Senior Security Consultant ICT Security Specialist
Wellington, Wellington Region, New Zealand · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 weeks ago
- Work mode
- In office
- Education
- Information Technology, Computer Science, Cybersecurity, or related field
- Eligibility
- New Zealand citizens, New Zealand residents, or candidates holding a valid NZ work visa may apply.
- Resume
- Required to apply
Where you'll work
Job description
About the company
Security Solution Consultants is a New Zealand-registered business focused on enterprise-level cyber security advisory and managed security services. The team helps organisations put practical, risk-led protections in place, strengthen governance, manage cyber exposure, and stay aligned with compliance obligations such as ISO/IEC 27001, NIST CSF, and the New Zealand Government Protective Security Requirements (PSR). Its client base includes central and local government, financial services, critical infrastructure, and commercial organisations that want to improve their security maturity.
The position suits someone who is self-driven, comfortable owning their workload, and interested in helping grow client relationships and service capability. Consultants work with client teams, suppliers, and other specialists to deliver pragmatic security outcomes.
Role overview
We are looking for a senior cybersecurity professional to step into the Senior Security Consultant position. The role centres on leading Cyber Governance, Risk Management and Compliance (GRC) work and acting as a trusted adviser to clients across multiple sectors.
This is a hands-on, client-facing consulting role that combines technical understanding, governance expertise, and strong communication. You will work with senior stakeholders, oversee complex assignments, and help shape the continued development of the firm’s services and internal capability.
Key responsibilities
Cyber governance
- Create, refine, and put into practice enterprise security governance frameworks and policies that align with ISO/IEC 27001, NIST CSF, and relevant New Zealand public sector standards.
- Build and support Information Security Management Systems (ISMS), including defining scope, developing policies, and setting governance structures.
- Prepare security programme roadmaps and deliver reporting for boards and executives on security posture.
- Advise clients on establishing durable governance that fits their business strategy and regulatory environment.
- Support clients through ISO 27001 and other certification or accreditation processes.
Risk management
- Lead cyber risk assessments and threat modelling across on-premises, cloud, and hybrid environments.
- Develop and implement risk frameworks, risk registers, and treatment plans.
- Carry out security architecture reviews and identify weaknesses in systems, networks, applications, and business processes.
- Draft risk findings and recommendations for both technical teams and executive audiences.
- Assess third parties and supply chain security risk.
Compliance and assurance
- Perform compliance gap assessments against standards and frameworks such as ISO 27001, NIST CSF, SOC 2, PCI DSS, NZ PSR, Essential Eight, and similar requirements where relevant.
- Design and run control assurance programmes and security audit activities.
- Assist with internal and external audits, including tracking findings and remediation actions.
- Keep up to date with New Zealand and international regulatory and compliance obligations affecting client industries.
Client engagement and delivery
- Serve as the main security adviser for senior client stakeholders on assigned engagements.
- Manage consulting work from initial scoping and planning through delivery, review, and close-out.
- Produce polished written outputs such as reports, frameworks, gap analyses, and strategic advice documents.
- Spot opportunities to deepen client relationships and support business development efforts.
- Mentor junior team members and contribute to knowledge sharing and capability building within the business.
Requirements
- At least 5 years of steady experience in information security or cybersecurity, including a minimum of 3 years in consulting, advisory, or specialist practitioner roles.
- Proven delivery of GRC engagements, including governance frameworks, risk assessments, and compliance programmes.
- Strong practical knowledge of ISO/IEC 27001, the NIST Cybersecurity Framework, and similar standards.
- Experience working with regulated organisations such as government, financial services, healthcare, or critical infrastructure.
- A tertiary qualification in IT, Computer Science, Cybersecurity, or a related discipline, or equivalent professional experience.
- One current certification from CISSP, CISM, CRISC, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or an equivalent credential.
- Excellent written and verbal communication skills, including confidence presenting to executive and board-level audiences.
- Must be a New Zealand citizen, resident, or hold a valid NZ work visa.
- Helpful background in New Zealand security frameworks such as PSR, NZISM, or NCSC guidance.
- Exposure to cloud security frameworks such as CSA CCM or AWS/Azure/GCP Well-Architected Security guidance.
- Additional certifications like CCSP, CEH, CompTIA Security+, or similar are an advantage.
- Practical experience with security tools such as SIEM platforms, vulnerability management systems, or GRC software is desirable.
- Existing New Zealand government security clearance, or willingness to complete security vetting.
- Methodical, risk-based thinking with strong analytical and problem-solving ability.
- Ability to manage several priorities in a fast-moving, client-facing setting with strong accountability.
- Comfortable working both collaboratively and independently with limited supervision.
- Professional, credible communication style that builds trust at all levels.
- Commitment to continuous professional development and staying current with cyber threats and regulatory change.
Additional information
Applicants should be prepared for a senior consulting role that combines delivery responsibility with relationship management and internal contribution. The role requires someone who can balance technical depth, advisory judgement, and ongoing professional learning.
Note: The source did not state salary, number of vacancies, start date, or application deadline.