Senior Manager Information Security
Summary
Hands-on 2IC security leadership role at an energy-sector organisation in Sydney, reporting to the CISO and leading up to five professionals across cyber governance & assurance, security consulting, and enterprise security architecture. Heavy focus on compliance with SOCI Act, AESCSF, ISO 27001, NIST CSF and APRA obligations.
2IC role leading a team within the energy industry, reporting to the CISO
Leading a team of up to five security professionals, you will oversee three critical security pillars:
- Cyber Governance & Assurance
- Cyber Security Consulting
- Enterprise Security Architecture
About the Role
As a senior member of the cyber security leadership team, you will provide strategic direction while maintaining end-to-end ownership of key security initiatives across the organisation.
You will act as a trusted advisor to executive stakeholders, technology leaders and business units, helping shape security strategy while ensuring practical and commercially aligned outcomes are achieved.
Key responsibilities include:
- Leading enterprise-wide cyber governance, assurance and compliance programs.
- Managing compliance against recognised security frameworks and regulatory obligations.
- Leading internal and external audits, assurance reviews and control effectiveness assessments.
- Providing specialist cyber security consulting and advisory services across technology and business initiatives.
- Driving secure-by-design principles across enterprise architecture, transformation and technology delivery programs.
- Overseeing security risk management activities and providing pragmatic guidance on risk treatment strategies.
- Developing and maintaining cyber security policies, standards and governance frameworks.
- Leading supplier and third-party assurance activities.
- Delivering cyber security reporting, metrics and insights to senior executives and governance committees.
- Championing security awareness, training and organisational culture initiatives.
- Monitoring emerging threats, regulatory changes and industry developments to ensure security strategies remain effective and future-focused.
You are an experienced cyber security leader who can comfortably operate in both strategic and operational environments.
You have built credibility through your ability to translate complex security requirements into practical business outcomes and have a proven history of influencing stakeholders at all levels of an organisation.
Most importantly, you enjoy leading people while remaining close to the work itself. You are equally comfortable presenting to executives, guiding architects and engineers, conducting assurance activities, or helping shape security solutions for key business initiatives.
Technical & Regulatory Experience
Exposure to the following frameworks, standards and regulatory environments would be advantageous:
- SOCI Act
- AESCSF
- ISO 27001
- NIST Cyber Security Framework
- CPS 234
- APRA Prudential Standards
- Enterprise Risk Management Frameworks
- Secure-by-Design Principles
- Security Architecture Frameworks
Why Apply?
This is a rare opportunity to lead multiple cyber security disciplines within an organisation that views information security as a strategic business enabler.
