Cyber Risk Analyst

Cubic Transportation Systems

Wellington

On-site

NZD 120,000 - 160,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Training budget

Job summary

Cubic Transportation Systems seeks an experienced Information Security professional in Wellington to support PCI-DSS, ISO 27001, and related audits. You will manage compliance programs, coordinate audits, and drive remediation with engineering and operations teams.

The role requires deep security controls knowledge, strong communication, and the ability to operate across vendor and customer interfaces within a global CTS framework based in NZ.

Qualifications

  • Minimum 8 years’ experience in services or IT systems in a mission critical setting.
  • University degree in Computer Science, Engineering, or related IT field.
  • At least 5 years’ experience in IT security and/or Payment Card processing systems.
  • The candidate must reside within commuting distance from CTS offices in Wellington NZ.

Responsibilities

  • Lead security risk assessment policy and processes.
  • Coordinate internal/external audits (PCI-DSS, ISO 27001, SOC 1/2).
  • Plan and execute compliance evaluations and remediation.
  • Engage with auditors and security teams to ensure remediation progress.
  • Maintain OneTrust GRC records and monitoring.

Skills

Security risk assessment
Audit coordination
Stakeholder management
PCI DSS knowledge
ISO 27001 knowledge
SOC 1/2 knowledge
Policy development

Education

University degree in Computer Science or related IT field
Security/compliance certifications

Tools

OneTrust GRC
Microsoft Office

Job description

Jora New Zealand will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

Cubic Transportation Systems – Wellington Central, North Island

Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.

Job Summary:

As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating environment to ensure compliance with organization security policies and controls. Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develop mitigation plans. Partners with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts. This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.

RESPONSIBILITIES

Essential Job Duties and Responsibilities

Perform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.

Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.

Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits. Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilities

Lead the design and control reviews and assessments to support continuous compliance with security policies and standards

Manage security review processes for all solutions to ensure they their design and implementation meets compliance requirements – including: PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements like the Australian Essential 8 and New Zealand NZ-ISM. Document and actively communicate any areas where the solutions and processes are not fully compliant.

Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.

Identify stakeholders in remediation of compliance gaps and actively elevate issues to them in a constructive manner that helps them understand the actions required. Work to gain acceptance of responsibility and track progress towards remediation. Actively manage escalation as needed if solutions are not resolved in a timely manner.

Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.

Capture compliance gaps and remediation plans in the OneTrust GRC system. Plans, reviews, and performs (as needed) controls monitoring around complex customer facing systems using the One Trust.

Liaise\engage with Cubic customers and Security Teams to build positive relationships and outcomes

Supports efforts to educate Security Management and Security Team Members in compliant IT processes and controls. Prepare and maintain process and control documentation

Aid in the development of solutions to problems identified during audits and translates these solutions into practical recommendations. Partner with Operations and Engineering Teams to ensure timely and acceptable remediation of issues.

Follow up on recommendations and appraises corrective actions taken to improve deficient conditions. To the greatest extent possible, ensure all Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.

Review vendor contracts and SOC reports to evaluate the impact on the company’s controls. Coordinates with third party vendors where appropriate.

General Duties and Responsibilities:

Reliably demonstrate accountability for work assignments and proactive communications about issues and status. A strong history of proactively identifying effective solutions for challenges.

Able to reliably demonstrate ethical behavior and accurate communications even when complex factors are involved.

Able to operate in a professional manner, even in tense or continuous settings.

Comply with Cubic's Quality Management System

Comply with Cubic's quality, health, safety, and security policies.

Support the company's strategic objectives and collaborate across departments.

Comply with Cubic Human Resources Procedures

SKILLS/EXPERIENCE/KNOWLEDGE

Strong written and oral communication skills in English, with capability to use Microsoft Office solutions. Ability to effectively and openly collaborate with team members clients, IT management, staff, and business units in a cross functional and matrixed IT organization

Comfortable working with staff at all levels and in other geographical locations within the organization

Familiarity with PCI DSS 4, ISO 27001-2022, and or SOC I/II requirements and audits.

Expert level experience collaborating with stakeholders and solution providers in a cross functional and matrixed IT organization. Able to adapt style efforts to persuade in delivering messages that relate to the wider business. Is frequently called on to advise others on complex matters and may be accountable through team for delivery of business targets.

Exhibits advanced wide- ranging experience, using in- depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures. Provides solutions to issues in creative and effective ways. Understands the interrelationships of different disciplines. Directs the application of existing principles and guides development of new policies and ideas.

Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors. Determines methods and procedures on new assignments. Exercises judgment in selecting methods, evaluating, adapting complex techniques and evaluation criteria for obtaining results.

Deep understanding of security risks and threats as they relate to the company's operating environments.

QUALIFICATIONS

Minimum 8 years’ experience in services or IT systems in a mission critical setting.

University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.

At least 5 years’ experience working in IT security and/or Payment Card processing systems. Strong understanding of technical concepts, as well as demonstrated ability to understand complex internally developed systems.

The candidate must reside within commuting distance from CTS offices in Wellington NZ, and be able to periodically travel within the region.

Relevant security or IT compliance certification in one or more areas, such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA or equivalent.

Knowledge of or willingness to learn information security best practices as it pertains to Open Payments, Mobility as a Service, data classifications, Microsoft Azure, AWS (or similar) cloud security and infrastructure, Web infrastructure security (Applications and APIs), Network security tools (IDS/IPS, firewalls, etc.), Encryption technology and implementation, Database security, Operating system security and hardening, vulnerability assessment tools and writing risk mitigation plans according to the assessment, and SIEM and FIM solutions.

Condition of Employment:

Successful outcome of a National Police Check

The description provided above is not intended to be an exhaustive list of all job duties, responsibilities and requirements. Duties, responsibilities and requirements may change over time and according to business need.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Risk & Compliance Analyst
Security Risk & Compliance Analyst

Cubic Transportation Systems • Wellington

On-site
NZD 120,000 - 160,000
Health insurance
Training budget
Senior Cyber Security Consultant
Senior Cyber Security Consultant

CyberCX • Auckland

Hybrid
NZD 110,000 - 180,000
Flexible hybrid working
Health and wellbeing program
Personalised development planning
+1
Senior Cyber Security Consultant
Senior Cyber Security Consultant

CyberCX • Wellington

On-site
NZD 120,000 - 180,000
Cyber Security Risk Manager | 1248878
Cyber Security Risk Manager | 1248878

H2R • Auckland

On-site
NZD 96,000 - 152,000
6mth+ contract
Dedicated security project team
Senior Cybersecurity Consultant
Senior Cybersecurity Consultant

Datacom • Auckland

On-site
NZD 140,000 - 190,000
Remote working
Flexi-hours
Professional development
Security Network Technician
Security Network Technician

JobSpace • Auckland

On-site
NZD 70,000 - 100,000
Information Security Manager
Information Security Manager

Orion NZ • Christchurch

Hybrid
NZD 150,000 - 190,000
Flexible working arrangements
My Days leave
Wellbeing allowance
+1
System and Security Specialist
System and Security Specialist

Civil Aviation Authority New Zealand • Wellington

On-site
NZD 99,000 - 121,000
KiwiSaver contributions (up to 4%)
Vision assistance
Employee Assistance Programme
Security Lead, Cyber Operations and Engineering
Security Lead, Cyber Operations and Engineering

New Zealand Customs Service • Wellington

On-site
NZD 150,000 - 190,000
Experienced Security Technician
Experienced Security Technician

Aotea security • Hamilton

On-site
NZD 90,000 - 120,000