28th May, 2026
About CyberCX
CyberCX is the leading provider of professional cyber security and cloud services across Australia and New Zealand. With a workforce of over 1,400 professionals, we are a trusted partner to private and public sector organisations helping our customers confidently manage cyber risk, respond to incidents and build resilience in an increasingly complex and challenging threat environment.
Through our end-to-end range of cyber and cloud capabilities, CyberCX empowers our customers to securely accelerate opportunities in the digital economy. Our services include: consulting and advisory, governance, risk and compliance, incident response, penetration testing and assurance, network and infrastructure solutions, cloud security and solutions, identity and access management, managed security services, cyber security training, OT and secure AI design, build and run.
About the Role
The Director is responsible for leading our Secure AI advisory capability across strategy, governance, risk and control. The Director will partner with clients to define how AI should be adopted safely and securely, aligning business ambition with security, regulatory, and risk management expectations.
As a key leader in the practice, work closely with executive, risk, legal, and technology leaders to shape AI strategies, operating models, and control frameworks, while guiding complex AI risk and assurance engagements across enterprise and government environments. You will also lead and grow a multidisciplinary team spanning strategy, risk, and governance advisory services.
What You’ll Do
- Lead Secure AI strategy, risk, and governance advisory services
- Act as a trusted advisor to executives on AI risk, control, and regulatory exposure
- Define AI governance models, control frameworks, and operating models
- Lead AI and model risk assessments across GenAI and traditional ML use cases
- Translate security and regulatory requirements into practical AI control models
- Oversee complex AI assurance, compliance, and risk uplift engagements
- Partner with delivery and engineering leaders to align strategy with execution
- Support Secure AI presales, proposals, and executive-level client engagements
- Price, commercially plan and execute delivery quality review processes
- Contribute to thought leadership, IP, and Secure AI service development
- Mentor and grow junior talent
- Actively collaborate across CyberCX, and continuously look for ways to add value
- Facilitate communication, partnerships and cross-pollination across the business to allow teams to better engage and service customers
What You'll Bring - 10+ years in risk, security, technology strategy, or consulting leadership
- Strong background in technology risk, cyber security, or enterprise architecture
- Deep understanding of AI, model risk, and emerging GenAI risk domains
- Proven experience advising executives and boards on risk and governance
- Experience designing and operating risk and control frameworks
- Strong stakeholder engagement across risk, legal, compliance, and technology
- Experience working in regulated or security-sensitive environments
- Commercial and pricing experience, especially in a consultancy or services-based enterprise
Desirable Experience - AI and model risk management (MRM) frameworks
- Well-established security and risk frameworks relevant to AI (e.g. NIST CSF, ISO27001/42001, CSA AICM)
- AI-specific governance or control frameworks (e.g. NIST AI RMF, MITRE ATLAS, OWASP Top 10)
- Regulated or high assurance environments (e.g. financial services, government, critical infrastructure)
- Experience bridging risk, security, and engineering teams in projects, stakeholder management or presales roles
- Governance or security architecture certificates (e.g. ISO Auditor, CISM, SABSA, TOGAF)
- Building and experimenting with new security consulting processes including AI tools, workbench or coding agents and have a library or portfolio of code.
Why CyberCX - Flexible hybrid working – balance your time between home and office.
- Retail & lifestyle discounts through our corporate partners.
- Unmatched career development within Australia and New Zealand’s largest cyber community.
- Impactful consulting work across diverse industries, helping clients strengthen their security posture in a rapidly evolving cyber landscape.
We kindly request no agency submissions for this role. Unsolicited CV’s will not be accepted, and no fees will be payable.
Apply For Job