Head of Information Security
NewBe an early applicantSummary
Lead MAS's information security, cyber resilience and data protection function as Head of Information Security, reporting to the CTO. You'll drive security maturity, governance and incident response across a hybrid cloud (Azure/AWS), SaaS and on-prem environment, advising Executive and Board stakeholders while leading a small team.
Auckland, Wellington or Christchurch based | Permanent
Security is evolving faster than ever, and so are we.
At MAS, we're looking for an experienced and influential security leader to shape our cyber security, information protection and resilience capability for the future.
Reporting to the Chief Technology Officer, you'll lead our information security strategy, drive cyber maturity across the organisation and help ensure security remains an enabler of innovation, growth and exceptional Member outcomes.
This is a highly visible leadership role, working closely with the Executive team and Board while leading a small team and partnering across technology, risk, legal, compliance and the wider business. If you're excited by influencing enterprise-wide change and building a modern security capability, this is an opportunity to make a lasting impact.
Why this role?
This is an opportunity to:
Shape MAS's enterprise-wide security and data protection strategy
Influence decisions at Executive and Board level
Lead and grow a high-performing security team
Drive meaningful cyber resilience, information management and data protection outcomes
Lead organisation-wide security maturity and culture uplift initiatives
Help embed security as a business enabler in a hybrid cloud, SaaS and on prem environment
What you'll be doing
As Head of Information Security, you'll be responsible for leading MAS's information security, cyber resilience and data protection capability while helping the organisation continue its security maturity journey.
You will:
Develop and deliver MAS's Security and Data Protection Strategy
Drive security maturity initiatives and foster a strong security culture across the organisation
Lead cyber resilience, security operations and incident response capability
Strengthen information management, data protection and data loss prevention practices
Establish security governance frameworks and provide security risk oversight, ensuring regulatory, legal and compliance obligations are effectively managed
Manage third-party, supplier and security supply chain risks, including oversight of external security providers and key technology partners
Support the secure adoption of cloud and emerging technologies, including AI
Provide trusted security advice and reporting to Executive and Board stakeholders
Lead and develop a small team while building security capability across the wider business
What you'll bring
We're looking for a leader who has successfully guided organisations through a security maturity journey and knows how to influence change through people, communication and leadership.
You'll bring:
Significant experience in information security, cyber security, technology risk or security leadership roles
Experience working within complex organisations, ideally in financial services, technology, SaaS, telecommunications, government or other regulated environments
Proven experience engaging with Executive teams, Boards and governance forums
Strong knowledge of security and governance frameworks such as NIST, ISO 27001 and SOC 2
Experience leading enterprise security strategy, governance and organisational uplift programmes
Strong understanding of information management, data protection, risk management and regulatory obligations
Experience managing third-party providers, supplier risk and security supply chain controls
Experience with cloud security including Azure and/or AWS
Outstanding communication and stakeholder management skills, with the ability to engage technical and non-technical audiences alike
The ability to operate strategically while remaining effective in operational delivery and execution
Willingness to travel as required
We're particularly interested in hearing from leaders who have helped organisations improve security capability, uplift culture and navigate meaningful change while balancing risk, business objectives and customer outcomes.
If you're looking for a role where you can combine strategic leadership with hands-on influence and leave a lasting security legacy, we'd love to hear from you.
Why MAS?
MAS is a New Zealand-owned mutual insurer and investment company. Because we're owned by our Members rather than shareholders, we're focused on doing what's right for our Members, our people and our communities.
When you join MAS, you'll be part of a team that's:
Motivated to make a difference
Focused on achieving great outcomes for our Members and building a stronger mutual
Guided by our values: Make a Difference, In It Together and Own It, Do It
Supportive, inclusive and committed to helping people thrive
Backed by a range of benefits, including Health and Life Insurance and 6% KiwiSaver
Ready to make an impact?
If you're ready to shape the future of information security at MAS and help strengthen the trust our Members place in us every day, we'd love to hear from you.