Senior Information Security Specialists
If you're the kind of security professional who's tired of ticking boxes instead of building real resilience — this is the opposite of that. You'll own the security posture end-to-end: the strategy, the client relationship, the hard calls, and the outcome. Not a piece of the defence. All of it.
Why AMARU?
Six years ago, we set out to change how cybersecurity is delivered for businesses across the region. Today, we're New Zealand's fastest-growing cybersecurity company, working with organisations across NZ, Australia, Fiji and Papua New Guinea, and we're expanding.
We're not here to tick boxes. We're here to do security right, and we're building a team that feels the same way. You'll have real ownership over your client accounts, work alongside people who care about the craft, and be part of a company that's growing fast and doing things differently. There's a lot to learn here, and we invest in the people who bring that same energy to their work.
If you're someone who takes ownership, stays curious, and wants to be part of something that's genuinely raising the bar, read on.
This role reports directly to our CEO — you'll have direct visibility into company direction and a genuine seat at the table, not layers of management between you and the decisions that matter.
This role suits someone with real drive — you'll be juggling multiple clients at once, each with their own risks, timelines and priorities, and you'll bring the energy and organisation to give every one of them your best. It's also not a clock-watching, nine-to-five kind of role. Security incidents and client needs don't run on a schedule, and the people who thrive here are the ones who genuinely care about getting it right for the client in front of them — not just closing out the ticket. If that sounds like more effort than you're looking to give, this probably isn't the role for you. If it sounds like exactly the kind of work you want to be doing, keep reading.
What leading end-to-end actually means here
You won't be a cog handing findings to someone else to action. You'll be the one:
Leading compliance assessments and framework implementations across SOC 2, ISO 27001, NIST CSF and other major standards — from first conversation to final sign-off
Managing multiple client accounts simultaneously, each moving at its own pace
Owning risk assessments and security analysis, then building remediation plans that get executed, not shelved
Designing security strategy around what each client's business genuinely needs
Taking penetration testing findings and driving remediation through with clients, personally, start to finish
Getting hands-on with serious tooling — EDR, SIEM, SOAR, IAM, MDM, WAF, CASB, DLP, ZTNA, password managers, cloud security controls — when the work calls for it
Delivering security awareness training that changes how people actually behave, not just ticks a box
Being the trusted voice in the room — boardroom or engineering team — when it matters most
Shaping how AMARU itself grows, not just executing inside a system someone else built
What you'll bring
High drive and the discipline to manage multiple clients well
Excellent communication — the kind that builds trust with a CEO and a sysadmin in the same day
Real, hands-on implementation experience with SOC 2, ISO 27001 or NIST CSF
Confident, everyday use of AI tools to work faster and smarter — this is a must, not a nice-to-have
A genuine desire to protect the businesses you work with, and the willingness to go the extra mile when a client needs it
5+ years delivering security and GRC work with outcomes you can point to and are proud of
Enough technical depth to advise, oversee, and roll up your sleeves when needed
The ability to turn pentest findings into remediation plans clients will actually follow through on
Comfort with ambiguity, and the instinct to build the plan when there isn't one handed to you
NZ experience and the right to work in New Zealand
Bonus points for ISO 27001 Lead Implementer, CISSP, CISM or CRISC
If you want a role where you carry real responsibility for real outcomes — not just deliverables — we’d love to hear from you.