Chief Information Security Officer
A chief information security officer heads an organisation's security function at executive level, setting the strategy, policy and budget that keep its data and systems safe.

- Median salary*
- $200,200
3.6%vs last year, before tax
- People employed
- 6,800
1.5%vs last year
- Projected growth*
- +14%
to 2035
- AI exposure*
- Moderate
- automation risk
- Average hours*
- 45/wk
+5h vs all jobs
- Shortage status*
- In shortage
national
A chief information security officer sits at executive level, usually reporting to the chief executive or the board, and carries final responsibility for how an organisation manages cyber risk. The scope separates it from a security manager or architect: governance, regulatory obligations and budget take up as much of the week as technology does, and the job turns on translating technical risk into decisions a board can act on. Most work in larger organisations or regulated sectors such as financial services, government and health, where a dedicated security executive is expected rather than optional.
How much do chief information security officers earn?
The median full-time salary for a chief information security officer is $200,200 per annum, before tax, up $42,700 since 2018.
Pay at this level depends on the size of the organisation, the scope of the security function and whether the role reports to the chief executive or the board. Packages usually combine base salary with short and long term incentives, so the base figure can understate total earnings. Interim and consulting work is common at the top of the market, where rates are set per engagement rather than per year.
What does a chief information security officer do day to day?
The list below is what fills most weeks; the exact mix shifts with seniority and whatever stage the current work is at.
- Setting information security strategy and policy that line up with business goals and the organisation's stated risk appetite
- Leading the response when a breach or critical vulnerability hits, from containment through to notifying regulators and the board
- Running risk assessments, vulnerability programs and compliance audits against frameworks such as ISO 27001 and the Essential Eight
- Hiring, structuring and mentoring the security team, including deciding who owns which risk across the business
- Briefing executives and the board on security posture, regulatory obligations and the trade-offs behind each spending decision
What skills do chief information security officers need?
Employers look for cyber security, risk and internal controls, regulatory compliance, backed by Security Information and Event Management (SIEM) platforms fluency and strong stakeholder management.
Specialist skills
- Cyber security
- Risk and internal controls
- Regulatory compliance
- Strategy development
Software and tools
- Security Information and Event Management (SIEM) platforms
- Identity and Access Management (IAM) systems
- Vulnerability scanning and patch management tools
- Risk management frameworks (NIST, ISO 27001)
General skills
- Stakeholder management
- People leadership
- Written communication
- Problem solving
Is the job growing?
About 6,800 people work as chief information security officers in Australia, and employment is projected to grow 14% over the decade to 2035. That's healthy, above-average growth, and the role should stay in solid demand.
How do you become a chief information security officer?
Here's the path most chief information security officers take, step by step.
- 1Build a technical or risk foundation
A bachelor degree in information technology, computing, cyber security or a related field is the usual starting point, and 52% of the people in the role today hold one. Degrees in IT audit, risk or compliance can lead here too, because the job is as much about governance as technology.
- 2Work in hands-on security or assurance roles
Security analyst, engineer, architect and IT auditor positions teach you how controls behave in practice, which is the evidence you draw on later when you argue for a control at executive level. Expect several years here, ideally including a stint in incident response or a major uplift program.
- 3Move into security management
Leading a team, owning a budget and reporting to a chief information officer or a risk committee is the step that separates operational work from executive work. It is also where you learn to brief people who do not want technical detail.
- 4Add a postgraduate qualification or certification
A master's degree in cyber security or an MBA is common at this level, and 26% of the workforce holds a postgraduate qualification. Certifications such as CISSP or CISM carry weight in hiring, though they rarely substitute for leadership experience.
- 5Take on board and regulator exposure
Presenting to an audit and risk committee, answering to a regulator such as APRA or the OAIC, and working closely with the executive team is the experience a search panel is usually testing for. It is the difference between managing security and being accountable for it.
Ready to apply as a chief information security officer?
Whether you're working toward becoming a chief information security officer or already are one and want a hand with the next step (sharpening your resume for ATS screening, tightening your cover letter, or knowing what you'll actually be asked at interview), here are examples grounded in this specific role, not generic templates.
What jobs can a chief information security officer move to?
None of the roles chief information security officers typically move into pay more than the role itself. Chief Technology Officer is the closest match. If a bigger salary is the goal, moving up into a senior or principal position within the role is usually the faster route than moving sideways.
| Move to | Typical pay change | Overlap | Retraining |
|---|---|---|---|
| Chief Technology Officer A chief information security officer brings technology risk and resilience insight to the top technology strategy role. | +$0 | 41% | reskill |
| Chief Information Officer A chief information security officer brings security strategy and risk oversight to broader IT leadership. | −$28,100 | 42% | reskill |
| Non-Executive Director A chief information security officer brings board-level cyber risk and governance expertise to a non-executive director role. | −$54,600 | 68% | minimal |
Moves are chosen from Jobs and Skills Australia's Data on Occupation Mobility, which follows income tax records between 2011-12 and 2020-21, together with entry requirements and skill overlap. A known move is one people were seen making in that data. Pay change compares median full-time pay for the two roles.
Who works as a chief information security officer?
The typical chief information security officer is 45 years old; 88% are men, 97% work full-time, and full-timers average 45 hours a week.
- 45
- Median age
- 12%
- Female share
- 97%
- Full-time
- +5h
- vs all-jobs avg
What's it like being a chief information security officer?
The job has two rhythms: a steady cycle of reporting, risk reviews and committee papers, and the sudden disruption of an incident that overrides everything else. Much of the work is persuasion, because a control only holds if the business units agree to live with it. It suits someone who can hold a firm position in front of senior people and stay measured when the news is bad.
What people like
- You see how the whole organisation works. Security touches finance, operations, HR and legal, so the view is broader than in almost any other technical role.
- The mandate comes from the top. Reporting to the chief executive or the board means the argument gets heard without passing through three layers of management first.
- The field keeps moving. Threats, cloud architectures and regulation all shift, so the strategy you set two years ago rarely survives untouched.
- Building a function that holds up. Hiring analysts and engineers, then watching them catch something before it becomes an incident, is the clearest measure of whether the work is landing.
What people find hard
- You carry the consequences. When a breach happens, the security executive is in the room, even if the root cause sits in a business unit that declined a control.
- Funding is a fight every year. Security competes for budget against projects that generate revenue, and justifying spend against incidents that never happened is a difficult case to make.
- Incidents do not keep office hours. Escalations arrive at night and on weekends, and full-time chief information security officers average about 45 hours a week.
- Regulation keeps shifting. Obligations differ across jurisdictions and industries, and keeping the compliance map current is ongoing work that rarely feels finished.
Based on our synthesis of professional-body surveys and public accounts of the role, not first-person verified reviews.
Which industries employ chief information security officers?
Professional, Scientific and Technical Services employs the largest share of chief information security officers, followed by Financial and Insurance Services.
Top employing industries
- 1Professional, Scientific and Technical Services
- 2Financial and Insurance Services
- 3Public Administration and Safety
- 4Health Care and Social Assistance
- 5Information Media and Telecommunications
Ranked by employment share; the source doesn't publish an exact percentage per industry.
| Bachelor degree | 52% | |
|---|---|---|
| Postgraduate | 26% | |
| Diploma / