Security Engineering
Secure design, implementation, and operation of technology platforms across cloud and on-premise environments.
Security Principles & Governance
Driving the adoption of security standards, best practices, and secure-by-design methodologies across the organisation.
Data Security
Protecting business-critical and sensitive information throughout its lifecycle.
Application Security
Ensuring applications are designed, developed, tested, and deployed securely.
Risk Mitigation
Identifying, assessing, and reducing security risks through effective engineering controls and security improvements.
Key Responsibilities
Cyber Security Leadership
Stay current with emerging cyber threats, vulnerabilities, attack techniques, and industry best practices.
Translate security trends and intelligence into actionable improvements and recommendations.
Promote and foster a culture of cyber security awareness, accountability, and responsibility across technology teams.
Advocate cloud-native security capabilities and modern security engineering approaches that deliver maximum value to the business.
Act as a security subject matter expert and trusted advisor to regional and global technology stakeholders.
Security Engineering
Ensure cloud platforms and on-premise systems align with secure design principles and industry best practices.
Design, implement, and maintain security controls across infrastructure, platforms, and services.
Ensure secure configuration of cloud resources and enterprise infrastructure.
Develop scalable security solutions aligned to business and technical requirements.
Lead the adoption and continuous improvement of security standards, policies, and technical controls.
Support security reviews and assessments for new and existing technology solutions.
Data Security
Identify and classify information based on business value, sensitivity, and regulatory requirements.
Implement and maintain data security controls throughout the entire data lifecycle.
Ensure data is appropriately protected during creation, storage, transmission, use, sharing, and disposal.
Implement solutions such as:
Encryption at rest and in transit
Data Loss Prevention (DLP)
Access controls
Data masking
Information protection technologies
Monitor developments in data security technology and integrate appropriate improvements into the organisation's strategy.
Application Security
Implement application security controls and secure development practices.
Support vulnerability assessments and penetration testing activities.
Promote secure coding principles and best practices.
Work with development and technology teams to identify and address security weaknesses early in the development lifecycle.
Support continuous improvement of application security maturity across the organisation.
Risk Management & Security Improvement
Translate business and project requirements into secure, scalable solutions.
Identify vulnerabilities, weaknesses, and security risks across technology environments.
Implement security improvements that reduce organisational risk and strengthen resilience.
Balance security requirements with usability, scalability, cost, and resource considerations.
Contribute to security roadmaps and ongoing cyber security improvement initiatives.
Collaboration & Enablement
Collaborate with business and technology teams to understand objectives and design secure solutions that support business outcomes.
Provide security engineering expertise during cloud and technology transformation initiatives.
Work closely with teams integrating new applications and services into existing environments.
Support cloud migration activities where required.
Deliver security guidance, coaching, and training to colleagues and third-party partners.
Build strong working relationships across multiple functions, regions, and cultures.
Compliance & Assurance
Support compliance with recognised security frameworks and industry standards.
Contribute to cloud security governance and compliance reporting activities.
Ensure security controls and engineering practices align with organisational and regulatory requirements.
Support audit and assurance activities where appropriate.
Essential Skills & Experience
Collaboration & Communication
Experience working successfully within multinational and multicultural environments.
Strong stakeholder management and relationship-building skills.
Ability to communicate complex technical information to technical and non-technical audiences.
Ability to influence decision-making and drive adoption of secure practices.
Security Engineering & Architecture
In-depth experience in cloud security architecture and secure design patterns.
Practical cloud engineering experience.
Experience designing and implementing secure technology solutions.
Experience with hybrid cloud and on-premise environments.
Strong understanding of security engineering principles and practices.
Data Security
Deep understanding of:
Encryption technologies
Data Loss Prevention (DLP)
Access control models
Information protection
Data lifecycle security
Application Security
Strong knowledge of application security principles and methodologies.
Understanding of secure coding practices and the OWASP Top 10.
Experience supporting vulnerability management and application security activities.
Network & Infrastructure Security
In-depth understanding of:
WAN technologies
LAN technologies
Cloud networking
Infrastructure security principles
Security Frameworks & Governance
Practical experience working with recognised frameworks and standards including:
ISO 27001
SOX
TISAX
NIST
CIS Controls
NIS2
Understanding of security governance, risk management, and compliance.
Problem Solving
Strong analytical skills with the ability to assess complex security challenges.
Ability to develop practical, risk-based solutions.
Experience balancing business requirements with security needs.
Desirable Skills & Experience
Industry Experience
Manufacturing sector experience.
Understanding of industrial technology environments and associated security challenges.
Knowledge of Operational Technology (OT) environments and security best practices.
Advanced Security Capabilities
Security automation experience.
Threat intelligence exposure.
Incident response experience.
Advanced cloud-native security capabilities.
Professional Certifications
Relevant industry certifications are desirable, including:
CISSP
CCSP
CISM
GIAC
AZ-500
CEH
Equivalent security certifications