Назад
Company hidden
7 часов назад

Head of Cyber Security

Формат работы
hybrid
Тип работы
fulltime
Грейд
head
Английский
b2
Страна
Australia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Head of Cyber Security: Owning end-to-end security strategy, governance, operations, and platform security for a digital home improvement marketplace with an accent on cloud security, application security, risk governance, and AI-assisted engineering. Focus on presenting cyber risk to the Board, leading incident response and audits, governing agentic-system security, and scaling security delivery through a lean team and engineering partners.

Location: Sydney, New South Wales, Australia; hybrid working model

Company

hirify.global is an ASX-listed Australian technology company operating a digital platform that connects households with home improvement businesses.

What you will do

  • Own the cyber security strategy and roadmap based on NIST CSF 2.0 and OWASP SAMM.
  • Present security posture and risk to the Audit & Risk Committee and Tech Working Group.
  • Govern cloud, endpoint, identity, network/SSE, WAF, CI/CD vulnerability gates, and related security tooling.
  • Lead incident response, vulnerability management, secrets management, IAM hygiene, penetration testing, and external IT audits.
  • Define secure-by-default practices for AI-assisted engineering and agentic systems, including agent identity, access, tooling governance, and shadow-AI visibility.
  • Lead, coach, and grow the Lead Application Security Engineer while partnering with Engineering, SRE, and IT Operations.

Requirements

  • 8+ years of security experience, including leadership of a security function or second-in-command responsibility.
  • Experience translating technical security posture into risk reporting for boards or committees.
  • Strong technical knowledge of AWS cloud security, application security, secure SDLC, CNAPP/CSPM, EDR, SSE, IdP/MDM, WAF, and cloud SIEM.
  • Experience with NIST CSF 2.0, OWASP SAMM or equivalent frameworks, external audits, and remediation.
  • Knowledge of Australian privacy law and listed-company security obligations.
  • Experience with LLM and agentic threat models, non-human identity, agent-tooling governance, and using AI to increase security-team output.

Nice to have

  • Experience in a product-led technology, SaaS, marketplace, or consumer-scale organisation.
  • Experience securing multi-geography workforces and offshore development partners.
  • Purple teaming or offensive security experience.
  • CISSP, CISM, SABSA, or a similar security certification.

Culture & Benefits

  • Hybrid working model with a Sydney CBD office near Town Hall and Gadigal Stations.
  • Competitive salary, benefits, and everyday discounts.
  • Talent development, mentoring, workshops, and stretch projects.
  • Collaborative agile squads, hackathons, off-sites, and roadshows.
  • Additional leave for birthdays and volunteering, plus workplace refreshments.
  • Inclusive culture recognised by Great Place to Work and WORK180.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →