Skip to main content
AfterDuty

Director (SO) Cyber and Information Security

Queensland Government · Brisbane, Queensland

Type
Full-time
Posted
5 days ago

Overview

Your operational command and incident response experience gives you a credible foundation for leading cyber incident response and threat assessment, and your background in managing multi-agency operations translates to coordinating security frameworks. However, this role demands deep technical expertise in cloud-native environments, architecture models, and security frameworks, plus certifications like CISM or CISSP, which are not typically part of a policing background. Without substantial retraining and technical upskilling, you would struggle to meet the core requirements.

About this role

  • About us

The Queensland Fire Department (QFD) provides fire prevention, preparedness and response services to fire in the built and landscape environments, as well as scientific and specialist capabilities to Queensland communities. The QFD provides a multi-hazard emergency response, including road crash rescue, bushfire, hazardous material, technical and vertical rescue, severe weather incidents, remote and swiftwater rescue, and provides a number of functions supporting community safety outcomes.

The department encompasses Queensland Fire and Rescue (QFR), Rural Fire Service Queensland (RFSQ), as well as the broader department which work together to pre-empt, prevent, mitigate and manage the consequences of fires and other emergencies on Queensland communities and support our large volunteer membership across the state.

The QFD is an organisation that is committed to reframing the department's relationship with Aboriginal and Torres Strait Islander peoples, communities, and organisations through activities identified in the QFD Reframing the Relationship Plan, contributing to Closing the Gap outcomes and building our cultural capability.

Purpose of the role

Cyber and Information Security is responsible for managing the agency's roadmap and response to the departments information and technology by effectively managing risks and associated cyber security, information availability, information privacy and information security requirements and infrastructure operations, while enabling and advancing business outcomes.

Reporting to the Executive Director, Information and Technology you will provide leadership and direction through all functions of the branch, including managing human resource, financial and budget, planning and program management, and reporting. You will be responsible for driving, influencing and managing strategic change for cyber and information security within the agency by developing (with specialist partners) and information security approach that is fit for purpose and consistent with industry standards and frameworks.

Key requirements

Highly desirable requirements

  • Minimum of 5 years' experience in leadership roles specialising in risk management, information security, ICT security and modern cloud native environments.
  • 4 + years experience managing and supporting information security in a mid size to large IT environment across a wide range of technologies and applications.
  • 2 + years experience as lead in planning for information security capabilities.
  • Demonstrated understanding of a wide range of architecture models, service deployment models and operational and security frameworks.
  • Certifications of either Cyber Information Security Manager (CISM) or Cyber Information Systems Security Professional (CISSP) preferred.

Your key accountabilities

Your part in the ongoing success of our department, in supporting frontline services will see you responsible for a variety of work, including, but not limited to:

  • Lead and manage the development and execution of the Cyber Security Framework and Roadmap to define and deliver initiatives in support of business strategies and objectives, ensuring the department meets it's obligations under cyber security standards.
  • Provide strategic guidance and risk advice for the agency's cyber and information security requirements to inform continuous improvement strategies and ensure effective decision-making processes.
  • Promote the agency's cyber and information security approach to senior executives, vendor partners and internal and external stakeholders to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy and recovery of information assets
  • Lead, manage and coordinate ongoing threat assessments to identify key risks to the organisation and adoption of relevant treatment plans to contain information security incidents and events, and protect the department's IT assets, intellectual property, regulated data and reputation.
  • Develop and implement initiatives focused on reducing technology risk and ensuring compliance to Queensland Government policies and regulatory standards.
  • Evaluate existing technology implementations and new technology initiatives, and consider associated consequences for all aspects of cyber and information security to improve the department's security posture.
  • Develop, maintain and report a pragmatic suite of information security related metrics and key performance indicators to promote the culture of strong information security and appreciation of the importance of cyber security and data management with staff and vendors to mitigate information security risks.
  • Manage human, financial and physical resources ensuring client service and performance management and drive a culture of accountability and fairness that encourages and enables teams and individual staff to meet challenges, develop skills and achieve results.

Capabilities

To determine your suitability for the role, you will be assessed on the following Leadership Competencies for Queensland behavioural profiles that link to the "key accountabilities" for this role:

Leadership Competency Stream - Program Leader (leading teams and/or projects)

Vision

  • Leads strategically
  • Leads change in complex environments

Results

  • Builds enduring relationships
  • Drives accountability and outcomes

Accountability

  • Fosters healthy and inclusive workplaces
  • Demonstrates sound governance

Once you join us we will want you to exemplify the QFD core values:

  • Respect
  • Integrity
  • Trust
  • Courage
  • Loyalty This work is licensed under a Creative Commons Attribution 3.0 Australia License.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Brisbane

Why this fits a police background

  • Incident command & response
  • Risk & threat assessment
  • Working to legislation & regulation

More cyber security & digital forensics jobs for ex-police

  • Your background running operational units and coordinating multi-agency responses maps directly onto leading national support functions and ensuring consistent, secure operations across multiple sites. You're used to setting clear accountabilities, managing risk, and driving continuous improvement, which is exactly what this role requires. Your experience with compliance and governance, from PACE to internal procedures, means you can bring structure and discipline from day one.

    Posted 2 days ago

  • Full-time

    Your experience working to strict regulatory frameworks like PACE and CPIA gives you a natural grounding in compliance and assurance, which is exactly what this cyber security GRC role demands. You've spent years maintaining accurate records, managing risk registers, and engaging with diverse stakeholders under pressure, so coordinating audits and driving adherence to standards like ISO 27001 will feel familiar. The role is a development opportunity, so your proven attention to detail and process-oriented mindset will let you build the specific cyber security knowledge on the job.

    Posted 5 days ago

  • Integrity and Security Analyst

    NSW Government · Sydney

    Full-time

    A$133,348 – A$146,945Estimated

    This role directly leverages your operational intelligence experience from policing — you'll produce intelligence products that identify security risks and inform frontline decisions, just as you did under the National Intelligence Model. Your ability to assess threats, manage multi-agency coordination, and apply legislative frameworks like PACE or RIPA is exactly what the NSW Electoral Commission needs to safeguard election integrity. The requirement for 10+ years in law enforcement confirms this is a role built for your background, not a sideways move into a completely new field.

    Posted 5 days ago

  • Full-time

    Your investigative experience from policing—evidence handling, chain of custody, case file management, and conducting structured interviews—maps directly onto the core responsibilities of this insider threat role. You are used to working with sensitive information, maintaining confidentiality, and producing defensible reports for multiple stakeholders, which is exactly what this position demands. The analytical and risk-assessment skills you developed through intelligence-led policing and managing complex investigations will let you hit the ground running in identifying and mitigating insider

    Posted 7 days ago