Back to board
Early applicant
hipagesgroup·18 hours ago

Head of Cyber Security

Sydney, AustraliaHybridFull-timeSenior · 8+ yearsH1B likely

About this role

Hi! We’re hipages, an ASX-listed tech company and Australia’s #1 digital platform connecting households with trusted home improvement businesses. We're on a mission to transform the home improvement industry to build better lives for everyone.
With teams across Australia, New Zealand, the Philippines and Vietnam, we work as one team with a shared purpose.

We’re proud to be a certified Great Place to Work and WORK180’s #1 Employer for Women. At hipages, you’ll find real impact, career growth and a workplace where everyone belongs.

About the role

You'll own security strategy, governance and operations end-to-end: from presenting posture and risk to the Board's Audit & Risk Committee and Tech Working Group, to steering the security platform and its continuous improvement with a small, high-calibre team through an AI-accelerated engineering transformation.

Why join our Engineering team?

  • Hybrid working model
  • Competitive salary, benefits, and everyday discounts
  • In-house Talent Development team to prioritise personal and career growth
  • Cross-functional collaboration
  • Hands-on learning opportunities and workshops for continuous upskilling

How you will add value

  • Own the cyber security strategy and roadmap, anchored to NIST CSF 2.0 and OWASP SAMM, and present posture and risk quarterly to the Audit & Risk Committee and periodically to the Tech Working Group.
  • Own the security platform — cloud, endpoint, identity, network/SSE, WAF and CI/CD vulnerability gates — configuring and governing tooling, delivered through your AppSec lead, IT Operations and SRE.
  • Lead security incident response including board-level exercises, run vulnerability management end-to-end, and drive secrets management and IAM hygiene with SRE and Platform teams.
  • Set the security model for AI-assisted engineering and agentic systems: secure-by-default development practices, agent identity and access, agent-tooling governance and shadow-AI visibility.
  • Own the external IT audit relationship, run the annual penetration testing program, and oversee privacy operations and vendor due diligence alongside Legal.
  • Lead, coach and grow your Lead Application Security Engineer, building a partnering model across Engineering, SRE and IT Operations that scales security guidance without becoming a bottleneck.

About you

  • 8+ years experience in security, including experience leading a security function or operating as the clear second-in-command of a larger one, ideally within a listed company or similarly governed environment, with working knowledge of Australian privacy law and listed-company security obligations
  • Proven board/committee reporting capability: You can translate technical posture into risk language for non-technical directors and hold the room on "are we doing enough?"
  • Strong technical command of cloud security (AWS), application security / secure SDLC, and the modern control stack (CNAPP/CSPM, EDR, SSE, IdP/MDM, WAF, cloud SIEM), able to configure, evaluate and direct these tools
  • Framework and audit fluency: NIST CSF 2.0 and OWASP SAMM (or equivalents), with experience running external audits (Big-4 ITGC or similar) through to remediation
  • Credible AI security depth: LLM and agentic threat models, non-human identity, agent-tooling governance — and demonstrated use of AI to multiply a small team's output
  • A landscape thinker who delivers through others: You synthesise the evolving threat environment into posture, priorities and pragmatic risk trade-offs, leading through a lean team and partner teams with commercial discipline on a flat budget

Bonus points for:

  • Experience in a product-led technology, SaaS or marketplace/consumer-scale organisation
  • Multi-geography workforce security (offshore teams and development partners)
  • Purple teaming / offensive security background
  • Security certifications (CISSP, CISM, SABSA or similar)

Life at hipages

We're more than just a workplace. We're a place where you can be yourself, do great work and grow your career. Recognised as a Great Place to Work, our inclusive, supportive culture helps people thrive.

You'll use the best tools and tech, with real impact on our products and customers. We invest in your development and lead with coaching, not micromanagement – it's why 85% of our team say their leader is great.

And there's more:

  • Diverse, collaborative teams that love solving problems
  • Agile squads, hackathons, off-sites and roadshows
  • Extra leave for birthdays, volunteering, and more
  • Healthy snacks, continental breakfast and fresh fruit
  • Sydney CBD office near Town Hall and Gadigal Stations
  • Tailored growth support, mentoring and stretch projects
  • A vibrant social scene - we work hard and have fun doing it

We prioritise Diversity

At hipages, innovation and collaboration thrive in diverse and inclusive teams. We don't expect you to know everything - we care more about who you are as a person, a team member, and a leader. We're proud to be endorsed by WORK180 for supporting women's careers and we value diversity across culture, age, gender identity and sexual orientation.

Research shows that men often apply when they meet just 60% of the criteria, while women and minority groups wait until they tick every box. If you think you'd be a great fit - even if you don't meet every requirement - we'd love to hear from you.

We're also a Circle Back Initiative Employer, which means we commit to responding to every applicant.

#LI-JL1 #LI-Hybrid