ICT Risk and Assurance Manager

Transpower New Zealand

Wellington

Hybrid

NZD 180,000 - 240,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health and wellness benefits

Job summary

Transpower New Zealand is seeking an experienced ICT Risk and Assurance Manager to lead the security risk, assurance and governance function across IT, OT, cloud and third‑party environments. You’ll connect cyber risks, control performance and assurance findings to provide a clear basis for senior decision‑making.

You’ll shape a more integrated, evidence-led GRC capability while preparing for evolving regulatory expectations and critical infrastructure obligations in a nationally significant

Qualifications

  • Experience in ICT risk, assurance, governance, audit or compliance functions.
  • Proven ability to develop and operate ICT risk and assurance frameworks.
  • Experience supporting senior leadership, governance and risk-based decisions.
  • Experience with regulatory compliance, assurance activity, control assessments and evidence-based reporting.
  • Strong understanding of IT and OT security, including cloud and third‑party risk.
  • Relevant tertiary qualification in cyber security, information security, CS, engineering or risk management.

Responsibilities

  • Develop ICT security risk, assurance and governance frameworks.
  • Lead assurance programmes assessing risk, controls and resilience outcomes.
  • Provide reporting on ICT risk and compliance to senior management and governance forums.
  • Coordinate internal and external assurance activities including audits and regulatory reviews.
  • Shape regulatory readiness and evidence maturity for critical infrastructure.

Skills

ICT risk
assurance
regulatory reporting
leadership
stakeholder influence
cloud and third‑party risk

Education

Cyber security / information security degree

Job description

  • Lead ICT cyber risk, assurance and governance
  • Strengthen resilience across IT, OT and cloud environments
  • Influence executive, regulatory and sector-level outcomes

Transpower’s purpose is to empower the energy future for New Zealand - a future that delivers a net-zero carbon economy and a reliable and secure electricity system.

At the forefront of the energy sector, Transpower is the regulated state-owned enterprise that owns and operates the national electricity transmission system and fulfils the role of system operator. With over $5 billion in critical infrastructure assets, we play a pivotal role in connecting electricity generators to users and distribution networks across Aotearoa, New Zealand.

Role Context

Transpower operates at the centre of Aotearoa New Zealand’s electricity system. As cyber threats, technology dependencies and regulatory expectations develop, Transpower needs a risk and assurance function that pushes past demonstrating compliance. It will connect risk, control performance, assurance evidence and investment choices into a clear view of resilience across nationally significant infrastructure.

About The Team

The Security Services team sits within our Information Services and Technology (ICT) Division and is responsible for keeping Transpower safe from cybersecurity risks across Information Technology (IT), Operational Technology (OT), identity, physical security and personnel security domains. The team also provides risk and assurance services to ICT, helping ensure security risks are understood, actively managed and appropriately governed.

The Opportunity

As ICT Risk and Assurance Manager, you’ll lead Transpower’s security risk, assurance and governance function across IT, OT, cloud and third‑party environments. You’ll maintain the disciplines that support effective risk management today, then help shape a more integrated and evidence‑led GRC capability for the future.

The role sits at the intersection of technology, critical infrastructure, executive decision‑making and emerging regulation. You’ll connect cyber risks, control performance, assurance findings and resilience outcomes, giving senior leaders and governance forums a clear basis for decisions and investment.

You’ll play a central role in preparing Transpower for developing critical infrastructure expectations, shaping regulatory readiness across the digital and operational systems that support New Zealand’s national grid. This includes assessing likely obligations, building reusable assurance evidence, supporting regulatory engagement and helping the organisation adopt practical, risk‑based responses.

This is a rare opportunity to influence how a nationally significant operator governs cyber risk during a period of sustained technology investment, regulatory evolution and growing demand for demonstrable resilience.

The interesting work you’ll be involved in will include:
  • Developing, maintaining and continuously improving ICT security risk, assurance and governance frameworks
  • Developing and maintaining bowtie-based risk models for critical ICT systems and services, including IT, OT, cloud and third‑party environments
  • Leading assurance programmes that assess risk, control effectiveness, compliance obligations and resilience outcomes
  • Providing reporting on ICT risk, security controls, resilience and compliance to senior management, governance forums and executive leaders
  • Coordinating internal and external assurance activity, including audits, regulatory reviews, security assessments and control validation
  • Preparing Transpower for evolving critical infrastructure regulation through readiness assessments, evidence, engagement and practical implementation planning
  • Connecting control effectiveness, operational evidence and security investment into a coherent view of cyber resilience
  • Supporting security incident post‑event reviews and identifying systemic improvements and assurance outcomes
  • Building ICT risk and assurance capability across Transpower through practical tools, coaching, workshops and shared learning
  • Contributing to sector discussions, regulatory consultations and critical infrastructure security initiatives

Transpower’s security GRC capability is entering its next stage of maturity. The successful candidate will help develop the methods, evidence structures and working practices needed to respond to greater assurance demand and evolving regulatory expectations. This creates scope to shape how the function develops, supported by specialists across Security Services, ICT and the wider organisation.

What will you bring?

You’ll bring strong experience in ICT risk, assurance, governance, audit or compliance, with the credibility to influence senior leaders and the practical judgement to turn complex risks into clear business advice. You’ll be comfortable working across technology, operational and regulatory settings, and will understand the importance of resilient cyber practices in critical infrastructure or similarly high‑assurance environments.

Skills and experience we’ll assess (please provide examples):
  • 5+ years’ experience in cyber/ICT, risk, assurance, audit or governance functions
  • Demonstrated experience developing and operating cyber/ICT risk and assurance frameworks
  • Experience supporting senior leadership, executive‑level governance and risk‑based decision making
  • Experience with regulatory compliance, assurance activity, control assessments and evidence‑based reporting
  • Strong understanding of both IT and OT security environments, ideally including cloud and third‑party technology risk
  • A relevant tertiary qualification in Cyber Security, Information Security, Computer Science, Engineering, Risk Management or a related discipline
What’s advantageous but not essential:

Additional professional certifications or qualifications in cyber risk, information systems audit, security architecture, or security assurance would be useful, but are not essential. This could include CRISC, CISA, SABSA, TOGAF, Cyber Lead Auditor or Cyber Lead Implementer.

We’d also value practical experience applying recognised security and control frameworks such as NICT, ISO 27001, CIS Controls or IEC 62443, along with experience in any of the following areas:

  • Experience working in critical infrastructure, utilities, electricity, regulated or similarly high‑resilience enterprise environments
  • Experience conducting or managing penetration testing, security reviews, architecture assessments, control validation or threat modelling activity
  • Experience engaging with regulators, government agencies, assurance bodies, external auditors, industry forums or strategic vendors
Join us at Transpower!

Aotearoa, New Zealand is powered by the people who work here. Every home, every marae, every electric vehicle, every hospital relies on the electricity we manage and deliver. This is your opportunity to join us on a mission that affects all New Zealanders, the planet, and the economy.

With over 28 nationalities, our people provide diverse perspectives, knowledge, and deep and varied experience which they love to share and which we celebrate. We work in the office or on‑site for a minimum of three days each week, which helps us build and maintain relationships, support learning, deliver outcomes, and sustain our culture. This approach also offers staff the flexibility they need for both work and personal commitments, with adaptable daily start and finish times.

We prioritise employee wellbeing with a range of health and wellness benefits - check them out here: https://www.transpower.co.nz/about-us/careers-transpower/staff-benefits

Next Steps

To understand more about the breadth of our work at Transpower - check out our Integrated Report 2506 Transpower Integrated Report FY25, ICT Strategy ICT Strategy and review the position description for this role.

Role closes: 6th October

Applications will be reviewed as they are received, and conversations may commence prior to the close date.

Exciting eligibility to work in Aotearoa New Zealand is required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ICT Risk and Assurance Manager
ICT Risk and Assurance Manager

Transpower New Zealand • Hamilton

On-site
NZD 140,000 - 190,000
Staff benefits link provided
ICT Risk and Assurance Manager
ICT Risk and Assurance Manager

Transpower New Zealand Limited (TPNZ) • Auckland

Hybrid
NZD 140,000 - 190,000
Office on-site 3 days/week
Health and wellbeing benefits
ICT Risk and Assurance Manager
ICT Risk and Assurance Manager

New Zealand Government • Wellington

On-site
NZD 150,000 - 230,000
ICT Risk & Assurance Leader for Critical Infrastructure
ICT Risk & Assurance Leader for Critical Infrastructure

New Zealand Government • Wellington

Hybrid
NZD 120,000 - 180,000
Health and wellness benefits
On-site/office work model
Flexible start times
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand Limited (TPNZ) • Wellington

Hybrid
NZD 150,000 - 190,000
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand • Hamilton

On-site
NZD 120,000 - 160,000
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand • Auckland

On-site
NZD 90,000 - 120,000
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand • Wellington

On-site
NZD 140,000 - 180,000
Health & wellness benefits
Design & Infrastructure Manager - 10 to 12 month fixed term
Design & Infrastructure Manager - 10 to 12 month fixed term

Transpower New Zealand • Christchurch

On-site
NZD 140,000 - 200,000
Health and wellness benefits
Flexible daily start times
Health and Safety Practitioner - Christchurch
Health and Safety Practitioner - Christchurch

Transpower New Zealand • Christchurch

Hybrid
NZD 90,000 - 120,000
Wellbeing benefits
Hybrid work arrangement
Vehicle for business use