Information Security Manager (Cyber)

A leading Australian financial services organisation is seeking a hands-on Information Security Manager to uplift cyber maturity and build a strong, practical security function across cloud and core platforms. This is a high-velocity environment where success comes from clear prioritisation, rapid execution and continuous improvement.

With the hiring manager due to commence paternity leave in the coming months, this is a high-priority hire—they need someone who can step in quickly, own work end-to-end, and drive outcomes in a lean team.

What you’ll be doing

  • Drive cyber maturity uplift across Essential Eight, NIST CSF and maintain ISO27001:2022 alignment

  • Build and run a pragmatic security program across identity, network, data and application security

  • Shift from traditional vulnerability management to exposure management

  • Lead design, implementation and continuous improvement of cloud security controls across AWS, Azure, Snowflake, Appian and OutSystems

  • Drive adoption of Security as Code, DevSecOps and data security practices across delivery teams

  • Own and mature cloud security tooling: CSPM, CWPP, DSPM and container security

  • Oversee key security controls/tooling, including:

    • Microsoft security stack (Entra ID, Sentinel, Defender), Azure Policy

    • Cloudflare (WAF/edge protection, rules, logging/integration)

    • Proofpoint, Traceable

    • Palo Alto Networks

    • Qualys

  • Oversee MSSP/SOC outcomes through metrics, incident reporting, continuous improvement and service governance

What you’ll bring (must-haves)

  • Strong background in Cyber Security Engineering + Security Operations

  • Proven experience uplifting security maturity and controls (Essential Eight / NIST CSF / ISO27001)

  • Experience leading cloud security controls/tooling and embedding security into engineering delivery

  • Comfortable in a fast-paced, evolving environment—prioritise, execute, iterate

  • Strong stakeholder engagement: able to simplify risk and drive practical decisions

  • Calm, decisive incident leadership with clear communication

Nice to have

  • Experience driving adoption of security policies/standards and refining them as environments evolve

  • Familiarity with Snowflake/Appian/OutSystems security patterns

  • Experience with Cloudflare WAF tuning, bot/DDoS controls, and SIEM integration

What’s on offer

  • Permanent role with a leading financial services organisation

  • $160–$170k base + super

  • North Sydney location, hybrid (3 days onsite)

  • High-impact role with autonomy and visibility

Apply

If you’re an outcomes-led Security Manager who can run initiatives end-to-end in a lean team, we’d love to hear from you. Apply now or reach out for a confidential discussion.

Amanda  Evans's Our  Infrastructure Permanent

Infrastructure Permanent

Amanda Evans

Infrastructure – Permanent

[email protected]
02 8346 6716