Lead end-to-end cybersecurity engagements for NZ/Australia clients delivering risk-based security programs.

Senior Cybersecurity Consultant

Are you a seasoned cybersecurity professional who thrives on turning complex security challenges into clear, actionable outcomes? We're looking for a Senior Cybersecurity Consultant to join our team and lead high-impact engagements for some of New Zealand's most important organisations.

This is a role for someone who can operate independently, earn trust quickly, and bring both strategic thinking and deep technical credibility to every client conversation. You'll work across a diverse portfolio of customers — shaping their cybersecurity posture, aligning security outcomes to business strategy, and leaving organisations genuinely more resilient.

What You Will Do

  • Lead consulting engagements end-to-end, delivering high-quality outcomes on time and on budget
  • Develop and present cybersecurity strategies and roadmaps tailored to each organisation's risk appetite and maturity
  • Design and implement governance frameworks that are practical, sustainable and fit for purpose
  • Conduct cybersecurity audits and assessments across a wide range of domains and industries
  • Manage organisational and system-level risk, helping clients understand and prioritise what matters most
  • Build and test security programmes, including system assurance, third-party/vendor assurance, incident management and security awareness
  • Develop policies and compliance programmes that stick in the real world
  • Engage confidently with senior leaders, technical specialists and everyone in between in workshops, writing and one-on-one
  • Mentor and support the growth of colleagues through knowledge sharing and hands-on guidance

What You Will Bring

  • Extensive cybersecurity experience that spans the full breadth of the discipline, from governance and risk through to technology and operations
  • Demonstrated consulting experience, with a reputation for delivering independently, managing competing priorities and earning client trust from day one
  • Deep, working knowledge of leading international frameworks including NIST CSFv2, NIST SP800-53, ISO 27001/27002/27005, IEC 62443, PCI-DSS, SOC2 Type I/II and ASD Essential 8
  • Strong familiarity with New Zealand and Australian local guidance, including NZ PSR, NCSC Minimum Cyber Security Standards, HISO 10029/HISF, NZ ISM, AU ISM and the NZ Privacy Act 2020
  • Hands-on PCI-DSS experience including scoping, SAQ selection and issuer/processor/acquirer relationship management
  • The ability to clearly articulate how controls relate to threats, vulnerabilities and business risk

Skills

  • A natural communicator. Equally comfortable in a boardroom, a technical deep-dive or a facilitated workshop
  • Sharp analytical skills for information gathering, evidence collection and system analysis
  • Proven ability to juggle multiple projects with strong self-management and professionalism
  • Able to define solutions that are effective, feasible and sustainable — regardless of an organisation's size or maturity
  • A genuine understanding of the intersection between cybersecurity and privacy
  • Curious and current. Keep up with emerging threats and developments and know what they mean for NZ organisations

Qualifications

  • Relevant tertiary or professional qualifications or relevant experience
  • Desirable certifications: ISO 27001 Lead Implementor/Auditor, CISM, CRISC