Chief Information Security Officer
redshield · Australia
About The Role
Cyber Security & Information Security Management
- Establish, own, and continuously improve RedShield's Information Security Management System (ISMS),
ensuring alignment with ISO 27001, SOC 2, and applicable regulatory frameworks.
- Develop, implement, and maintain security policies, standards, and procedures across the organisation,
ensuring they are embedded in day-to-day operations and understood by all staff.
- Lead RedShield's security incident response programme, including the development of incident response
plans, tabletop exercises, and post-incident reviews to drive continuous improvement.
- Oversee and manage RedShield's internal security posture — including vulnerability management, patch
- management, and security hardening across systems, applications, and cloud infrastructure.
- RedShield Security · Chief Information Security Officer · Page 1
Commercial in Confidence
- Drive a culture of security awareness throughout the organisation, designing and delivering training and
awareness programmes that equip staff to identify and respond to threats.
Security Research & Threat Intelligence
- Rebuild and lead RedShield's security research capability, establishing a programme of proactive vulnerability
- research and CVE discovery that reinforces RedShield's reputation as an expert authority in application
- security.
- Develop and maintain a threat intelligence programme that monitors the evolving threat landscape,
translating intelligence into actionable risk insights for the business and its customers.
- Oversee the development and publication of security research, threat advisories, and vulnerability disclosures
in accordance with responsible disclosure standards.
- Ensure security research capabilities are aligned to RedShield's product and service strategy, contributing to
the development of new and enhanced service offerings.
- Foster relationships with the broader security research community, academic institutions, and government
bodies to ensure RedShield remains at the forefront of emerging threat knowledge.
Testing & Assurance
- Oversee the delivery of vulnerability assessment capabilities, including testing of controls, ensuring
methodologies, standards, and reporting meet the highest professional benchmarks.
- Ensure rigorous quality assurance processes are applied to all testing and assurance outputs, maintaining
RedShield's standard of excellence and customer trust.
- Lead the development and continuous improvement of testing methodologies, tools, and frameworks,
including red team and purple team exercises where appropriate.
- Work with the Customer and Technology pillars to embed security assurance into the delivery lifecycle,
ensuring testing insights contribute to customer security improvement programmes.
Technology Risk & Compliance
- Develop and maintain a comprehensive technology risk framework and risk register, ensuring all material risks
are identified, assessed, and managed in line with RedShield's risk appetite.
- Lead RedShield's compliance programme, ensuring ongoing adherence to relevant regulatory requirements,
- industry standards, and contractual obligations across all jurisdictions in which RedShield operates (New
- Zealand, Australia, United States).
- Manage third-party and supply chain risk assessments, ensuring that vendors and partners meet RedShield's
security and compliance requirements.
- Provide regular risk and compliance reporting to the CEO and Board, delivering clear, concise insights that
enable informed decision-making at the executive and governance level.
- Monitor the regulatory environment for changes that may impact RedShield's compliance obligations,
proactively developing plans to address emerging requirements.
Government Assurance & Certification
- Own RedShield’s continuous NZISM certification and accreditation programme for services delivered to New
Zealand Government agencies, based on ongoing security risk management.
- Own IRAP (Infosec Registered Assessors Program) assessment planning, evidence preparation, remediation
- tracking and assessor engagement to maintain and renew RedShield’s IRAP-assessed posture at the
- PROTECTED classification level.
- Ensure compliance with the Australian Government Information Security Manual (AU ISM) and alignment with
the Protective Security Policy Framework (PSPF) for Australian Government agency services.
- Ensure timely notification of cyber security incidents to the Australian Signals Directorate (ASD) and Australian
Cyber Security Centre (ACSC) in line with PSPF Policy 10 and applicable mandatory obligations.RedShield Security · Chief Information Security Officer · Page 2
Commercial in Confidence
Internal Audit
- Develop, manage, and execute RedShield's internal audit programme, providing independent assurance over
the effectiveness of internal controls, risk management processes, and governance frameworks.
- Report audit findings clearly and objectively, working constructively with business owners to agree
remediation actions and track delivery to resolution.
- Act as RedShield's primary liaison for external audit processes, regulatory examinations, and certifications,
coordinating evidence gathering and response activities across the organisation.
- Ensure audit findings and control gaps are remediated in a timely and effective manner, escalating material
issues to the CEO and Board as appropriate.
Team Leadership & Development
- Build, lead, and develop the Security pillar team — initially comprising the InfoSec Manager, we have
- identified key roles across security research, penetration / controls testing and security engineering we need
- to recruit with an expectation that the team will grow as RedShield scales.
- Recruit and onboard new Security team members with a focus on technical excellence, cultural fit, and
alignment to RedShield's mission.
- Foster a high-performance, collaborative team culture that balances rigour and discipline with innovation and
continuous learning.
- Ensure all Security team members have clear goals, regular feedback, and meaningful development
opportunities aligned to their career aspirations and RedShield's strategic needs.
- Ensure all work is tracked, prioritised, and delivered in an organised manner through appropriate sprint
planning, work allocation, and project management practices.
- Collaborate closely with the Chief Technology Officer to ensure alignment between the Security pillar and the
- Technology pillar, particularly on matters of infrastructure security, cloud architecture, and security
- engineering.
Customer Trust & Commercial Enablement
- Act as RedShield’s senior security authority in strategic customer engagements, executive briefings and
Quarterly Business Reviews, articulating RedShield’s security posture and value.
- Own customer-facing security assurance collateral — trust packs, certifications, and responses to customer
security questionnaires and due-diligence requests.
- Support the Customer and Commercial pillars on security aspects of RFPs, contracts and pre-sales
- engagements, translating RedShield’s internal security maturity into a demonstrable commercial
- differentiator.
- Use RedShield’s own ‘beyond reproach’ security posture as a proof point that reinforces customer trust and
supports revenue growth.
Qualifications & Experience
- 5+ years of experience in senior cyber security roles, including demonstrable experience leading security
functions within technology businesses or managed security service providers.
- Proven experience in controls testing and assurance, vulnerability assessment, or offensive security, with the
ability to lead and quality-assure technical testing programmes.
- Demonstrated experience designing and implementing an ISMS aligned to ISO 27001 and/or SOC 2, including
policy development, control implementation, and certification management.
- Strong background in technology risk management, including risk framework development, risk register
management, and risk reporting to executive and board-level stakeholders.
- Experience managing or overseeing internal audit programmes, with the ability to deliver independent
assurance across complex operational and technology environments.
- Demonstrated leadership of technical security teams, including recruitment, performance management, and
professional development of security professionals.
- Excellent communication and stakeholder management skills, with the ability to present complex security and
risk topics clearly to non-technical executive and board audiences.
Key Competencies
- Strategic Security Leadership: Demonstrated ability to develop and execute a forward-looking security
- strategy that is aligned to business objectives, builds organisational resilience, and positions RedShield as a
- trusted security authority.
- Technical Depth: Deep technical expertise across cyber security domains including controls testing,
- vulnerability research, cloud security, identity and access management, and application security — with the
- credibility to lead highly skilled technical teams.
- Risk & Compliance Acumen: Comprehensive understanding of technology risk frameworks, compliance
- standards (ISO 27001, SOC 2, NZISM), and regulatory obligations, with the ability to translate risk insights into
- actionable management decisions.
- Team Building & Development: Proven experience building high-performing security teams from the ground
- up, with a track record of attracting talent, developing capability, and fostering a culture of excellence,
- learning, and accountability.
- Stakeholder Engagement & Communication: Exceptional ability to communicate complex security and risk
- matters clearly and persuasively to diverse audiences — from technical practitioners to CEO and Board —
- building confidence and enabling informed decision-making.
- Operational Discipline: Skilled in establishing and maintaining rigorous security operations, audit processes,
- and reporting cadences, ensuring the Security pillar delivers consistently high-quality outputs in a structured,
- accountable manner.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
