About the Role
The Senior Cybersecurity Officer will strengthen Energy One’s security posture and safeguard our digital assets. You will bring a strong background in application and infrastructure security, penetration testing, and hands-on expertise with modern security tools. You will play a key role in identifying vulnerabilities, managing risks, and ensuring compliance with industry standards.
Responsibilities
- Understand and support developers in an application security context
- Coordinate the response to security events and vulnerabilities (including MDR escalations) and track remediation to closure
- Maintain and improve security controls and baselines
- Support the ISMS by maintaining policies/standards, collecting evidence, and preparing for internal/external audits
- Perform risk assessments and maintain security risk/issue registers
- Produce clear status reporting and run operational governance cadence with regional stakeholders
- Support access reviews, exception handling, and change control
- Partner with the engineering and product teams to uplift application security by embedding secure SDLC practices (security requirements, threat modelling, design reviews), support penetration testing activities, oversight over security tooling (e.g., SAST/DAST/SCA/secret scanning as applicable), and triage/remediate application findings with agreed SLAs.
Requirements
- 5+ years in information/cyber security operations, GRC, and/or security service delivery
- Strong stakeholder management and written reporting skills
- Hands-on, pragmatic risk/issue management and incident/vulnerability coordination
- Familiarity with ISO 27001/ISMS evidence and audit practices
- Working knowledge of common security controls (identity and access management, vulnerability management, endpoint/network security, logging/monitoring)
- Application security experience including secure SDLC, threat modelling, and coordinating remediation of SAST/DAST/SCA and penetration test findings
- Ability to partner effectively with software engineers and product teams, translate security requirements into actionable work, and collaborate with global teams.
Skills
- Application security
- Infrastructure security
- Penetration testing
- Security tools
- Risk management
- Compliance
- ISO 27001
- ISMS
- Identity and access management
- Vulnerability management
- Endpoint security
- Network security
- Logging
- Monitoring
- Secure SDLC
- Threat modelling
- SAST
- DAST
- SCA
- Secret scanning
Location
- Australia
Work Type
- Hybrid
Experience Level
- Senior
- 5+ years
Benefits
- Flexible hybrid work environment
- Modern office environment
- Work with diverse and inclusive teams
- Career growth and professional development
- Part of a growing global business with exciting prospects
- $3,500 referral bonus
About the Company
- Energy One is a publicly listed leader in energy trading software, with over 15 years of experience delivering mission-critical services to wholesale energy, environmental, and carbon trading markets.
- We are the largest provider of 24/7 operational energy services in Australia and the second largest in Europe.
- Our technology supports a wide range of clients - from agile start-ups to major global energy enterprises, helping them navigate a fast-evolving industry shaped by climate goals, renewable energy integration, and market volatility.
Equal Opportunity
- Energy One is committed to diversity, inclusion, and equal opportunity. We welcome applications from people of all backgrounds.
