Chief Information Security Officer Jobs in the IT Industry

Find your next role as a Chief Information Security Officer in New Zealand

Chief Information Security Officers lead the vision, strategy, and enterprise programme that keep a business’s digital assets, systems, and technologies protected and secure. They’re accountable for strategic plans and roadmaps, disaster recovery and business continuity, security policies and controls, and cyber incident response and investigation. At Younity, we specialise in connecting CISOs with New Zealand’s leading tech companies, helping you find a role that matches your skills and career goals.

 

Why choose Younity as your recruitment partner for Chief Information Security Officer roles?

Hiring (or becoming) a CISO is one of the most consequential decisions an organisation can make. It’s a role where trust, judgement, and the ability to influence matter just as much as technical capability, and that’s where a human-first approach makes the difference.

When you partner with Younity, you get New Zealand market knowledge, understanding how security leadership operates locally, including the realities of working across regulated industries, critical infrastructure, and complex stakeholder environments in NZ. You also get access to public and private sector opportunities, since CISOs operate across both sectors here, and we support security professionals into roles that match their background, values, and career direction.

We provide support for both IT jobseekers and IT employers, taking time to understand the people behind the brief, your leadership style, risk mindset, communication approach, and what success looks like in the first 6 to 12 months.

If you’re exploring IT jobs in senior cyber security, the simplest next step is to register your CV and tell us what kind of organisation, mandate, and challenge you want next.

 

What does a Chief Information Security Officer do in IT?

A Chief Information Security Officer (CISO) is the leader within a business responsible for establishing and maintaining the vision, strategy, and enterprise programme to ensure digital assets, systems and technologies are adequately protected and secure. They are accountable for strategic plans and road maps, disaster recovery and business continuity plans, security policies, protocols & controls, cyber incident responses and investigations of incidents and events.

In practice, CISOs in New Zealand typically lead across developing and leading information security programmes to protect an organisation’s assets, applications, systems, and technology, and risk management and compliance, including educating and managing technology risk in collaboration with business leaders. They build and drive cyber security strategy and frameworks, and handle governance and reporting, including implementing and managing cyber governance, risk, and compliance (GRC) processes and reporting to the board of directors and CEO.

CISOs also develop, justify, and evaluate cyber security investments, monitor emerging threats, industry best practices, and technology trends, and implement user security awareness training to foster a security-minded culture. They lead security operations, including oversight of key controls and response capability, own disaster recovery and business continuity planning, cyber incident response and investigation, and security policies, protocols & controls, and collaborate across the executive team, working with leaders such as CIO, CTO, CSO, CRO, and CEO to improve the organisation’s security posture.

If you’re aiming for CISO jobs NZ, your ability to balance security outcomes with business priorities is often what sets you apart, especially when you can demonstrate how you’ve influenced decision-making at senior levels.

 

What’s it like to work in this discipline?

CISO roles are rewarding, and demanding. You’re operating in a fast-evolving threat environment while also navigating budgets, organisational change, and the expectations of boards and regulators.

Many CISOs describe the discipline as high trust and high accountability, since you’re the voice of security risk when the stakes are highest, and strategic and people-focused, since success relies on leading teams, influencing executives, and building a culture, not just implementing tools.

It’s also always evolving, as the NZ cyber security landscape is changing quickly and demand for senior security leadership continues to grow across industries, and it offers cross-sector opportunity, since CISOs operate in both public and private sector roles in NZ, and the government landscape includes the Government Chief Information Security Officer (GCISO) function managed through GCSB.

Whether you’re based in Auckland, Wellington, or Christchurch, we can help you understand how different organisations approach security maturity, what “good” looks like in their environment, and how to position yourself for the right leadership mandate.

 

What qualifications or experience does this role benefit from?

CISOs often come from a blend of deep technical foundations and progressively broader leadership experience. A bachelor’s degree in Computer Science, Information Technology, Information Systems, or a related field is a common starting point, followed by significant hands-on experience in areas like security operations, risk management, or IT governance.

For many professionals, progression into a CISO role is supported by proven experience in senior security roles (for example, Security Manager, Head of Security, Security Architect), strong governance and risk capability, including GRC oversight and executive reporting, incident response leadership, plus ownership of disaster recovery and business continuity practices, and recognised certifications and/or postgraduate study.

Common certifications and study pathways include the Certified Chief Information Security Officer (C|CISO) by EC-Council, which requires 5 years’ experience in 3 of 5 domains and covers governance, risk, compliance, security operations, strategic planning, and finance, and the Certified Information Systems Security Professional (CISSP) by ISC2, which requires 5 years’ cumulative experience in 2+ of 8 domains and is the gold standard for senior security professionals. The Certified Information Security Manager (CISM) by ISACA is focused on security management and governance and is highly regarded for CISO-track professionals, while the Certified in Risk and Information Systems Control (CRISC) by ISACA focuses on enterprise IT risk management and complements CISM well.

On the study side, the Master of Information Technology (Cyber Security specialisation) at Whitecliffe is NZQA Level 9, supports the CISO certification pathway, and is available full-time (1 year) or part-time (2 years). The Master of Cyber Security and Digital Forensics at AUT is a postgraduate programme combining cybersecurity and digital forensics, and the Master of Information Technology at University of Auckland develops ICT skills and business acumen for senior IT roles.

In New Zealand, it can also be valuable to connect into the local community and learning ecosystem. ISACA has an Auckland chapter, and Lumify Work provides CCISO training in Auckland, Wellington, and Christchurch.

 

Preparing a CV or cover letter for a Chief Information Security Officer role

CISO applications are won on leadership, influence, and measurable outcomes, not just a list of tools. Your CV should make it easy for a reader (including a board member) to quickly understand the scale of your responsibilities and the impact you’ve delivered.

CISO CV tips: lead with strategic achievements, not only technical skills, and quantify your impact where possible, for example: reduced security incidents by X%, led a team of X security professionals, or managed a security budget of $X.

Highlight board-level communication and your ability to translate technical risk into business language, and list relevant certifications prominently (for example, CISSP, CISM, C|CISO, CRISC). Demonstrate experience with recognised frameworks such as NIST, ISO 27001, NZISM, SOC 2, and any sector-specific requirements, and show clear ownership of incident response, disaster recovery, and business continuity.

For your cover letter, articulate your security philosophy and how it aligns with the organisation’s risk appetite, and explain how you build trust across the business, from engineers through to executives. Tailor your message to the sector (for example, government, finance, healthcare), and reflect the reality of their stakeholder landscape.