About the Company The Northern Australia Infrastructure Facility is a development financier established by the Federal Government to provide financial support to advance the development of infrastructure projects in northern Australia. NAIF provides finance to encourage and complement private and public sector investment in economic infrastructure.
NAIF is passionate about making a difference to the local economy by funding the construction of facilities or facility upgrades that will boost employment in the region. NAIF has been allocated $7 billion and is well established with commitments totalling over $4.6 billion across 33 investments in Central and North Queensland, Northern Territory, and northern Western Australia.
While NAIF’s funding facility comes from the Federal Government, funding for projects in particular states must be channelled through each of those States, meaning that the Queensland, Western Australia and Northern Territory Governments are key stakeholders.
About the Role
This is an exciting opportunity to join NAIF as an Associate Director, Cyber & Cloud Security, leading the organisation’s cyber security and cloud security capability while supporting the delivery of secure, resilient, and compliant technology environments. Reporting to the Director of IT, this role plays a key leadership role in shaping and implementing cyber security strategies, strengthening security frameworks, managing cyber risk, and ensuring the protection of NAIF’s information assets and cloud-based platforms.
Working closely with stakeholders across the organisation, the Associate Director, Cyber & Cloud Security will provide expert advice on security governance, risk management, compliance obligations, and emerging cyber threats. The role is responsible for driving continuous improvement across security operations, policies, and controls, while fostering a strong security culture that supports NAIF’s strategic objectives.
Location
NAIF has a strong preference to recruit employees based in Northern Australia,
reflecting our purpose and the communities we serve. This role is ideally located in Cairns; however, we will consider applicants from other locations where this supports securing the best candidate.
Responsibilities
- Lead NAIF’s cyber security governance framework, including cyber risk management, security policies, compliance, and assurance activities.
- Drive cloud, infrastructure, and secure-by-design security practices across technology initiatives and projects.
- Provide strategic advice on cyber risk, security architecture, cloud services, and identity and access management.
- Oversee security controls across Azure, Microsoft 365, Entra ID, endpoints, networks, and core infrastructure.
- Deliver cyber security reporting, insights, and recommendations to Executive Management, BARC, and the Board.
- Manage and oversee the performance of managed cyber security service providers and security partners.
- Lead cyber incident governance, response oversight, and continuous improvement activities to strengthen organisational resilience.
- Monitor vulnerabilities, remediation programs, and emerging cyber threats to maintain a strong security posture.
About You
We are looking for someone who is collaborative, proactive, and thrives in a dynamic environment.
You will bring
- Relevant qualifications in Cyber Security, Information Technology, Risk Management, or related discipline, complemented by significant professional experience in cyber security leadership and governance.
- Demonstrated experience providing trusted advice, reporting, and recommendations to Executive Leadership, Risk Committees,
and Boards on cyber security, risk, and technology matters.
- Strong expertise in cyber security governance, risk management, assurance, audit activities, and security frameworks, including PSPF, ISM, Essential Eight, ISO 27001, and NIST.
- Proven capability in cloud and security architecture assurance, including secure-by-design reviews, security assessments, technology governance, and hands-on experience with Microsoft 365, Azure, Entra ID, and cloud security controls.
- Ability to exercise independent skilled judgement, make informed decisions, and provide pragmatic recommendations on matters with financial, operational, contractual, and risk implications.
- Exceptional stakeholder engagement skills, with experience overseeing managed service providers, vendors, and external advisers, supported by relevant industry certifications such as CISSP, CISM, CRISC, CCSP, or equivalent
- Relevant tertiary qualifications in Cyber Security, Information Technology, Risk Management, or a related discipline are desirable, together with relevant industry certifications such as CISSP, CISM, CRISC, CCSP, or equivalent.
Why Join NAIF?
At NAIF, we are driven by our purpose and values. We foster a collaborative and supportive work environment, valuing the growth and development of our team members. We offer opportunities for professional development and prioritize the wellbeing of our staff. The successful applicant will be welcomed into a high performing team that is supportive, dedicated, knowledgeable, and passionate about our purpose of investing in the economic and social growth of northern Australia.
How to Apply To apply for this position, please submit your resume and a cover letter outlining your relevant experience and how you align with NAIF's purpose and values. Applications should be submitted by 5:00pm, Friday 25 September 2026. Shortlisting may commence at any time. For further information, please email
[email protected].
📌 Associate Director, Cyber & Cloud Security (Cairns)
🏢 Northern Australia Infrastructure Facility (NAIF)
📍 Cairns