7 часов назад
Head of Cyber Security
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Head of Cyber Security: Owning end-to-end security strategy, governance, operations, and platform security for a digital home improvement marketplace with an accent on cloud security, application security, risk governance, and AI-assisted engineering. Focus on presenting cyber risk to the Board, leading incident response and audits, governing agentic-system security, and scaling security delivery through a lean team and engineering partners.
Location: Sydney, New South Wales, Australia; hybrid working model
Company
is an ASX-listed Australian technology company operating a digital platform that connects households with home improvement businesses.
What you will do
- Own the cyber security strategy and roadmap based on NIST CSF 2.0 and OWASP SAMM.
- Present security posture and risk to the Audit & Risk Committee and Tech Working Group.
- Govern cloud, endpoint, identity, network/SSE, WAF, CI/CD vulnerability gates, and related security tooling.
- Lead incident response, vulnerability management, secrets management, IAM hygiene, penetration testing, and external IT audits.
- Define secure-by-default practices for AI-assisted engineering and agentic systems, including agent identity, access, tooling governance, and shadow-AI visibility.
- Lead, coach, and grow the Lead Application Security Engineer while partnering with Engineering, SRE, and IT Operations.
Requirements
- 8+ years of security experience, including leadership of a security function or second-in-command responsibility.
- Experience translating technical security posture into risk reporting for boards or committees.
- Strong technical knowledge of AWS cloud security, application security, secure SDLC, CNAPP/CSPM, EDR, SSE, IdP/MDM, WAF, and cloud SIEM.
- Experience with NIST CSF 2.0, OWASP SAMM or equivalent frameworks, external audits, and remediation.
- Knowledge of Australian privacy law and listed-company security obligations.
- Experience with LLM and agentic threat models, non-human identity, agent-tooling governance, and using AI to increase security-team output.
Nice to have
- Experience in a product-led technology, SaaS, marketplace, or consumer-scale organisation.
- Experience securing multi-geography workforces and offshore development partners.
- Purple teaming or offensive security experience.
- CISSP, CISM, SABSA, or a similar security certification.
Culture & Benefits
- Hybrid working model with a Sydney CBD office near Town Hall and Gadigal Stations.
- Competitive salary, benefits, and everyday discounts.
- Talent development, mentoring, workshops, and stretch projects.
- Collaborative agile squads, hackathons, off-sites, and roadshows.
- Additional leave for birthdays and volunteering, plus workplace refreshments.
- Inclusive culture recognised by Great Place to Work and WORK180.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Security Operations Analyst (Cybersecurity)
3 дня назад
Senior Cloud Security Operations Analyst (Cloud Security)
6 дней назад
Security Operations Centre Specialist (Cybersecurity)
Canva
4 дня назад
Enterprise Security Team Lead (Cybersecurity)
Canva
4 дня назад
Senior Security Engineer (Investigations)
8 часов назад