You’ve built strong technical cybersecurity capability.
You may have started your career in infrastructure, systems or networking before moving deeper into cybersecurity.
But the next step can be harder to find.
In larger security teams, careers become specialised quickly. You can become very good at one part of cybersecurity without getting the opportunity to bring the technical, risk and governance sides together.
This role gives you that broader remit.
Why this role is different
We’re partnering with a national retail business in Western Sydney to appoint a Cyber Security Manager who will become its primary cybersecurity subject matter expert.
This is a standalone role with no direct reports. You are being hired to own cybersecurity outcomes, not manage a large team.
Approximately 70% of the role is cybersecurity, spanning security operations and engineering, risk, governance, controls and compliance.
The remaining 30% is hands-on Level 3 infrastructure and networking, keeping you close to the underlying technology and providing additional technical resilience across the team.
Cybersecurity remains the priority.
This makes the role particularly relevant for a technically strong Senior Cyber Security Engineer or Cyber Lead who already has exposure to risk, governance and controls.
You won’t need to have independently owned every part of the remit, but you will need genuine experience beyond purely technical cybersecurity.
The opportunity is to build on that foundation and move from exposure and contribution into broader functional ownership, while remaining close to the technology.
What you’ll own
The cybersecurity foundations are established, but there is meaningful chance to continue lifting maturity.
Your remit will span:
- Cybersecurity risk, governance, policies and controls
- Security operations, incidents and vulnerability management
- NIST, Essential Eight,
PCI DSS, cyber insurance and audit
- Identity, endpoint, network and cloud security
- Third-party security, IT disaster recovery and resilience
- Security tooling, managed security partners and senior stakeholder reporting
There is established specialist security support around the role, including a 24/7 managed SOC.
With much of the routine monitoring and alert triage supported externally, you’ll have greater capacity to focus on material security issues, risk decisions and improving the broader cybersecurity capability.
The environment
This is a national retail environment spanning physical locations, supply chain, distribution and ecommerce.
Technology directly affects the organisation’s ability to trade, so cybersecurity needs to work in the real world.
The technology team is friendly, and the culture is practical, down-to-earth and low on unnecessary hierarchy. You’ll have visibility across the business and work directly with internal teams, senior stakeholders, vendors, auditors and specialist security partners.
There is genuine scope to influence how cybersecurity is approached, but the expectation is equally practical: understand the risk, form a view and implement solutions that work for the business.
That means balancing security with cost, usability and operational impact rather than pursuing controls in isolation.
For someone coming from a larger or more specialised environment, the attraction is the breadth of exposure,
proximity to decision-making and opportunity to make a visible contribution.
What you’ll bring
You may currently be operating as a Senior Cyber Security Engineer, Cyber Security Lead, Senior Infrastructure & Security Engineer or technically oriented Cyber Security Manager.
You’ll bring strong technical cybersecurity foundations across incident response, vulnerability management, threat detection, identity and access management, endpoint, network and cloud security.
Networking capability is important. You don’t need to be a dedicated Network Engineer, but you do need genuine networking foundations and enough technical depth to understand and troubleshoot complex issues across the environment.
Alongside your technical capability, you’ll need genuine exposure to cybersecurity governance, risk and controls.
You may not have independently owned every framework, audit or compliance obligation, but you should have worked with cybersecurity risk assessments, security policies and controls, governance and compliance processes, and NIST and/or Essential Eight.
The important distinction is that this isn’t your first exposure to GRC. You already understand how technical security connects to risk and controls; you’re now ready for greater accountability across them.
Most importantly, you’ll be curious, self-directed and comfortable taking initiative.
Location and remuneration
The role is based in Western Sydney, with onsite parking available.
The working model is four days per week onsite, with Friday available to work from home.
Next steps
For a confidential discussion about the role, contact Steven Fulop at xceltium on 04•• ••• 446 or
[email protected]
All applications and conversations will be treated discreetly. We look forward to supporting you with your job search.
📌 Cyber Security Manager (Homebush)
🏢 Xceltium
📍 Homebush