11 Sep
|
RedShield Security
|
Victoria
11 Sep
RedShield Security
Victoria
Job Description
Cyber Security & Information Security Management
n
n
- Establish, own, and continuously improve RedShield's Information Security Management System (ISMS), ensuring alignment with ISO 27001, SOC 2, and applicable regulatory frameworks.
n
- Develop, implement, and maintain security policies, standards, and procedures across the organisation, ensuring they are embedded in day-to-day operations and understood by all staff.
n
- Lead RedShield's security incident response programme, including the development of incident response plans, tabletop exercises, and post-incident reviews to drive continuous improvement.
n
- Oversee and manage RedShield's internal security posture — including vulnerability management, patch management, and security hardening across systems, applications, and cloud infrastructure.
n
- RedShield Security · Chief Information Security Officer · Page 1
n
- Commercial in Confidence
n
- Drive a culture of security awareness throughout the organisation, designing and delivering training and awareness programmes that equip staff to identify and respond to threats.
n
n
Security Research & Threat Intelligence
n
n
- Rebuild and lead RedShield's security research capability, establishing a programme of proactive vulnerability research and CVE discovery that reinforces RedShield's reputation as an expert authority in application security.
n
- Develop and maintain a threat intelligence programme that monitors the evolving threat landscape, translating intelligence into actionable risk insights for the business and its customers.
n
- Oversee the development and publication of security research, threat advisories, and vulnerability disclosures in accordance with responsible disclosure standards.
n
- Ensure security research capabilities are aligned to RedShield's product and service strategy, contributing to the development of new and enhanced service offerings.
n
- Foster relationships with the broader security research community, academic institutions, and government bodies to ensure RedShield remains at the forefront of emerging threat knowledge.
n
n
Testing & Assurance
n
n
- Oversee the delivery of vulnerability assessment capabilities, including testing of controls, ensuring methodologies, standards, and reporting meet the highest professional benchmarks.
n
- Ensure rigorous quality assurance processes are applied to all testing and assurance outputs, maintaining RedShield's standard of excellence and customer trust.
n
- Lead the development and continuous improvement of testing methodologies, tools, and frameworks, including red team and purple team exercises where appropriate.
n
- Work with the Customer and Technology pillars to embed security assurance into the delivery lifecycle, ensuring testing insights contribute to customer security improvement programmes.
n
n
Technology Risk & Compliance
n
n
- Develop and maintain a comprehensive technology risk framework and risk register, ensuring all material risks are identified, assessed, and managed in line with RedShield's risk appetite.
n
- Lead RedShield's compliance programme, ensuring ongoing adherence to relevant regulatory requirements, industry standards, and contractual obligations across all jurisdictions in which RedShield operates (New Zealand, Australia, United States).
n
- Manage third-party and supply chain risk assessments, ensuring that vendors and partners meet RedShield's security and compliance requirements.
n
- Provide regular risk and compliance reporting to the CEO and Board, delivering clear,
concise insights that enable informed decision-making at the executive and governance level.
n
- Monitor the regulatory environment for changes that may impact RedShield's compliance obligations, proactively developing plans to address emerging requirements.
n
n
Government Assurance & Certification
n
n
- Own RedShield's continuous NZISM certification and accreditation programme for services delivered to New Zealand Government agencies, based on ongoing security risk management.
n
- Own IRAP (Infosec Registered Assessors Program) assessment planning, evidence preparation, remediation tracking and assessor engagement to maintain and renew RedShield's IRAP-assessed posture at the PROTECTED classification level.
n
- Ensure compliance with the Australian Government Information Security Manual (AU ISM) and alignment with the Protective Security Policy Framework (PSPF) for Australian Government agency services.
n
- Ensure timely notification of cyber security incidents to the Australian Signals Directorate (ASD) and Australian Cyber Security Centre (ACSC) in line with PSPF Policy 10 and applicable mandatory obligations.
n
n
Internal Audit
n
n
- Develop, manage, and execute RedShield's internal audit programme, providing independent assurance over the effectiveness of internal controls, risk management processes, and governance frameworks.
