Job description
Transpower's purpose is to empower the energy future for New Zealand - a future that delivers a net-zero carbon economy and a reliable and secure electricity system.
At the forefront of the energy sector, Transpower is the regulated state-owned enterprise that owns and operates the national electricity transmission system and fulfils the role of system operator. With over $5 billion in critical infrastructure assets, we play a pivotal role in connecting electricity generators to users and distribution networks across Aotearoa, New Zealand.
Role Context
Transpower operates at the centre of Aotearoa New Zealand's electricity system. As cyber threats, technology dependencies and regulatory expectations develop, Transpower needs a risk and assurance function that pushes past demonstrating compliance. It will connect risk, control performance, assurance evidence and investment choices into a clear view of resilience across nationally significant infrastructure.
About the team
The Security Services team sits within our Information Services and Technology (ICT) Division and is responsible for keeping Transpower safe from cybersecurity risks across Information Technology (IT), Operational Technology (OT), identity, physical security and personnel security domains. The team also provides risk and assurance services to ICT, helping ensure security risks are understood, actively managed and appropriately governed.
Reporting to the Head of Security Services, this role works closely with Security Operations, Identity and Access Management, Security Architecture and Design, Operational Technology teams, Enterprise Risk, Legal, Compliance and Privacy, ICT leaders, business system owners, regulators, auditors, industry partners and strategic vendors.
The Opportunity
As ICT Risk and Assurance Manager, you'll lead Transpower's security risk, assurance and governance function across IT, OT, cloud and third-party environments. You'll maintain the disciplines that support effective risk management today, then help shape a more integrated and evidence-led GRC capability for the future.
The role sits at the intersection of technology, critical infrastructure, executive decision-making and emerging regulation. You'll connect cyber risks, control performance, assurance findings and resilience outcomes, giving senior leaders and governance forums a clear basis for decisions and investment.
You'll play a central role in preparing Transpower for developing critical infrastructure expectations, shaping regulatory readiness across the digital and operational systems that support New Zealand's national grid. This includes assessing likely obligations, building reusable assurance evidence, supporting regulatory engagement and helping the organisation adopt practical, risk-based responses.
This is a rare opportunity to influence how a nationally significant operator governs cyber risk during a period of sustained technology investment, regulatory evolution and growing demand for demonstrable resilience.
The interesting work you'll be involved in will include
- Developing, maintaining and continuously improving ICT security risk, assurance and governance frameworks
- Developing and maintaining bowtie-based risk models for critical ICT systems and services, including IT, OT, cloud and third-party environments
- Leading assurance programmes that assess risk, control effectiveness, compliance obligations and resilience outcomes
- Providing reporting on ICT risk, security controls, resilience and compliance to senior management, governance forums and executive leaders
- Coordinating internal and external assurance activity, including audits, regulatory reviews, security assessments and control validation
- Preparing Transpower for evolving critical infrastructure regulation through readiness assessments, evidence, engagement and practical implementation planning
- Connecting control effectiveness, operational evidence and security investment into a coherent view of cyber resilience
- Supporting security incident post-event reviews and identifying systemic improvements and assurance outcomes
- Building ICT risk and assurance capability across Transpower through practical tools, coaching, workshops and shared learning
- Contributing to sector discussions, regulatory consultations and critical infrastructure security initiatives
Transpower's security GRC capability is entering its next stage of maturity. The successful candidate will help develop the methods, evidence structures and working practices needed to respond to greater assurance demand and evolving regulatory expectations. This creates scope to shape how the function develops, supported by specialists across Security Services, ICT and the wider organisation.
What will you bring?
You'll bring strong experience in ICT risk, assurance, governance, audit or compliance, with the credibility to influence senior leaders and the practical judgement to turn complex risks into clear business advice. You'll be comfortable working across technology, operational and regulatory settings, and will understand the importance of resilient cyber practices in critical infrastructure or similarly high-assurance environments.
Skills and experience we'll assess (please provide examples)
- 5+ years' experience in cyber/ICT, risk, assurance, audit or governance functions
- Demonstrated experience developing and operating cyber/ICT risk and assurance frameworks
- Experience supporting senior leadership, executive-level governance and risk-based decision making
- Experience with regulatory compliance, assurance activity, control assessments and evidence-based reporting
- Strong understanding of both IT and OT security environments, ideally including cloud and third-party technology risk
- A relevant tertiary qualification in Cyber Security, Information Security, Computer Science, Engineering, Risk Management or a related discipline
What's advantageous but not essential:
Additional professional certifications or qualifications in cyber risk, information systems audit, security architecture, or security assurance would be useful, but are not essential. This could include CRISC, CISA, SABSA, TOGAF, Cyber Lead Auditor or Cyber Lead Implementer.
