Senior Manager Information Security
Hays · Sydney, New South Wales, Australia
Apply & track with Apply EdgeShape enterprise security strategy and roadmaps.Lead a team within critical energy environmentReport to the board and executives 2IC role leading a team within the energy industry, reporting to the CISOThis role offers the opportunity to shape cyber strategy, influence executive decision-making, and lead the continued evolution of a mature security capability. While the position carries leadership responsibility, it remains a hands-on role requiring a leader who enjoys actively contributing to governance, assurance, advisory and architecture outcomes rather than solely directing from a distance.Leading a team of up to five security professionals, you will oversee three critical security pillars:Cyber Governance & AssuranceCyber Security ConsultingEnterprise Security ArchitectureThe successful candidate will play a pivotal role in safeguarding critical business operations, embedding security into enterprise decision-making, and ensuring compliance with a range of regulatory and industry obligations.About the RoleAs a senior member of the cyber security leadership team, you will provide strategic direction while maintaining end-to-end ownership of key security initiatives across the organisation.You will act as a trusted advisor to executive stakeholders, technology leaders and business units, helping shape security strategy while ensuring practical and commercially aligned outcomes are achieved.Key responsibilities include:Leading enterprise-wide cyber governance, assurance and compliance programs.Managing compliance against recognised security frameworks and regulatory obligations.Leading internal and external audits, assurance reviews and control effectiveness assessments.Providing specialist cyber security consulting and advisory services across technology and business initiatives.Driving secure-by-design principles across enterprise architecture, transformation and technology delivery programs.Overseeing security risk management activities and providing pragmatic guidance on risk treatment strategies.Developing and maintaining cyber security policies, standards and governance frameworks.Leading supplier and third-party assurance activities.Delivering cyber security reporting, metrics and insights to senior executives and governance committees.Championing security awareness, training and organisational culture initiatives.Monitoring emerging threats, regulatory changes and industry developments to ensure security strategies remain effective and future-focused.About YouYou are an experienced cyber security leader who can comfortably operate in both strategic and operational environments.You have built credibility through your ability to translate complex security requirements into practical business outcomes and have a proven history of influencing stakeholders at all levels of an organisation.Most importantly, you enjoy leading people while remaining close to the work itself. You are equally comfortable presenting to executives, guiding architects and engineers, conducting assurance activities, or helping shape security solutions for key business initiatives.Technical & Regulatory ExperienceExposure to the following frameworks, standards and regulatory environments would be advantageous:SOCI ActAESCSFISO 27001NIST Cyber Security FrameworkCPS 234APRA Prudential StandardsEnterprise Risk Management FrameworksSecure-by-Design PrinciplesSecurity Architecture FrameworksRelevant certifications such as CISSP, CISM, CISA, CRISC, TOGAF, SABSA, ISO 27001 Lead Auditor or Lead Implementer will be highly regarded. Why Apply?This is a rare opportunity to lead multiple cyber security disciplines within an organisation that views information security as a strategic business enabler.