
Cyber Security & Information Security Management
• Establish, own, and continuously improve RedShield's Information Security Management System (ISMS),
ensuring alignment with ISO 27001, SOC 2, and applicable regulatory frameworks.
• Develop, implement, and maintain security policies, standards, and procedures across the organisation,
ensuring they are embedded in day-to-day operations and understood by all staff.
• Lead RedShield's security incident response programme, including the development of incident response
plans, tabletop exercises, and post-incident reviews to drive continuous improvement.
• Oversee and manage RedShield's internal security posture — including vulnerability management, patch
management, and security hardening across systems, applications, and cloud infrastructure.
RedShield Security · Chief Information Security Officer · Page 1
Commercial in Confidence
• Drive a culture of security awareness throughout the organisation, designing and delivering training and
awareness programmes that equip staff to identify and respond to threats.
Security Research & Threat Intelligence
• Rebuild and lead RedShield's security research capability, establishing a programme of proactive vulnerability
research and CVE discovery that reinforces RedShield's reputation as an expert authority in application
security.
• Develop and maintain a threat intelligence programme that monitors the evolving threat landscape,
translating intelligence into actionable risk insights for the business and its customers.
• Oversee the development and publication of security research, threat advisories, and vulnerability disclosures
in accordance with responsible disclosure standards.
• Ensure security research capabilities are aligned to RedShield's product and service strategy, contributing to
the development of new and enhanced service offerings.
• Foster relationships with the broader security research community, academic institutions, and government
bodies to ensure RedShield remains at the forefront of emerging threat knowledge.
Testing & Assurance
• Oversee the delivery of vulnerability assessment capabilities, including testing of controls, ensuring
methodologies, standards, and reporting meet the highest professional benchmarks.
• Ensure rigorous quality assurance processes are applied to all testing and assurance outputs, maintaining
RedShield's standard of excellence and customer trust.
• Lead the development and continuous improvement of testing methodologies, tools, and frameworks,
including red team and purple team exercises where appropriate.
• Work with the Customer and Technology pillars to embed security assurance into the delivery lifecycle,
ensuring testing insights contribute to customer security improvement programmes.
Technology Risk & Compliance
• Develop and maintain a comprehensive technology risk framework and risk register, ensuring all material risks
are identified, assessed, and managed in line with RedShield's risk appetite.
• Lead RedShield's compliance programme, ensuring ongoing adherence to relevant regulatory requirements,
industry standards, and contractual obligations across all jurisdictions in which RedShield operates (New
Zealand, Australia, United States).
• Manage third-party and supply chain risk assessments, ensuring that vendors and partners meet RedShield's
security and compliance requirements.
• Provide regular risk and compliance reporting to the CEO and Board, delivering clear, concise insights that
enable informed decision-making at the executive and governance level.
• Monitor the regulatory environment for changes that may impact RedShield's compliance obligations,
proactively developing plans to address emerging requirements.
Government Assurance & Certification
• Own RedShield’s continuous NZISM certification and accreditation programme for services delivered to New
Zealand Government agencies, based on ongoing security risk management.
• Own IRAP (Infosec Registered Assessors Program) assessment planning, evidence preparation, remediation
tracking and assessor engagement to maintain and renew RedShield’s IRAP-assessed posture at the
PROTECTED classification level.
• Ensure compliance with the Australian Government Information Security Manual (AU ISM) and alignment with
the Protective Security Policy Framework (PSPF) for Australian Government agency services.
• Ensure timely notification of cyber security incidents to the Australian Signals Directorate (ASD) and Australian
Cyber Security Centre (ACSC) in line with PSPF Policy 10 and applicable mandatory obligations.RedShield Security · Chief Information Security Officer · Page 2
Commercial in Confidence
Internal Audit
• Develop, manage, and execute RedShield's internal audit programme, providing independent assurance over
the effectiveness of internal controls, risk management processes, and governance frameworks.
