Senior Security Specialist
Job Description
Auckland, New Zealand Full-time Senior
\nHaumaru Technologies Limited is a premier cybersecurity organization operating under the Haumaru Whānau umbrella, delivering advanced security consulting, assurance, and governance services across New Zealand, UAE, and global markets. With CREST-accredited capabilities and deep expertise across penetration testing, security architecture, and compliance, we partner with financial institutions, government entities, and enterprise clients to build resilient and secure digital ecosystems.
About This Role\nThis is a full-time hybrid Senior Security Specialist role based in Auckland, New Zealand, with the flexibility to work from home part of the time. We are seeking a highly experienced Senior Security Specialist to lead and strengthen our cybersecurity, GRC, and data privacy capabilities.
\nThis role is ideal for professionals with a strong background in IT Audit, Security Operations, Risk Management, Data Privacy, and Compliance frameworks (ISO 27001, ISO 27701, NIST, NCA).
\nThe specialist will be responsible for leading cybersecurity audits, privacy assessments, ISO 27001 implementations, and enterprise security programs, while working closely with internal teams and clients to ensure effective security governance and regulatory compliance.
Responsibilities\nLead and execute IT audits, cybersecurity assessments, and ISO 27001 compliance engagements
\nDesign, implement, and maintain Information Security Management Systems (ISMS) aligned with ISO 27001
\nConduct data privacy assessments, Privacy Impact Assessments (PIA), and data protection reviews
\nEnsure compliance with data privacy regulations and frameworks (e.g., PDPL, GDPR, ISO 27701)
\nDevelop and review security policies, standards, and procedures aligned with regulatory requirements
\nPerform enterprise risk assessments and develop mitigation strategies
\nOversee Security Operations (SOC), SIEM monitoring, and incident response processes
\nConduct vulnerability assessments and security testing across infrastructure, applications, and cloud environments
\nEvaluate and implement security controls across: Network security (firewalls, routers, switches), Operating systems (Windows, Linux, Unix), Databases and enterprise systems
\nAssess and review security technologies such as DLP, WAF, Proxy, Endpoint Protection, and Cloud Security solutions
\nPerform application security audits (SAP, Oracle, custom applications)
\nPrepare and present audit findings, risk reports, and executive-level dashboards
\nLead, mentor, and guide teams on security audit methodology, ISO 27001 practices, and data privacy frameworks
\nCollaborate with cross-functional teams to ensure secure architecture, compliance, and continuous improvement
Requirements\nProficiency in Cybersecurity, Network Security, and Information Security practices
\nStrong experience in IT Audit, Risk Assessment, and Governance, Risk & Compliance (GRC)
\nHands-on experience with ISO 27001 implementation, auditing, and ISMS management
\nExperience in Data Privacy and Protection frameworks (e.g., ISO 27701, PDPL, GDPR or equivalent)
\nStrong understanding of Security Operations (SOC), SIEM, and Incident Response
\nExperience with vulnerability assessments, security reviews, and control implementations
\nKnowledge of enterprise security technologies such as DLP, WAF, Proxy, Endpoint Security, and Cloud Security
\nExperience in ERP and business application audits (SAP, Oracle, or similar systems)
\nStrong understanding of IT General Controls (ITGC), application controls, and audit methodologies
\nExceptional communication skills for executive reporting, stakeholder engagement, and client interaction
\nProven ability to lead security audits, compliance programs, and privacy initiatives
\nBachelor’s degree in Cybersecurity, Information Technology, or a related field
\nCISA (Highly Preferred)
\nCISSP / CISM
\nISO 27001 Lead Auditor or Lead Implementer
\nCEH or equivalent technical certification
\nISO 22301 or other risk/compliance certifications are an advantage
\n