Confidential mandate
Chief Data Officer — Cybersecurity Portfolio
Planned Hiring / New
CDO - Data mandate in Sydney, Australia · Technology
Convert fragmented cybersecurity data investment into trusted, reusable products with accountable adoption.
The mandate
A listed cybersecurity portfolio has invested heavily in data platforms, pipelines and analytics, yet reusable business value remains limited. Product-line consolidation has made duplicated definitions, access paths and engineering visible. Teams build local extracts because shared assets lack clear ownership, trust or service commitments. A new Chief Data Officer will turn investment into adopted data products.
The CDO will steward data activity connected to approximately A$1,400 million in annual recurring revenue and lead around 725 employees and material partners. Scope includes data strategy, governance, engineering, architecture, analytics, data products, quality, privacy partnership, commercial value, platforms and talent. The reporting line is to the Group Chief Executive or designated executive committee sponsor.
The first step is to map high-value decisions and workflows. Threat intelligence, product telemetry, customer adoption, service operations, commercial performance and risk each require different timeliness and control. The CDO will identify where reusable data can change an outcome, rather than begin with a catalogue of sources or technologies.
Data products need customers, owners and service levels. A trusted product should define its consumers, meaning, quality, latency, access, cost and support. The executive will distinguish durable shared assets from one-off analysis, retiring pipelines that duplicate logic without a justified need.
Product-line consolidation requires canonical definitions and governed migration. Customer, entitlement, incident, vulnerability, usage and revenue data may have conflicting histories. The CDO will decide which concepts become common, preserve necessary lineage and ensure changes do not corrupt controls or customer reporting.
Trust must be measurable. Accuracy, completeness, freshness, lineage, access and observed use should be visible by consequence. Not every field deserves the same control. Named business and technical owners must respond when thresholds fail, and remediation should address upstream causes rather than recurring manual correction.
Cybersecurity data carries sensitive obligations. Access, minimisation, retention, sovereignty and ethical use should be embedded in product design. Security and privacy functions retain independent authority, while the CDO ensures governance is practical enough that teams use approved paths instead of creating uncontrolled copies.
Adoption is the test of reusable value. Dashboards viewed occasionally or platforms with many registered users may not change a decision. The CDO will measure recurring workflow use, decisions improved, manual effort removed, customer value and economic benefit. Data products without adoption need redesign or retirement.
Investment decisions should compare build, buy and partner options through lifetime economics. Cloud consumption, licences, engineering, data acquisition, support and exit cost belong in the case. Benefits count when work, risk or customer outcomes change, not when infrastructure is deployed.
The organisation needs federated accountability without fragmented standards. Domain teams may own products close to business context, supported by common platform and governance capability. The CDO will assess leaders, clarify decision rights and build succession for engineering, governance and product roles.
Why this seat is open
The role is newly created for the next operating model and is not an incumbent replacement. A planned four-to-six-month search allows the appointee to arrive before capital and talent choices. Existing leaders retain responsibility until the remit is formally activated.
What you will own
- Identify data products tied to consequential cybersecurity decisions.
- Steward data investment across approximately A$1,400 million of annual recurring revenue.
- Establish customer, owner and service levels for reusable assets.
- Consolidate definitions and pipelines while preserving lineage.
- Lead approximately 725 employees and material partners.
- Embed access, privacy and retention controls into product design.
- Measure adoption through workflow and economic outcomes.
- Build federated ownership, common standards and leadership succession.
The first 12 months
The first 90 days should map priority decisions, meet the 30 stakeholders closest to limited reuse and assess leaders. Reconcile the data estate, stop acute control risks and agree product, quality, investment and retirement gates with the board.
Months four to nine should launch selected data products, retire duplicate pipelines and establish service ownership. Improve critical definitions, access and lineage, fill leadership gaps and prove early adoption through changed workflows or released effort.
By year end, trusted data products, accountable ownership and measurable adoption should reinforce the product consolidation. Delivery must remain within 10% of approval, with three forecasts aligning product demand, cloud cash, users, customers and people. Severe data-quality or access issues need verified resolution inside 30 days.
What the board will measure
- Priority data products with named customers, owners and service levels.
- Quality and lineage meeting thresholds based on business consequence.
- Reusable assets replacing duplicate pipelines and manual reconciliation.
- Adoption demonstrated through decisions, workflow and economic value.
- Preserve over nine in ten pivotal data specialists and establish ready succession across seven in ten positions reporting to the CDO.
- Sensitive data governed through practical, evidenced controls.
The person
You are a Chief Data Officer, Data and Analytics Head or Digital Executive with 18–22 years in technology or an adjacent enterprise. Your record shows governed data becoming routinely used products whose ownership, service commitments and financial contribution were explicit.
Your accountable P&L, book, budget or portfolio has been at least A$800 million, and you have led 500 or more people. Examples should show adoption and value sustained across two reporting periods.
You understand cybersecurity data, product management, governance and cloud economics. You can challenge platform enthusiasm, work credibly with domain leaders and make investment choices when technical reuse has no clear customer.
Compensation and terms
Base salary is A$520,000–700,000 plus annual incentive and LTI. The permanent Sydney role is onsite and supports international relocation. Notice periods up to six months are acceptable.
Confidentiality
The organisation, data estate, customers and control findings remain confidential. Identifying information follows mutual fit under an undertaking; the public context and values have been blended.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.