Cyber
Security
Security talent from SOC analyst to CISO.
Threat detection, SOC operations, penetration testing, secure development, GRC and executive cyber appointments. Both in-house teams and managed-security-service-provider environments.
What we do here
We place across the breadth of cyber - operations, engineering, architecture, and executive. Our CISO-level work is mostly retained; mid-senior IC engagements are typically specialist recruitment.
Recent engagements in this sector
A CISO appointment into a defence-technology scaleup; multiple senior security-engineering placements into a national MSSP; a Head of GRC search for a regulated fintech.
Capabilities we cover
- ▸ Security engineering and architecture
- ▸ DevSecOps and platform security
- ▸ Penetration testing and red team
- ▸ GRC, risk and compliance
Typical roles & bands
- Senior Security Engineer$140k-$200k base
- Security Architect$170k-$240k base
- Head of Security / CISO$240k-$380k total
- Source. The founder's placement records across 15 years of recruitment practice, continuing into AEY, plus ongoing market benchmarking.
- Composition. Base salary unless otherwise specified. Total-comp roles include equity / bonus / day-rate where stated.
- Variance. Actual offers move with stage, location, technical specialism, clearance status and the candidate's alternative options. The bands above are 25th–75th percentile, not floor and ceiling.
- Currency. All amounts in AUD.
Market notes
Cyber hiring in Australia has been compressed by demand from both the private sector and federal government in parallel. The strongest candidates have multiple offers in any given quarter. Speed of process and clarity of mandate matter more here than in almost any other sector we work in.
Sydney + Melbourne dominate; smaller pools in Brisbane and Canberra. CISO-level pool tracked nationally.
Anonymised, never shared. Maintained as a live working map, not a database.
- Sydney · April 2026Chief Information Security OfficerExecutive Search14d shortlist · 63d close
Let's talk about cyber security.
A 30-minute call is enough for us to know whether we can add value - and whether you should be talking to us, or to someone else.