- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- Hybrid
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Serko
Serko is a pioneering technology platform specializing in global business travel and expense solutions. Joining Serko means becoming part of a passionate team of travelers and technologists committed to revolutionizing the business travel marketplace worldwide. The company has offices in New Zealand, Australia, North America, China, and is expanding in Bengaluru, India, embracing diversity and fostering authentic contributions to make a positive impact.
Role Overview
This Auckland-based hybrid position reports to the Chief Information Security Officer (CISO) and plays a vital role during an ongoing transformation aimed at accelerating the delivery of Serko's business strategy. The successful candidate will collaborate closely with multiple cross-functional teams composed of industry-leading security professionals.
Key Responsibilities
- Act as a trusted security advisor building strong relationships across the organization.
- Perform business-focused security risk assessments.
- Empower teams by sharing security knowledge to help them operate within acceptable risk parameters.
- Work alongside the CISO and security team to define and implement the Security Strategy.
- Maintain up-to-date awareness of the evolving security threat landscape and appropriate countermeasures relevant to Serko.
- Proactively identify opportunities to enhance security measures that support business objectives.
- Lead and contribute to DevSecOps initiatives, security operations management, incident response, threat intelligence, and security awareness training.
- Manage security risk and explore emerging technologies and innovations.
- Collaborate and lead within the security team effectively.
Candidate Profile
- Extensive experience in DevSecOps and managing security risk.
- Comprehensive understanding of security attack and defense methodologies.
- Excellent verbal and written communication skills, conveying complex security concepts clearly.
- Proven capability to perform high-quality security risk management in dynamic environments.
- Hands-on expertise managing Microsoft security technologies such as Azure Security Center, Azure Active Directory, and Sentinel.
- Strong background in integrating security practices throughout the software development lifecycle.
- In-depth knowledge of risk management frameworks, standards like NIST and ISO 27001, plus regulations including GDPR and HIPAA.
- Experience with incident response, threat intelligence gathering, and conducting security assessments.
- Familiarity with security automation, orchestration tools, vulnerability scanning, and secure coding practices.
- Outstanding problem-solving and analytical abilities to tackle complex security challenges.
- Team player with the ability to collaborate across departments and communicate effectively with non-technical stakeholders.
- Relevant certifications such as CISSP, CISM, CCSP, or Azure Security Engineer Associate are strongly preferred.
- Confidence to challenge or push back in a safe, inclusive environment when security risks emerge.
- Knowledge of cloud infrastructure security, particularly within Azure environments.
- Experience with security compliance (e.g., PCI-DSS) is advantageous but not mandatory.
Benefits
- Competitive base salary package.
- Medical benefits.
- Discretionary incentive plan tied to individual and company performance.
- Access to continuous learning and development resources, supporting career ownership and advancement.
- Flexible working policy enabling a balanced work environment.