecurity, governance and strategic transformation. She has built her career across financial services and wealth management, progressing from hands-on technology and development roles into senior technology leadership and ultimately executive responsibility for cybersecurity and data governance.
Sanja currently serves as General Manager, Cyber Security & Data Governance at HUB24, where she is responsible for the intersection of cyber resilience, data governance, risk, privacy and technology leadership within a highly regulated financial services environment. Her experience combines technical understanding with enterprise-level governance, allowing her to connect security and data considerations with broader business strategy, operational requirements and organisational outcomes.
A defining feature of Sanja’s career has been her ability to bridge functions that traditionally operate separately. She brings together technology, security, data, governance and business teams to establish shared accountability, strengthen organisational resilience and embed risk considerations into everyday decision-making rather than treating them as isolated security or compliance activities.
Role at Factor
As an Expert Advisor at Factor, Sanja brings senior financial services experience across cybersecurity, data governance, technology strategy, resilience and organisational transformation to executive discussions on the future of technology and risk leadership.
Her expertise is particularly relevant as organisations navigate an environment where cyber risk, data governance, privacy, AI adoption and technology transformation are increasingly interconnected. Sanja helps leaders examine how security and governance can become embedded within technology and business operations, rather than operating as separate control functions.
Sanja brings a practical perspective on the relationship between IT operations and cybersecurity. Her recent work exploring security as a shared responsibility reflects her view that effective cyber resilience depends on stronger collaboration between technology and security teams, shared measures of success and a common understanding of operational constraints.
She also helps executives consider how governance needs to evolve alongside emerging technologies. As organisations adopt AI and increasingly depend on data-driven systems, Sanja brings a risk-aware perspective on responsible adoption, accountability, privacy, resilience and the foundations required to support innovation safely.
Key roles Sanja works with include: Chief Information Officers (CIOs), Chief Technology Officers (CTOs), Chief Information Security Officers (CISOs), Chief Data & AI Officers (CDAOs), Chief Risk Officers (CROs), Chief Operating Officers (COOs), Chief Privacy & Data Leaders, Technology & Transformation Leaders, Cybersecurity & Governance Leaders, and Board & Risk Leaders.
Previous Roles
Sanja currently serves as General Manager, Cyber Security & Data Governance at HUB24, having previously held the role of General Manager, Cyber Security & Governance. Across these roles, she has operated at the intersection of cybersecurity, governance, technology risk and business resilience within the financial services sector.
Prior to her executive cybersecurity leadership, Sanja spent almost three years as Head of Cyber Security and Governance at HUB24. She was responsible for strengthening cybersecurity capability and governance while helping the organisation navigate an increasingly complex technology and regulatory environment.
Earlier, Sanja served as Program Manager, Strategic Alignment and Continuous Improvement at HUB24, developing her focus on organisational alignment, operational improvement and connecting strategic priorities with practical execution.
Sanja spent more than 12 years with Xplore Wealth, progressing through technology and development roles before becoming Head of Information Technology. During her eight years as Head of IT, she led technology capability across the organisation, bringing together application development, technology operations, strategic planning and business requirements. Her earlier roles as Development Team Leader and Programmer Analyst provided a strong technical foundation that continues to inform her executive approach to technology and security.
She began her career with IFAA, progressing from Service Desk Officer into software engineering, business analysis and business outsourcing roles. This early experience gave her a detailed understanding of technology from the operational and user perspective, before progressing into development, IT leadership, governance and cybersecurity.
Sanja holds a Bachelor of Information Technology in Software Engineering from Queensland University of Technology and has continued to build her expertise across cybersecurity, privacy and governance. Her professional development includes ISC2 Certified in Cybersecurity and formal training in privacy and the Australian Privacy Principles through the Office of the Australian Information Commissioner.
Media Presence and Industry Contributions
Sanja is an active contributor to Australia's cybersecurity and technology leadership community, regularly participating in industry conferences, executive discussions and thought leadership focused on cyber resilience, governance, technology transformation and the future of financial services.
She has spoken at major industry events including CISO and cybersecurity forums, sharing perspectives developed through more than two decades in technology and financial services. Her recent discussions have explored the evolution of cyber strategy, the importance of organisational resilience and the need to move beyond traditional boundaries between IT operations and security.
Sanja is also a strong advocate for knowledge sharing and professional development within the cybersecurity community. She has been recognised as a finalist in the Australian Women in Security Awards for Best Volunteer / Mentor, reflecting her commitment to supporting emerging talent, creating opportunities and helping others develop their potential.
Her industry perspective extends beyond cybersecurity itself. Through her involvement in discussions around financial services modernisation, AI and technology transformation, she brings together cyber, data, governance and business considerations to examine how organisations can modernise while maintaining trust, resilience and accountability.
Leadership Philosophy
Sanja believes cybersecurity is most effective when it becomes a shared organisational responsibility rather than something owned exclusively by the security team. Strong resilience requires technology, security, data and business teams to understand one another's priorities, constraints and responsibilities.
She believes governance should enable better decision-making rather than simply create additional layers of control. In highly regulated environments, organisations need to understand their risks, establish appropriate guardrails and build governance into the way technology and data are used every day.
Sanja also places strong emphasis on collaboration and shared accountability. The traditional divide between IT Operations and SecOps can create gaps in ownership, communication and execution. Bringing teams together around common measures, integrated workflows and mutual understanding can strengthen both security outcomes and operational effectiveness.
As organisations increasingly adopt AI and modernise their technology environments, Sanja believes the fundamentals become even more important. Strong data foundations, clear accountability, effective governance, privacy, security and organisational resilience provide the conditions in which innovation can be adopted responsibly.
Her advisory approach combines technical depth with executive perspective. Sanja helps leaders understand not only the security or technology issue in front of them, but how it connects to business strategy, data, operational resilience, regulatory expectations and organisational behaviour, enabling more integrated and sustainable technology leadership.