We'd also value practical experience applying recognised security and control frameworks such as NICT, ISO 27001, CIS Controls or IEC 62443, along with experience in any of the following areas:
- Experience working in critical infrastructure, utilities, electricity, regulated or similarly high-resilience enterprise environments
- Experience conducting or managing penetration testing, security reviews, architecture assessments, control validation or threat modelling activity
- Experience engaging with regulators, government agencies, assurance bodies, external auditors, industry forums or strategic vendors
Join us at Transpower!
Aotearoa, New Zealand is powered by the people who work here. Every home, every marae, every electric vehicle, every hospital relies on the electricity we manage and deliver. This is your opportunity to join us on a mission that affects all New Zealanders, the planet, and the economy.
With over 28 nationalities, our people provide diverse perspectives, knowledge, and deep and varied experience which they love to share and which we celebrate. We work in the office or on-site for a minimum of three days each week, which helps us build and maintain relationships, support learning, deliver outcomes, and sustain our culture. This approach also offers staff the flexibility they need for both work and personal commitments, with adaptable daily start and finish times.
We prioritise employee wellbeing with a range of health and wellness benefits - check them out here: https://www.transpower.co.nz/about-us/careers-transpower/staff-benefits
Next Steps
To understand more about the breadth of our work at Transpower - check out our Integrated Report 2506 Transpower Integrated Report FY25, ICT Strategy ICT Strategy and review the position description for this role.
To help strengthen cyber resilience across transpower's critical infrastructure environment, please apply without delay.
Exciting eligibility to work in Aotearoa New Zealand is required.
Interested in knowing more, and seeing our Wellington head office? Watch a brief video here
Pay & benefits
About this role
About Transpower
Company Overview
Transpower New Zealand, a state-owned enterprise owned by the New Zealand Crown
HeadquartersWellington City, New Zealand
Founded1987
SizeApproximately 1,300 employees globally, with reported staff numbers ranging from about 800 to over 1,300 in recent years (source: linkedin.com, ibisworld.com). Operating revenue of NZ$986 million in FY25 (source: transpower.co.nz).
What They Do
Transpower New Zealand is the state-owned enterprise responsible for owning and operating the country’s national electricity transmission system, known as the National Grid, and also acts as the System Operator managing real-time electricity system stability and security (source: transpower.co.nz). Their core business focuses on planning, building, maintaining, and operating the high-voltage transmission network that moves electricity across New Zealand, serving generators, lines companies, large industrial users, and the wider electricity market (source: transpower.co.nz). The company operates under heavy regulatory oversight, with over 90% of its revenue derived from regulated transmission activities overseen by the Commerce Commission (source: transpower.co.nz). Transpower’s strategic importance stems from its dual role as both asset owner and system operator, positioning it centrally within New Zealand’s electricity infrastructure and market operations (source: transpower.co.nz).
Projects & Track Record
Transpower’s project portfolio primarily consists of national grid investments rather than standalone power generation facilities. Their assets include approximately 12,000 kilometers of transmission lines, 168 substations, and around 25,000 transmission towers, managing over NZ$5 billion in transmission assets (source: transpower.co.nz, transpower.co.nz). The company has a substantial pipeline of regulated network investment, with proposed spending of NZ$4.7 billion under the RCP4 regulatory control period starting April 2025 (source: transpower.co.nz). Recent projects have focused on grid upgrades, substation enhancements, transmission corridor developments, and system operations initiatives to support customer growth and maintain network reliability (source: transpower.co.nz).
Recent Developments
In the last two years, Transpower released its FY25 annual results reporting operating revenue of NZ$986 million and operating expenses of NZ$420 million, reflecting growth linked to the commencement of the RCP4 regulatory period on 1 April 2025 (source: transpower.co.nz). The company has also actively recruited for a variety of roles across Wellington, Auckland, and Christchurch, including senior positions such as Group Financial Accountant, Project Engineering Group Manager, and Experienced Engineer – Power System Dynamics (source: transpower.co.nz, linkedin.com). These developments underscore Transpower’s ongoing investment in both its infrastructure and workforce to support New Zealand’s evolving electricity needs.
Working There
Transpower offers a wide range of career opportunities across engineering, system operations, project delivery, commercial and procurement, finance, investment management, and technical field support (source: transpower.co.nz). The company emphasizes roles critical to maintaining New Zealand’s 24/7 electricity supply, including power technicians, protection technicians, electricians, electrical fitters, mechanical fitters, transmission and distribution line mechanics, high-voltage switchers, site-based project managers, and site supervisors (source: transpower.co.nz). With offices in Wellington, Auckland, and Christchurch, Transpower supports a culture focused on nationally critical infrastructure, offering both office-based and field-based career paths (source: linkedin.com).
See how you’re connected
See your contacts at Transpower on LinkedIn and tap your network when applying.
View connections