Skip to main content
Posted 04 August, 2026

Senior Security Specialist

Haumaru Whānau
Auckland, AUK, NZ Full Time
Reference: 3dcaf1c1264bd911

Job Description

\n

Auckland, New Zealand Full-time Senior

\n

Haumaru Technologies Limited is a premier cybersecurity organization operating under the Haumaru Whānau umbrella, delivering advanced security consulting, assurance, and governance services across New Zealand, UAE, and global markets. With CREST-accredited capabilities and deep expertise across penetration testing, security architecture, and compliance, we partner with financial institutions, government entities, and enterprise clients to build resilient and secure digital ecosystems.

About This Role\n

This is a full-time hybrid Senior Security Specialist role based in Auckland, New Zealand, with the flexibility to work from home part of the time. We are seeking a highly experienced Senior Security Specialist to lead and strengthen our cybersecurity, GRC, and data privacy capabilities.

\n

This role is ideal for professionals with a strong background in IT Audit, Security Operations, Risk Management, Data Privacy, and Compliance frameworks (ISO 27001, ISO 27701, NIST, NCA).

\n

The specialist will be responsible for leading cybersecurity audits, privacy assessments, ISO 27001 implementations, and enterprise security programs, while working closely with internal teams and clients to ensure effective security governance and regulatory compliance.

Responsibilities\n

Lead and execute IT audits, cybersecurity assessments, and ISO 27001 compliance engagements

\n

Design, implement, and maintain Information Security Management Systems (ISMS) aligned with ISO 27001

\n

Conduct data privacy assessments, Privacy Impact Assessments (PIA), and data protection reviews

\n

Ensure compliance with data privacy regulations and frameworks (e.g., PDPL, GDPR, ISO 27701)

\n

Develop and review security policies, standards, and procedures aligned with regulatory requirements

\n

Perform enterprise risk assessments and develop mitigation strategies

\n

Oversee Security Operations (SOC), SIEM monitoring, and incident response processes

\n

Conduct vulnerability assessments and security testing across infrastructure, applications, and cloud environments

\n

Evaluate and implement security controls across: Network security (firewalls, routers, switches), Operating systems (Windows, Linux, Unix), Databases and enterprise systems

\n

Assess and review security technologies such as DLP, WAF, Proxy, Endpoint Protection, and Cloud Security solutions

\n

Perform application security audits (SAP, Oracle, custom applications)

\n

Prepare and present audit findings, risk reports, and executive-level dashboards

\n

Lead, mentor, and guide teams on security audit methodology, ISO 27001 practices, and data privacy frameworks

\n

Collaborate with cross-functional teams to ensure secure architecture, compliance, and continuous improvement

Requirements\n

Proficiency in Cybersecurity, Network Security, and Information Security practices

\n

Strong experience in IT Audit, Risk Assessment, and Governance, Risk & Compliance (GRC)

\n

Hands-on experience with ISO 27001 implementation, auditing, and ISMS management

\n

Experience in Data Privacy and Protection frameworks (e.g., ISO 27701, PDPL, GDPR or equivalent)

\n

Strong understanding of Security Operations (SOC), SIEM, and Incident Response

\n

Experience with vulnerability assessments, security reviews, and control implementations

\n

Knowledge of enterprise security technologies such as DLP, WAF, Proxy, Endpoint Security, and Cloud Security

\n

Experience in ERP and business application audits (SAP, Oracle, or similar systems)

\n

Strong understanding of IT General Controls (ITGC), application controls, and audit methodologies

\n

Exceptional communication skills for executive reporting, stakeholder engagement, and client interaction

\n

Proven ability to lead security audits, compliance programs, and privacy initiatives

\n

Bachelor’s degree in Cybersecurity, Information Technology, or a related field

\n

CISA (Highly Preferred)

\n

CISSP / CISM

\n

ISO 27001 Lead Auditor or Lead Implementer

\n

CEH or equivalent technical certification

\n

ISO 22301 or other risk/compliance certifications are an advantage

\n
#J-18808-Ljbffr

Sign up for Job Alerts