21 Aug
|
hipages Group
|
New South Wales
21 Aug
hipages Group
New South Wales
Job Description
Hi! We're hipages, an ASX-listed tech company and Australia's #1 digital platform connecting households with trusted home improvement businesses. We're on a mission to transform the home improvement industry to build better lives for everyone.
n With teams across Australia, New Zealand, the Philippines and Vietnam, we work as one team with a shared purpose.
n
We're proud to be a certified Great Place to Work and WORK180's #1 Employer for Women. At hipages, you'll find real impact, career growth and a workplace where everyone belongs.
n
About the role
n
You'll own security strategy,governance and operations end-to-end: from presenting posture and risk to the Board's Audit& Risk Committee and Tech Working Group, to steering the security platform and itscontinuous improvement with a small, high-calibre team through an AI-accelerated engineering transformation.
n
Why join our Engineering team?
n
n
- Competitive salary, benefits, and everyday discounts
n
- In-house Talent Development team to prioritise personal and growth opportunities
n
- Cross-functional collaboration
n
- Hands-on learning opportunities and workshops for continuous upskilling
n
n
How you will add value
n
n
- Own the cyber security strategy and roadmap, anchored to NIST CSF 2.0 and OWASP SAMM, and present posture and risk quarterly to the Audit & Risk Committee and periodically to the Tech Working Group.
n
- Own the security platform — cloud, endpoint, identity, network/SSE, WAF and CI/CD vulnerability gates — configuring and governing tooling, delivered through your AppSec lead, IT Operations and SRE.
n
- Lead security incident response including board-level exercises, run vulnerability management end-to-end, and drive secrets management and IAM hygiene with SRE and Platform teams.
n
- Set the security model for AI-assisted engineering and agentic systems: secure-by-default development practices, agent identity and access, agent-tooling governance and shadow-AI visibility.
n
- Own the external IT audit relationship, run the annual penetration testing program,
and oversee privacy operations and vendor due diligence alongside Legal.
n
- Lead, coach and grow your Lead Application Security Engineer, building a partnering model across Engineering, SRE and IT Operations that scales security guidance without becoming a bottleneck.
n
n
About you
n
n
- 8+ years experience in security, including experience leading a security function or operating as the clear second-in-command of a larger one, ideally within a listed company or similarly governed environment, with working knowledge of Australian privacy law and listed-company security obligations
n
- Proven board/committee reporting capability: You can translate technical posture into risk language for non-technical directors and hold the room on "are we doing enough?"
n
- Strong technical command of cloud security (AWS), application security / secure SDLC, and the modern control stack (CNAPP/CSPM, EDR, SSE, IdP/MDM, WAF, cloud SIEM), able to configure, evaluate and direct these tools
n
- Framework and audit fluency: NIST CSF 2.0 and OWASP SAMM (or equivalents), with experience running external audits (Big-4 ITGC or similar) through to remediation
n
- Credible AI security depth: LLM and agentic threat models, non-human identity, agent-tooling governance — and demonstrated use of AI to multiply a small team's output
n
- A landscape thinker who delivers through others: You synthesise the evolving threat environment into posture, priorities and pragmatic risk trade-offs, leading through a lean team and partner teams with commercial discipline on a flat budget
n
- Experience in a product-led technology, SaaS or marketplace/consumer-scale organisation
n
- Multi-geography workforce security (offshore teams and development partners)
n
- Purple teaming / offensive security background
n
- Security certifications (CISSP, CISM, SABSA or similar)
n
n
Life at hipages
n
We're more than just a workplace. We're a place where you can be yourself, do great work and grow your career. Recognised as a Outstanding Place to Work, our inclusive, supportive culture helps people thrive.
n
You'll use the best tools and tech, with real impact on our products and customers. We invest in your development and lead with coaching, not micromanagement – it's why 85% of our team say their leader is great.
n
And there's more:
n
n
- Diverse, collaborative teams that love solving problems
n
- Agile squads, hackathons, off-sites and roadshows
n
- Extra leave for birthdays, volunteering, and more
n
- Healthy snacks, continental breakfast and fresh fruit
n
- Sydney CBD office near Town Hall and Gadigal Stations
n
- Tailored growth support, mentoring and stretch projects
n
- A vibrant social scene - we work hard and have fun doing it
n
n
At hipages, innovation and collaboration thrive in diverse and inclusive teams. We don't expect you to know everything - we care more about who you are as a person, a team member, and a leader. We're proud to be endorsed by WORK180 for supporting women's careers and we value diversity across culture, age, gender identity and sexual orientation.
n
Research shows that men often apply when they meet just 60% of the criteria, while women and minority groups wait until they tick every box. If you think you'd be a great fit - even if you don't meet every requirement - we'd love to hear from you.
n
We're also a Circle Back Initiative Employer, which means we commit to responding to every applicant.
n
Be careful - Don't provide your bank or credit card details when applying for jobs. Don't transfer any money or complete suspicious online surveys. If you see something suspicious, report this job ad .
#J-18808-Ljbffr
📌 Head of Cyber Security New (New South Wales)
🏢 hipages Group
📍 New South Wales