- Experience
- 11+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 21 hours ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Position Overview
We are seeking a Manager for Cyber Defence Strategy and Operations to join our Information Systems team based in Brisbane, Queensland, Australia. This role involves leading GHD's enterprise cybersecurity strategy and ensuring operational resilience daily. The position interacts closely with the Chief Technology Officer, IS Leadership Team, and Board Risk Committee to communicate the company's cyber risk posture.
Key Responsibilities
- Lead development and ownership of a multi-year cybersecurity strategy and target-state security architecture for the enterprise.
- Represent the organization's cyber risk posture to executive leadership and the Board Risk Committee.
- Establish and manage specialist teams covering security architecture, vulnerability management, and cyber governance, risk, and compliance to support and enhance the Security Operations Centre's effectiveness and follow-the-sun coverage.
- Oversee the enterprise vulnerability management program, ensuring consistent remediation with clearly assigned responsibilities.
- Command major incident responses by coordinating efforts across IT, Legal, HR, and Communications departments.
- Define and govern the Zero Trust framework across GHD's Azure environment, identity management, and endpoint infrastructure.
- Manage GHD's AI security posture, including agentic systems, non-human identities, and shadow AI risks.
- Govern compliance readiness for CMMC Level 2 and FedRAMP certifications as facilitating factors for US Federal client engagements.
Candidate Qualifications and Experience
- Minimum of 12 years in cybersecurity roles, including experience building and leading dedicated specialist sub-functions within large or global organizations.
- Comprehensive expertise spanning security strategy, operations, threat intelligence, vulnerability management, and architecture across cloud platforms (Azure), endpoints, networks, identity, application, and data security.
- Proficient in Zero Trust models and Microsoft security technologies such as Defender, Sentinel, Entra ID, and Purview.
- Practical experience with regulatory and certification frameworks including CMMC Level 2, FedRAMP, ASD Essential Eight, ISO 27001, and NIST Cybersecurity Framework.
- Proven success guiding organizations through regulatory certification processes and capable of presenting cyber risks at executive and board levels.
- Solid incident command skills coupled with the capacity to establish security standards collaboratively and diplomatically.
- Required certifications include CISSP, CISM or their equivalents. Certifications like CMMC Registered Practitioner/Professional and Microsoft SC-100 or AZ-500 are highly desirable.
Why Join Us
- Leadership role with direct reporting to the CTO and visibility at the Board Risk Committee level.
- Opportunity to shape the cybersecurity strategy, architecture, and build specialist teams focusing on innovation rather than maintenance.
- Utilize security as a strategic growth enabler with certifications facilitating new US federal client opportunities.
- Lead the definition and governance of AI security posture during a critical phase of emerging threats.
- Engage globally as part of GHD's Enterprise Strategy 2035 with a strong technology focus.
About GHD
GHD is a global professional services firm specializing in engineering, architecture, environment, and advisory services. With over 11,000 skilled professionals across more than 200 offices worldwide, we are committed to sustainability and addressing some of the planet's most urgent challenges.
Equal Opportunity and Work Environment
GHD is an equal opportunity employer promoting a diverse and inclusive workplace. The company supports flexible hybrid work arrangements, focusing on employee well-being, productivity, and collaboration.