n
- Report audit findings clearly and objectively, working constructively with business owners to agree remediation actions and track delivery to resolution.
n
- Act as RedShield's primary liaison for external audit processes, regulatory examinations, and certifications, coordinating evidence gathering and response activities across the organisation.
n
- Ensure audit findings and control gaps are remediated in a timely and effective manner, escalating material issues to the CEO and Board as appropriate.
n
n
Team Leadership & Development
n
n
- Build, lead, and develop the Security pillar team — initially comprising the InfoSec Manager, we have identified key roles across security research, penetration / controls testing and security engineering we need to recruit with an expectation that the team will grow as RedShield scales.
n
- Recruit and onboard new Security team members with a focus on technical excellence, cultural fit, and alignment to RedShield's mission.
n
- Foster a high-performance, collaborative team culture that balances rigour and discipline with innovation and continuous learning.
n
- Ensure all Security team members have explicit goals, regular feedback, and meaningful development opportunities aligned to their career aspirations and RedShield's strategic needs.
n
- Ensure all work is tracked, prioritised, and delivered in an organised manner through appropriate sprint planning, work allocation, and project management practices.
n
- Collaborate closely with the Chief Technology Officer to ensure alignment between the Security pillar and the Technology pillar, particularly on matters of infrastructure security, cloud architecture, and security engineering.
n
n
Customer Trust & Commercial Enablement
n
n
- Act as RedShield's senior security authority in strategic customer engagements, executive briefings and Quarterly Business Reviews, articulating RedShield's security posture and value.
n
- Own customer-facing security assurance collateral — trust packs, certifications, and responses to customer security questionnaires and due-diligence requests.
n
- Support the Customer and Commercial pillars on security aspects of RFPs, contracts and pre-sales engagements, translating RedShield's internal security maturity into a demonstrable commercial differentiator.
n
- Use RedShield's own 'beyond reproach' security posture as a proof point that reinforces customer trust and supports revenue growth.
n
n
Qualifications & Experience
n
n
- 5+ years of experience in senior cyber security roles, including demonstrable experience leading security functions within technology businesses or managed security service providers.
n
- Proven experience in controls testing and assurance, vulnerability assessment, or offensive security, with the ability to lead and quality-assure technical testing programmes.
n
- Demonstrated experience designing and implementing an ISMS aligned to ISO 27001 and/or SOC 2, including policy development, control implementation, and certification management.
n
- Strong background in technology risk management, including risk framework development, risk register management, and risk reporting to executive and board-level stakeholders.
n
- Experience managing or overseeing internal audit programmes, with the ability to deliver independent assurance across complex operational and technology environments.
n
- Demonstrated leadership of technical security teams, including recruitment, performance management, and professional development of security professionals.
n
- Excellent communication and stakeholder management skills, with the ability to present complex security and risk topics clearly to non-technical executive and board audiences.
n
n
Key Competencies
n
n
- Strategic Security Leadership: Demonstrated ability to develop and execute a forward-looking security strategy that is aligned to business objectives, builds organisational resilience, and positions RedShield as a trusted security authority.
n
- Technical Depth: Deep technical expertise across cyber security domains including controls testing, vulnerability research, cloud security, identity and access management, and application security — with the credibility to lead highly skilled technical teams.
n
- Risk & Compliance Acumen: Comprehensive understanding of technology risk frameworks, compliance standards (ISO 27001, SOC 2, NZISM), and regulatory obligations, with the ability to translate risk insights into actionable management decisions.
n
- Team Building & Development: Proven experience building high-performing security teams from the ground up, with a track record of attracting talent, developing capability, and fostering a culture of excellence, learning, and accountability.
n
- Stakeholder Engagement & Communication: Exceptional ability to communicate complex security and risk matters clearly and persuasively to diverse audiences — from technical practitioners to CEO and Board — building confidence and enabling informed decision-making.
n
- Operational Discipline: Skilled in establishing and maintaining rigorous security operations, audit processes, and reporting cadences, ensuring the Security pillar delivers consistently high-quality outputs in a structured, accountable manner.
n
📌 Chief Information Security Officer (Victoria)
🏢 RedShield Security
📍 Victoria