• Report audit findings clearly and objectively, working constructively with business owners to agree
remediation actions and track delivery to resolution.
• Act as RedShield's primary liaison for external audit processes, regulatory examinations, and certifications,
coordinating evidence gathering and response activities across the organisation.
• Ensure audit findings and control gaps are remediated in a timely and effective manner, escalating material
issues to the CEO and Board as appropriate.
Team Leadership & Development
• Build, lead, and develop the Security pillar team — initially comprising the InfoSec Manager, we have
identified key roles across security research, penetration / controls testing and security engineering we need
to recruit with an expectation that the team will grow as RedShield scales.
• Recruit and onboard new Security team members with a focus on technical excellence, cultural fit, and
alignment to RedShield's mission.
• Foster a high-performance, collaborative team culture that balances rigour and discipline with innovation and
continuous learning.
• Ensure all Security team members have clear goals, regular feedback, and meaningful development
opportunities aligned to their career aspirations and RedShield's strategic needs.
• Ensure all work is tracked, prioritised, and delivered in an organised manner through appropriate sprint
planning, work allocation, and project management practices.
• Collaborate closely with the Chief Technology Officer to ensure alignment between the Security pillar and the
Technology pillar, particularly on matters of infrastructure security, cloud architecture, and security
engineering.
Customer Trust & Commercial Enablement
• Act as RedShield’s senior security authority in strategic customer engagements, executive briefings and
Quarterly Business Reviews, articulating RedShield’s security posture and value.
• Own customer-facing security assurance collateral — trust packs, certifications, and responses to customer
security questionnaires and due-diligence requests.
• Support the Customer and Commercial pillars on security aspects of RFPs, contracts and pre-sales
engagements, translating RedShield’s internal security maturity into a demonstrable commercial
differentiator.
• Use RedShield’s own ‘beyond reproach’ security posture as a proof point that reinforces customer trust and
supports revenue growth.
Qualifications & Experience
• 5+ years of experience in senior cyber security roles, including demonstrable experience leading security
functions within technology businesses or managed security service providers.
• Proven experience in controls testing and assurance, vulnerability assessment, or offensive security, with the
ability to lead and quality-assure technical testing programmes.
• Demonstrated experience designing and implementing an ISMS aligned to ISO 27001 and/or SOC 2, including
policy development, control implementation, and certification management.
• Strong background in technology risk management, including risk framework development, risk register
management, and risk reporting to executive and board-level stakeholders.
• Experience managing or overseeing internal audit programmes, with the ability to deliver independent
assurance across complex operational and technology environments.
• Demonstrated leadership of technical security teams, including recruitment, performance management, and
professional development of security professionals.
• Excellent communication and stakeholder management skills, with the ability to present complex security and
risk topics clearly to non-technical executive and board audiences.
Key Competencies
• Strategic Security Leadership: Demonstrated ability to develop and execute a forward-looking security
strategy that is aligned to business objectives, builds organisational resilience, and positions RedShield as a
trusted security authority.
• Technical Depth: Deep technical expertise across cyber security domains including controls testing,
vulnerability research, cloud security, identity and access management, and application security — with the
credibility to lead highly skilled technical teams.
• Risk & Compliance Acumen: Comprehensive understanding of technology risk frameworks, compliance
standards (ISO 27001, SOC 2, NZISM), and regulatory obligations, with the ability to translate risk insights into
actionable management decisions.
• Team Building & Development: Proven experience building high-performing security teams from the ground
up, with a track record of attracting talent, developing capability, and fostering a culture of excellence,
learning, and accountability.
• Stakeholder Engagement & Communication: Exceptional ability to communicate complex security and risk
matters clearly and persuasively to diverse audiences — from technical practitioners to CEO and Board —
building confidence and enabling informed decision-making.
• Operational Discipline: Skilled in establishing and maintaining rigorous security operations, audit processes,
and reporting cadences, ensuring the Security pillar delivers consistently high-quality outputs in a structured,
accountable manner.