The Department of Energy, Environment and Climate Action (DEECA) is seeking an experienced Chief Information Security Officer (CISO) to lead enterprise cyber security, cloud governance and digital resilience across a diverse portfolio that supports Victoria's energy, environment, climate action and emergency management outcomes.
This is a significant enterprise high-impact leadership role for a senior cyber professional who wants to influence strategy, strengthen organisational resilience and enable secure digital services in a complex and purpose-driven public sector environment.
As DEECA's Chief Information Security Officer, you will provide strategic leadership for the department's cyber security and information security functions, ensuring the protection of critical information assets while enabling the delivery of secure and innovative digital services. You will establish and oversee enterprise-wide security policies, frameworks, governance and risk management programs across DEECA and its portfolio entities, ensuring compliance with government and regulatory requirements. You will also provide strategic oversight of DEECA's cloud platforms and services, driving continuous optimisation to improve cost, service and quality outcomes.
The role is responsible for identifying, assessing and communicating cyber and information security risks, driving a strong security culture across the organisation, and leading the development and implementation of security strategies that strengthen resilience against emerging threats. As the department's principal security advisor, you will work closely with executives, business leaders and external partners to provide expert guidance, lead major security initiatives, build organisational capability, and ensure security is embedded into decision-making, project delivery and operational practices.
About You
You will bring:
- Proven success in senior leadership roles within cyber security, information security, risk management, IT and/or OT environments.
- Strong knowledge of security frameworks and standards including ISO 27001, NIST, ITIL and COBIT.
- Experience leading enterprise-wide security programs and major technical initiatives, such as Identity and Access Management (IAM) programs.
- Strong understanding of information security risk management and cyber security technologies.
- Experience overseeing cloud platforms and services, with a focus on operational performance, service quality, cost optimisation and secure cloud governance.
- Proven ability to advise executives and senior stakeholders on complex cyber, information security and digital risk matters.
- Demonstrated ability to lead organisational change, influence stakeholders and build high-performing teams.
- Excellent communication skills with the ability to translate complex technical issues into clear business outcomes.
- Sound judgement and the ability to balance security risk with operational and service delivery requirements.
About the Division
The Information Services Division within DEECA leads the provision and adoption of information and communication technology, services and processes that enable business groups to achieve their strategic objectives.
The focus of the division is to add value by leveraging technology and digital ways of working, to deliver a stable, secure and contemporary technology environment that provides the platform for DEECA to manage its business and deliver excellent customer services.
The Information Services Division (ISD) will be at the forefront of technology solutions and expertise to best deliver our customers' technology needs. We will apply best-practice methods and techniques to deliver, operate and govern our technology products and services, we will deliver cost-effective technology solutions and embed our customer's needs into all our decision-making.
This is an ongoing position. The work location for this position is flexible within Victoria with hybrid work arrangements available.
To be considered for this position, applicants are encouraged to submit a resume and cover letter (no longer than 2 pages) summarising their skills and relevant experience.
For further information, please refer to the attached position description or call Joanne Curran on 0436 808 212 or email [email protected].
Applications close at midnight on Monday, 10 August 2026.
Other relevant information:
Preferred candidates will be required to:
- undertake pre-employment screening, including completion of a Declaration and Consent form and a National Police Check
- have their misconduct declarations validated, irrespective of whether misconduct has been declared or not
- provide at least two appropriate referees, including their current direct line manager or where relevant (i.e. because they are not employed) most recent direct line manager in accordance with the requirements set out in executive reference checks.
- provide evidence of their right to work in Australia
For more information about the pre-screening requirements for this position, please refer to the position description.
To be eligible for appointment to this role, applicants will possess corresponding work rights for the advertised employment period. Appointment to an ongoing position is only available to an Australian/New Zealand citizen or an Australian Permanent Resident.
A Diverse, Inclusive and Flexible Workplace
DEECA welcomes applicants from a diverse range of backgrounds and we focus on the essential requirements of the job and being consistent and fair in our treatment of all applicants. We also understand that a balanced life is important to our employees. Talk to us about our flexible options such as working some days from home, starting early or late, working part time, job sharing or accessing paid or unpaid leave.
For further information including the position description, key selection criteria and to apply visit www.careers.vic.gov.au