Director of Security
Hybrid
Full Time
#Security
#E Commerce
#Retail
#Risk Management
#Incident Response
#Vulnerability Assessment
#Compliance
#Cloud Security
#Application Security
#DevSecOps
Since 2011, THE ICONIC has transformed the retail landscape across Australia and New Zealand. As a premier destination for fashion, sports, and lifestyle, we operate a complex ecosystem of retail, marketplace, and service platforms that serve millions of customers. We are a team of over 1,000 people dedicated to shaping the future of shopping through innovation, sustainability, and a deep commitment to our communities. We are now looking for a strategic Director of Security to lead our efforts in protecting our business and our customers.
Responsibilities
- Define and execute a comprehensive security strategy and roadmap that aligns with our business objectives and global standards.
- Oversee governance and ensure we maintain compliance with frameworks such as GDPR, NIST CSF, and ISO 27001.
- Lead our incident response efforts, including managing playbooks and conducting post-incident reviews to strengthen our defenses.
- Perform regular risk assessments and vulnerability management to proactively identify and mitigate threats.
- Collaborate with our product, engineering, and IT teams to embed security best practices throughout the entire development lifecycle.
- Drive company-wide security awareness programs to foster a culture of vigilance across the organization.
- Provide regular reporting to senior leadership and the board regarding our security posture, key performance indicators, and risk mitigation strategies.
Must-haves
- Extensive experience leading security teams and managing large-scale security programs.
- Deep technical knowledge in risk management, vulnerability assessments, and incident recovery.
- Proven ability to implement and manage security controls aligned with international compliance frameworks.
- Strong communication skills, with the ability to translate complex security risks for non-technical stakeholders and board members.
- A track record of influencing cross-functional teams to prioritize security without compromising business goals.
- A relevant degree or equivalent professional experience, with certifications such as CISSP, CISM, or CRISC being highly valued.
- Fluency in English.
Nice-to-haves
- Professional background working within the retail or e-commerce sectors at scale.
- Hands-on technical experience with cloud security across AWS, Azure, or GCP.
- Expertise in application security and DevSecOps practices.
- Experience balancing regional security requirements with broader global strategies.
Benefits
- Hybrid and flexible work arrangements to support your work-life balance.
- Comprehensive paid time off.
- Access to our Employee Assistance Program for you and your family.
- Participation in our dedicated wellness programs.
THE ICONIC
2 views









