About the Role
The Cyber Security Lead – Advisor plays a critical role in strengthening the organisation’s cyber security posture across its technology landscape. This role leads the development, implementation, and ongoing assurance of security policies, standards, and practices while guiding stakeholders on emerging threats, risk mitigation, and secure-by-design principles. The position partners closely with business, technology, and operational teams to uplift security capability, support security culture, and ensure compliance with relevant standards and industry regulations.
Primary Purpose
The purpose of this role is to provide expert leadership across cyber security governance, risk, and assurance activities. The Cyber Security Lead drives risk‑based decision-making, oversees security assessments, manages incident response activities, and ensures that security controls, frameworks, and practices are embedded effectively across the organisation. This role also supports continuity planning, third‑party assurance, and enterprise-wide improvement in cyber maturity.
Key Responsibilities
- Provide strategic cyber security advice on new products, services, technology solutions, and business processes to ensure secure and successful outcomes.
- Lead and contribute to security risk assessments, project reviews, and initiatives aligned to the organisation’s cyber security strategy.
- Coordinate and manage third‑party risk assessments, including ongoing validation of vendor security posture and remediation of identified issues.
- Lead investigations into security incidents and ensure timely response, escalation, and resolution based on risk severity.
- Maintain and enhance security policies, standards, and governance mechanisms to ensure continuous protection and compliance.
- Oversee and support the organisation’s Managed Security Services Provider to ensure effective monitoring, detection, and response capabilities.
- Collaborate with business and technology stakeholders to uplift security capability, drive awareness, and embed secure-by-design practices.
- Provide expert guidance on cyber assurance, risk mitigation, and improvements to security controls and processes.
Essential Knowledge, Skills & Experience
- Tertiary qualification in Information Security, Information Technology, or a related discipline.
- Strong understanding of cyber security frameworks such as ASD Essential Eight, ISO 27001/27002/27005, NIST, and ISM.
- Deep expertise in security control design, implementation, and continuous monitoring.
- Demonstrated experience securing Microsoft Azure and Entra ID environments.
- Significant experience leading cyber security governance, risk, and compliance activities.
- Proven capability conducting security assessments and reviews across applications, systems, and infrastructure.
- Ability to provide expert guidance on cyber assurance, risk mitigation, policy development, and security uplift initiatives.
- Knowledge of Operational Technology (OT) security is highly desirable.
- Relevant industry certifications (e.g., CISSP, CISM, CISA) are considered highly advantageous.
If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.
If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion on your career.
LHS 297508