Ict Risk And Assurance Manager

CGR Services

Auckland

Hybrid

NZD 150,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Transpower NZ is seeking an ICT Risk and Assurance Manager to lead governance across IT, OT, cloud and third‑party environments, shaping an integrated GRC capability for the future. You’ll connect cyber risks, assurance findings and resilience outcomes for senior leaders and governance forums, driving evidence-based decisions and regulatory readiness.

The role sits at the centre of critical infrastructure, with a strong emphasis on risk management, incident response post‑event reviews and

Qualifications

  • 5+ years in cyber / ICT risk and governance.
  • Experience developing risk and assurance frameworks.
  • Experience with regulatory compliance and evidence-based reporting.
  • Strong IT and OT security understanding.
  • tertiary qualification in Cyber Security, Information Security, CS, Engineering or Risk Management.

Responsibilities

  • Develop ICT security risk, assurance and governance frameworks.
  • Develop bowtie-based risk models for ICT systems and services, including IT, OT, cloud and third-party environments.
  • Lead assurance programmes that assess risk, control effectiveness, compliance obligations and resilience outcomes.
  • Provide reporting on ICT risk, security controls, resilience and compliance to senior management, governance forums and executive leaders.
  • Coordinate internal and external assurance activity, including audits, regulatory reviews, security assessments and control validation.
  • Prepare for evolving critical infrastructure regulation through readiness assessments, evidence, engagement and practical implementation planning.
  • Connect control effectiveness, operational evidence and security investment into a coherent view of cyber resilience.
  • Support security incident post-event reviews and identifying systemic improvements and assurance outcomes.
  • Build ICT risk and assurance capability across Transpower through practical tools, coaching, workshops and shared learning.
  • Contribute to sector discussions, regulatory consultations and critical infrastructure security initiatives.

Skills

ICT risk
Cyber risk
Governance
Audit
Regulatory compliance

Education

Bachelor's degree in Cyber Security / Information Security / related field

Job description

Lead ICT cyber risk, assurance and governance
  • Strengthen resilience across IT, OT and cloud environments
  • Influence executive, regulatory and sector‑level outcomes

Transpower’s purpose is to empower the energy future for New Zealand – a future that delivers a net‑zero carbon economy and a reliable and secure electricity system. At the forefront of the energy sector, Transpower is the regulated state‑owned enterprise that owns and operates the national electricity transmission system and fulfils the role of system operator. With over $5 billion in critical infrastructure assets, we play a pivotal role in connecting electricity generators to users and distribution networks across Aotearoa, New Zealand.

Role Context

Transpower operates at the centre of Aotearoa New Zealand’s electricity system. As cyber threats, technology dependencies and regulatory expectations develop, Transpower needs a risk and assurance function that pushes past demonstrating compliance. It will connect risk, control performance, assurance evidence and investment choices into a clear view of resilience across nationally significant infrastructure.

About the team

The Security Services team sits within our Information Services and Technology (ICT) Division and is responsible for keeping Transpower safe from cyber risks across Information Technology (IT), Operational Technology (OT), identity, physical security and personnel security domains. The team also provides risk and assurance services to ICT, helping ensure security risks are understood, actively managed and appropriately governed.

The Opportunity

As ICT Risk and Assurance Manager, you’ll lead Transpower’s security risk, assurance and governance function across IT, OT, cloud and third‑party environments. You’ll maintain the disciplines that support effective risk management today, then help shape a more integrated and evidence‑led GRC capability for the future.

The role sits at the intersection of technology, critical infrastructure, executive decision‑making and emerging regulation. You’ll connect cyber risks, control performance, assurance findings and resilience outcomes, giving senior leaders and governance forums a clear basis for decisions and investment.

You’ll play a central role in preparing Transpower for developing critical infrastructure expectations, shaping regulatory readiness across the digital and operational systems that support New Zealand’s national grid. This includes assessing likely obligations, building reusable assurance evidence, supporting regulatory engagement and helping the organisation adopt practical, risk‑based responses. This is a rare opportunity to influence how a nationally significant operator governs cyber risk during a period of sustained technology investment, regulatory evolution and growing demand for demonstrable resilience.

