Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Transpower New Zealand is seeking an experienced ICT Risk and Assurance Manager to lead the security risk, assurance and governance function across IT, OT, cloud and third‑party environments. You’ll connect cyber risks, control performance and assurance findings to provide a clear basis for senior decision‑making.
You’ll shape a more integrated, evidence-led GRC capability while preparing for evolving regulatory expectations and critical infrastructure obligations in a nationally significant
Transpower’s purpose is to empower the energy future for New Zealand - a future that delivers a net-zero carbon economy and a reliable and secure electricity system.
At the forefront of the energy sector, Transpower is the regulated state-owned enterprise that owns and operates the national electricity transmission system and fulfils the role of system operator. With over $5 billion in critical infrastructure assets, we play a pivotal role in connecting electricity generators to users and distribution networks across Aotearoa, New Zealand.
Transpower operates at the centre of Aotearoa New Zealand’s electricity system. As cyber threats, technology dependencies and regulatory expectations develop, Transpower needs a risk and assurance function that pushes past demonstrating compliance. It will connect risk, control performance, assurance evidence and investment choices into a clear view of resilience across nationally significant infrastructure.
The Security Services team sits within our Information Services and Technology (ICT) Division and is responsible for keeping Transpower safe from cybersecurity risks across Information Technology (IT), Operational Technology (OT), identity, physical security and personnel security domains. The team also provides risk and assurance services to ICT, helping ensure security risks are understood, actively managed and appropriately governed.
As ICT Risk and Assurance Manager, you’ll lead Transpower’s security risk, assurance and governance function across IT, OT, cloud and third‑party environments. You’ll maintain the disciplines that support effective risk management today, then help shape a more integrated and evidence‑led GRC capability for the future.
The role sits at the intersection of technology, critical infrastructure, executive decision‑making and emerging regulation. You’ll connect cyber risks, control performance, assurance findings and resilience outcomes, giving senior leaders and governance forums a clear basis for decisions and investment.
You’ll play a central role in preparing Transpower for developing critical infrastructure expectations, shaping regulatory readiness across the digital and operational systems that support New Zealand’s national grid. This includes assessing likely obligations, building reusable assurance evidence, supporting regulatory engagement and helping the organisation adopt practical, risk‑based responses.
This is a rare opportunity to influence how a nationally significant operator governs cyber risk during a period of sustained technology investment, regulatory evolution and growing demand for demonstrable resilience.
Transpower’s security GRC capability is entering its next stage of maturity. The successful candidate will help develop the methods, evidence structures and working practices needed to respond to greater assurance demand and evolving regulatory expectations. This creates scope to shape how the function develops, supported by specialists across Security Services, ICT and the wider organisation.
You’ll bring strong experience in ICT risk, assurance, governance, audit or compliance, with the credibility to influence senior leaders and the practical judgement to turn complex risks into clear business advice. You’ll be comfortable working across technology, operational and regulatory settings, and will understand the importance of resilient cyber practices in critical infrastructure or similarly high‑assurance environments.
Additional professional certifications or qualifications in cyber risk, information systems audit, security architecture, or security assurance would be useful, but are not essential. This could include CRISC, CISA, SABSA, TOGAF, Cyber Lead Auditor or Cyber Lead Implementer.
We’d also value practical experience applying recognised security and control frameworks such as NICT, ISO 27001, CIS Controls or IEC 62443, along with experience in any of the following areas:
Aotearoa, New Zealand is powered by the people who work here. Every home, every marae, every electric vehicle, every hospital relies on the electricity we manage and deliver. This is your opportunity to join us on a mission that affects all New Zealanders, the planet, and the economy.
With over 28 nationalities, our people provide diverse perspectives, knowledge, and deep and varied experience which they love to share and which we celebrate. We work in the office or on‑site for a minimum of three days each week, which helps us build and maintain relationships, support learning, deliver outcomes, and sustain our culture. This approach also offers staff the flexibility they need for both work and personal commitments, with adaptable daily start and finish times.
We prioritise employee wellbeing with a range of health and wellness benefits - check them out here: https://www.transpower.co.nz/about-us/careers-transpower/staff-benefits
To understand more about the breadth of our work at Transpower - check out our Integrated Report 2506 Transpower Integrated Report FY25, ICT Strategy ICT Strategy and review the position description for this role.
Applications will be reviewed as they are received, and conversations may commence prior to the close date.
Exciting eligibility to work in Aotearoa New Zealand is required.