职位描述
Transpower's purpose is to empower the energy future for New Zealand - a future that delivers a net-zero carbon economy and a reliable and secure electricity system.
At the forefront of the energy sector, Transpower is the regulated state-owned enterprise that owns and operates the national electricity transmission system and fulfils the role of system operator. With over $5 billion in critical infrastructure assets, we play a pivotal role in connecting electricity generators to users and distribution networks across Aotearoa, New Zealand.
Role Context
Transpower operates at the centre of Aotearoa New Zealand's electricity system. As cyber threats, technology dependencies and regulatory expectations develop, Transpower needs a risk and assurance function that pushes past demonstrating compliance. It will connect risk, control performance, assurance evidence and investment choices into a clear view of resilience across nationally significant infrastructure.
About the team
The Security Services team sits within our Information Services and Technology (ICT) Division and is responsible for keeping Transpower safe from cybersecurity risks across Information Technology (IT), Operational Technology (OT), identity, physical security and personnel security domains. The team also provides risk and assurance services to ICT, helping ensure security risks are understood, actively managed and appropriately governed.
Reporting to the Head of Security Services, this role works closely with Security Operations, Identity and Access Management, Security Architecture and Design, Operational Technology teams, Enterprise Risk, Legal, Compliance and Privacy, ICT leaders, business system owners, regulators, auditors, industry partners and strategic vendors.
The Opportunity
As ICT Risk and Assurance Manager, you'll lead Transpower's security risk, assurance and governance function across IT, OT, cloud and third-party environments. You'll maintain the disciplines that support effective risk management today, then help shape a more integrated and evidence-led GRC capability for the future.
The role sits at the intersection of technology, critical infrastructure, executive decision-making and emerging regulation. You'll connect cyber risks, control performance, assurance findings and resilience outcomes, giving senior leaders and governance forums a clear basis for decisions and investment.
You'll play a central role in preparing Transpower for developing critical infrastructure expectations, shaping regulatory readiness across the digital and operational systems that support New Zealand's national grid. This includes assessing likely obligations, building reusable assurance evidence, supporting regulatory engagement and helping the organisation adopt practical, risk-based responses.
This is a rare opportunity to influence how a nationally significant operator governs cyber risk during a period of sustained technology investment, regulatory evolution and growing demand for demonstrable resilience.
The interesting work you'll be involved in will include
- Developing, maintaining and continuously improving ICT security risk, assurance and governance frameworks
- Developing and maintaining bowtie-based risk models for critical ICT systems and services, including IT, OT, cloud and third-party environments
- Leading assurance programmes that assess risk, control effectiveness, compliance obligations and resilience outcomes
- Providing reporting on ICT risk, security controls, resilience and compliance to senior management, governance forums and executive leaders
- Coordinating internal and external assurance activity, including audits, regulatory reviews, security assessments and control validation
- Preparing Transpower for evolving critical infrastructure regulation through readiness assessments, evidence, engagement and practical implementation planning
- Connecting control effectiveness, operational evidence and security investment into a coherent view of cyber resilience
- Supporting security incident post-event reviews and identifying systemic improvements and assurance outcomes
- Building ICT risk and assurance capability across Transpower through practical tools, coaching, workshops and shared learning
- Contributing to sector discussions, regulatory consultations and critical infrastructure security initiatives
Transpower's security GRC capability is entering its next stage of maturity. The successful candidate will help develop the methods, evidence structures and working practices needed to respond to greater assurance demand and evolving regulatory expectations. This creates scope to shape how the function develops, supported by specialists across Security Services, ICT and the wider organisation.
What will you bring?
You'll bring strong experience in ICT risk, assurance, governance, audit or compliance, with the credibility to influence senior leaders and the practical judgement to turn complex risks into clear business advice. You'll be comfortable working across technology, operational and regulatory settings, and will understand the importance of resilient cyber practices in critical infrastructure or similarly high-assurance environments.
Skills and experience we'll assess (please provide examples)
- 5+ years' experience in cyber/ICT, risk, assurance, audit or governance functions
- Demonstrated experience developing and operating cyber/ICT risk and assurance frameworks
- Experience supporting senior leadership, executive-level governance and risk-based decision making
- Experience with regulatory compliance, assurance activity, control assessments and evidence-based reporting
- Strong understanding of both IT and OT security environments, ideally including cloud and third-party technology risk
- A relevant tertiary qualification in Cyber Security, Information Security, Computer Science, Engineering, Risk Management or a related discipline
What's advantageous but not essential:
Additional professional certifications or qualifications in cyber risk, information systems audit, security architecture, or security assurance would be useful, but are not essential. This could include CRISC, CISA, SABSA, TOGAF, Cyber Lead Auditor or Cyber Lead Implementer.
