Head of Cyber Security and IT
Contract Type
Location
Industry
Specialisation
Salary
Contact Name
Contact Email
Date published
Job Reference
Description
Role Summary
This senior leadership position carries enterprise-wide accountability for the security, resilience, and governance of the organisation's technology environment. You will define and lead the enterprise IT roadmap and cybersecurity function, ensuring infrastructure, applications, and identity systems are secure, compliant, and capable of enabling global hyperscale cloud growth, with an initial focus on APAC.
Reporting to the CTO and working in close partnership with the Chief Security Officer and Risk & Compliance team, success in this role will be measured against key business outcomes, including uptime, reduction in incidents, MTTD/MTTR performance, and audit results. This role is critical to sustaining customer trust and operational stability as the organisation scales globally.
Key Responsibilities
Act as the organisation's strategic authority on emerging cyber risks, particularly those driven by advancements in AI. This includes AI-enabled threat vectors, deepfake-based social engineering, and adversarial techniques targeting infrastructure. You will continuously assess the evolving threat landscape, conduct red team exercises and simulation-based testing, and strengthen the organisation's overall cyber risk posture.
Lead the end-to-end delivery of corporate IT infrastructure, including networks, compute, storage, and cloud platforms (Azure and AWS), alongside the IT service desk and ITIL-aligned service management. You will define the future-state architecture, rationalise tooling, and drive clear buy/build/integrate decisions across regions.
Own the corporate applications landscape, working closely with business leaders to align technology solutions with operational needs. You will govern the SaaS ecosystem (e.g., M365, Atlassian, Slack, HRIS, CRM, finance platforms), with responsibility for licensing, data classification, and data loss prevention controls.
Execute the organisation-wide cybersecurity strategy, encompassing endpoint protection, identity and access management (MFA, SSO, RBAC/ABAC), threat detection, incident response, and vulnerability management. You will oversee enterprise identity platforms and lifecycle processes (Joiner-Mover-Leaver), manage SOC/MDR operations, and support security awareness initiatives and risk reporting.
Partner with Risk & Compliance to achieve and maintain key certifications and regulatory alignments, including ISO 27001, SOC 2, IRAP, DISP, and MAS TRM.
Support the organisation in shaping IT strategy, annual planning, and budgeting. You will build and lead a high-performing, multidisciplinary team across service delivery, infrastructure, and security functions, with accountability for talent development and succession planning. You will also manage strategic vendor relationships, ensuring performance against SLAs, KPIs, and budget targets.
What You Bring
You bring a proven track record of building and scaling IT and cybersecurity capabilities from early-stage environments through to large-scale or hyperscale operations. You have led enterprise IT and security functions within cloud, SaaS, or infrastructure-intensive organisations, ideally across multiple regions and regulated environments.
You take a forward-looking, intelligence-led approach to cybersecurity, anticipating future threats rather than reacting to current ones. You are equally comfortable engaging technical teams and communicating complex concepts to senior executives and Board-level stakeholders.
Key Requirements:
- 10+ years' experience across IT and cybersecurity, including at least 5 years in leadership roles with responsibility for teams and budgets
- Bachelor's degree in Computer Science, IT, Cybersecurity, or a related discipline; postgraduate qualifications or certifications (e.g., CISSP, CISM, ITIL) are highly regarded
- Strong expertise in cloud-first architectures, zero trust models, and supporting remote/hybrid workforces
- Deep knowledge of network architecture, enterprise identity (IdP, SSO, RBAC), and industry security best practices
- Familiarity with AI/ML environments or high-performance computing is advantageous
- Experience in threat intelligence, red teaming, or proactive security operations is highly valued
- Australian Government Negative Vetting Level 1 (NV1) clearance (or ability to obtain)