- Position Cyber Security Architect
- Division Project Plus
- Job Type Contract
- Location Wellington - Central
- Ref# ZC49366
- Posted 3 September 2026
Cyber Security Architect
Contract: 10 months
Location: Wellington
Start: ASAP
Utilisation: 100%
Rate: Up to $165 per hour inclusive of fees
About the Role
We are seeking an experienced Cyber Security Architect to join a security assurance team supporting the certification, accreditation and ongoing security assessment of information systems.
This role will focus on security risk assessments, control validation, certification and accreditation activities, and the development of pragmatic security remediation plans. You will work closely with both technical and non-technical stakeholders to identify risks, assess security controls and communicate recommendations clearly.
The successful candidate will also have the opportunity to provide security consulting support across a range of projects, applying Secure by Design principles and contributing to security architecture and technical documentation.
Key Responsibilities
- Perform certification and accreditation activities for existing information systems.
- Review information system designs and security architecture.
- Develop and update Security Risk Assessments (SRAs) and Control Validation Plans (CVPs).
- Conduct Security Control Effectiveness Audits, including evidence collection and assessment.
- Develop practical security control remediation and risk management plans.
- Review and assess penetration testing results where required.
- Communicate security risks, audit findings and remediation recommendations to technical and business stakeholders.
- Prepare clear and concise memoranda, reports and supporting documentation.
- Contribute to technical designs, architecture documentation and security standards.
- Provide security consulting and Secure by Design guidance to project teams.
- Develop security artefacts required to support Certification and Accreditation under the NZISM framework.
About You
You will have:
- Detailed knowledge of the NZISM Certification and Accreditation (C&A) process within public sector organisations.
- Proven experience conducting Security Risk Assessments within public sector environments.
- Strong understanding of information system business and technical contexts.
- Experience identifying cyber security risks and developing clear risk statements.
- Experience assessing risk likelihood, consequence and impact.
- Strong knowledge of selecting and recommending appropriate security controls based on identified risks.
- Experience developing Control Validation Plans (CVPs).
- Experience conducting Control Validation Audits (CVAs), including security control evidence collection and effectiveness assessments.
- Experience developing Security Risk Management and Remediation Plans.
- Strong understanding of security controls, risk management and certification processes.
- Excellent written and verbal communication skills.
- Experience preparing memoranda, reports, technical standards and security documentation.
- Ability to translate complex technical information for non-technical audiences.
- Experience contributing to technical designs and architecture documentation.
What We’re Looking For
The ideal candidate will be a confident security professional who can work independently, manage competing priorities and build effective relationships across technical and business teams.
You will be pragmatic and solutions-focused, with the ability to assess complex security risks and provide clear, practical recommendations that support informed decision-making.
How to Apply
If you are an experienced Cyber Security Architect with strong NZISM, security risk assessment and certification and accreditation experience, we would like to hear from you.
Apply now with your CV and a brief summary of your relevant experience.