We'd also value practical experience applying recognised security and control frameworks such as NICT, ISO 27001, CIS Controls or IEC 62443, along with experience in any of the following areas:
- Experience working in critical infrastructure, utilities, electricity, regulated or similarly high-resilience enterprise environments
- Experience conducting or managing penetration testing, security reviews, architecture assessments, control validation or threat modelling activity
- Experience engaging with regulators, government agencies, assurance bodies, external auditors, industry forums or strategic vendors
Join us at Transpower!
Aotearoa, New Zealand is powered by the people who work here. Every home, every marae, every electric vehicle, every hospital relies on the electricity we manage and deliver. This is your opportunity to join us on a mission that affects all New Zealanders, the planet, and the economy.
With over 28 nationalities, our people provide diverse perspectives, knowledge, and deep and varied experience which they love to share and which we celebrate. We work in the office or on-site for a minimum of three days each week, which helps us build and maintain relationships, support learning, deliver outcomes, and sustain our culture. This approach also offers staff the flexibility they need for both work and personal commitments, with adaptable daily start and finish times.
We prioritise employee wellbeing with a range of health and wellness benefits - check them out here: https://www.transpower.co.nz/about-us/careers-transpower/staff-benefits
Next Steps
To understand more about the breadth of our work at Transpower - check out our Integrated Report 2506 Transpower Integrated Report FY25, ICT Strategy ICT Strategy and review the position description for this role.
To help strengthen cyber resilience across transpower's critical infrastructure environment, please apply without delay.
Exciting eligibility to work in Aotearoa New Zealand is required.
Interested in knowing more, and seeing our Wellington head office? Watch a brief video here
薪资与福利
职位详情
关于 Transpower
公司概况
新西兰变电公司(Transpower New Zealand),一家由新西兰政府拥有的国有企业
总部新西兰惠灵顿市
成立时间1987年
规模全球约有1,300名员工,近年来员工人数报告范围从约800人到超过1,300人不等(来源:linkedin.com,ibisworld.com)。2025财年营业收入为9.86亿新西兰元(来源:transpower.co.nz)。
业务介绍
新西兰变电公司是负责拥有和运营全国电力输电系统(即国家电网)的国有企业,同时作为系统运营商,管理实时电力系统的稳定性和安全性(来源:transpower.co.nz)。其核心业务涵盖规划、建设、维护和运营高压输电网络,负责将电力输送至新西兰各地,服务发电商、线路公司、大型工业用户及更广泛的电力市场(来源:transpower.co.nz)。公司在严格的监管环境下运营,超过90%的收入来自由商务委员会监管的输电业务(来源:transpower.co.nz)。新西兰变电公司的战略重要性体现在其作为资产所有者和系统运营商的双重角色,使其在新西兰电力基础设施和市场运营中处于核心地位(来源:transpower.co.nz)。
项目与业绩
新西兰变电公司的项目组合主要集中于国家电网投资,而非独立发电设施。其资产包括约12,000公里的输电线路、168个变电站和约25,000座输电塔,管理着超过50亿新西兰元的输电资产(来源:transpower.co.nz,transpower.co.nz)。公司拥有大量受监管的网络投资计划,计划在2025年4月开始的RCP4监管控制期内投资47亿新西兰元(来源:transpower.co.nz)。近期项目重点包括电网升级、变电站改造、输电走廊开发及系统运营举措,以支持客户增长并保持网络可靠性(来源:transpower.co.nz)。
最新动态
过去两年中,新西兰变电公司发布了2025财年年度业绩,报告营业收入为9.86亿新西兰元,营业费用为4.2亿新西兰元,反映了与2025年4月1日开始的RCP4监管期相关的增长(来源:transpower.co.nz)。公司还积极在惠灵顿、奥克兰和基督城招聘多个职位,包括集团财务会计、高级项目工程经理以及有经验的电力系统动力学工程师等高级岗位(来源:transpower.co.nz,linkedin.com)。这些发展体现了新西兰变电公司在基础设施和人才队伍上的持续投资,以支持新西兰不断发展的电力需求。
工作环境
新西兰变电公司提供涵盖工程、系统运营、项目交付、商业与采购、财务、投资管理及技术现场支持等多个领域的丰富职业机会(来源:transpower.co.nz)。公司重视维护新西兰全天候电力供应的关键岗位,包括电力技术员、保护技术员、电工、电气装配工、机械装配工、输电与配电线路机械师、高压开关操作员、现场项目经理及现场主管等职位(来源:transpower.co.nz)。公司在惠灵顿、奥克兰和基督城设有办公室,支持以国家关键基础设施为核心的企业文化,提供办公室及现场两种职业发展路径(来源:linkedin.com)。
您的 LinkedIn 人脉
在 LinkedIn 上查看您在 Transpower 的联系人,申请时善用您的人脉。
查看人脉