Senior Cybersecurity Consultant
Are you a seasoned cybersecurity professional who thrives on turning complex security challenges into clear, actionable outcomes? We're looking for a Senior Cybersecurity Consultant to join our team and lead high-impact engagements for some of New Zealand's most important organisations.
This is a role for someone who can operate independently, earn trust quickly, and bring both strategic thinking and deep technical credibility to every client conversation. You'll work across a diverse portfolio of customers — shaping their cybersecurity posture, aligning security outcomes to business strategy, and leaving organisations genuinely more resilient.
What You Will Do
- Lead consulting engagements end-to-end, delivering high-quality outcomes on time and on budget
- Develop and present cybersecurity strategies and roadmaps tailored to each organisation's risk appetite and maturity
- Design and implement governance frameworks that are practical, sustainable and fit for purpose
- Conduct cybersecurity audits and assessments across a wide range of domains and industries
- Manage organisational and system-level risk, helping clients understand and prioritise what matters most
- Build and test security programmes, including system assurance, third-party/vendor assurance, incident management and security awareness
- Develop policies and compliance programmes that stick in the real world
- Engage confidently with senior leaders, technical specialists and everyone in between in workshops, writing and one-on-one
- Mentor and support the growth of colleagues through knowledge sharing and hands-on guidance
What You Will Bring
- Extensive cybersecurity experience that spans the full breadth of the discipline, from governance and risk through to technology and operations
- Demonstrated consulting experience, with a reputation for delivering independently, managing competing priorities and earning client trust from day one
- Deep, working knowledge of leading international frameworks including NIST CSFv2, NIST SP800-53, ISO 27001/27002/27005, IEC 62443, PCI-DSS, SOC2 Type I/II and ASD Essential 8
- Strong familiarity with New Zealand and Australian local guidance, including NZ PSR, NCSC Minimum Cyber Security Standards, HISO 10029/HISF, NZ ISM, AU ISM and the NZ Privacy Act 2020
- Hands-on PCI-DSS experience including scoping, SAQ selection and issuer/processor/acquirer relationship management
- The ability to clearly articulate how controls relate to threats, vulnerabilities and business risk
Skills
- A natural communicator. Equally comfortable in a boardroom, a technical deep-dive or a facilitated workshop
- Sharp analytical skills for information gathering, evidence collection and system analysis
- Proven ability to juggle multiple projects with strong self-management and professionalism
- Able to define solutions that are effective, feasible and sustainable — regardless of an organisation's size or maturity
- A genuine understanding of the intersection between cybersecurity and privacy
- Curious and current. Keep up with emerging threats and developments and know what they mean for NZ organisations
Qualifications
- Relevant tertiary or professional qualifications or relevant experience
- Desirable certifications: ISO 27001 Lead Implementor/Auditor, CISM, CRISC