  • Developing, maintaining and continuously improving ICT security risk, assurance and governance frameworks
  • Developing and maintaining bowtie‑based risk models for critical ICT systems and services, including IT, OT, cloud and third‑party environments
  • Leading assurance programmes that assess risk, control effectiveness, compliance obligations and resilience outcomes
  • Providing reporting on ICT risk, security controls, resilience and compliance to senior management, governance forums and executive leaders
  • Coordinating internal and external assurance activity, including audits, regulatory reviews, security assessments and control validation
  • Preparing Transpower for evolving critical infrastructure regulation through readiness assessments, evidence, engagement and practical implementation planning
  • Connecting control effectiveness, operational evidence and security investment into a coherent view of cyber resilience
  • Supporting security incident post‑event reviews and identifying systemic improvements and assurance outcomes
  • Building ICT risk and assurance capability across Transpower through practical tools, coaching, workshops and shared learning
  • Contributing to sector discussions, regulatory consultations and critical infrastructure security initiatives
What will you bring?

You’ll bring strong experience in ICT risk, assurance, governance, audit or compliance, with the credibility to influence senior leaders and the practical judgement to turn complex risks into clear business advice. You’ll be comfortable working across technology, operational and regulatory settings, and will understand the importance of resilient cyber practices in critical infrastructure or similarly high‑assurance environments.

Skills and experience we’ll assess (please provide examples)
  • 5+ years’ experience in cyber / ICT, risk, assurance, audit or governance functions
  • Demonstrated experience developing and operating cyber / ICT risk and assurance frameworks
  • Experience supporting senior leadership, executive‑level governance and risk‑based decision making
  • Experience with regulatory compliance, assurance activity, control assessments and evidence‑based reporting
  • Strong understanding of both IT and OT security environments, ideally including cloud and third‑party technology risk
  • A relevant tertiary qualification in Cyber Security, Information Security, Computer Science, Engineering, Risk Management or a related discipline
What’s advantageous but not essential

Additional professional certifications or qualifications in cyber risk, information systems audit, security architecture, or security assurance would be useful, but are not essential. This could include CRISC, CISA, SABSA, TOGAF, Cyber Lead Auditor or Cyber Lead Implementer.

We’d also value practical experience applying recognised security and control frameworks such as NICT, ISO 27001, CIS Controls or IEC 62443, along with experience in any of the following areas:

  • Experience working in critical infrastructure, utilities, electricity, regulated or similarly high‑resilience enterprise environments
  • Experience conducting or managing penetration testing, security reviews, architecture assessments, control validation or threat modelling activity
  • Experience engaging with regulators, government agencies, assurance bodies, external auditors, industry forums or strategic vendors
Join us at Transpower!

Aotearoa, New Zealand is powered by the people who work here. Every home, every marae, every electric vehicle, every hospital relies on the electricity we manage and deliver. This is your opportunity to join us on a mission that affects all New Zealanders, the planet, and the economy.

With over 28 nationalities, our people provide diverse perspectives, knowledge, and deep and varied experience which they love to share and which we celebrate.

We work in the office or on‑site for a minimum of three days each week, which helps us build and maintain relationships, support learning, deliver outcomes, and sustain our culture. This approach also offers staff the flexibility they need for both work and personal commitments, with adaptable daily start and finish times.

We prioritise employee wellbeing with a range of health and wellness benefits - check them out here : https : / / www.transpower.co.nz / about-us / careers-transpower / staff-benefits

Role closes : 6th October. Exciting eligibility to work in Aotearoa New Zealand is required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ICT Risk and Assurance Manager
ICT Risk and Assurance Manager

New Zealand Government • Wellington

On-site
NZD 150,000 - 230,000
ICT Risk and Assurance Manager
ICT Risk and Assurance Manager

Transpower New Zealand • Hamilton

On-site
NZD 140,000 - 190,000
Staff benefits link provided
Ict Risk And Assurance Manager
Ict Risk And Assurance Manager

CGR Services • Wellington

On-site
NZD 120,000 - 160,000
ICT Risk and Assurance Manager
ICT Risk and Assurance Manager

Transpower New Zealand • Wellington

Hybrid
NZD 180,000 - 240,000
Health and wellness benefits
ICT Risk and Assurance Manager
ICT Risk and Assurance Manager

Transpower New Zealand Limited (TPNZ) • Auckland

Hybrid
NZD 140,000 - 190,000
Office on-site 3 days/week
Health and wellbeing benefits
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand Limited (TPNZ) • Wellington

Hybrid
NZD 150,000 - 190,000
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand • Auckland

On-site
NZD 90,000 - 120,000
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand • Wellington

On-site
NZD 140,000 - 180,000
Health & wellness benefits
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand • Hamilton

On-site
NZD 120,000 - 160,000
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand • Christchurch

On-site
NZD 140,000 - 200,000
Health and wellness benefits
Flexible daily start times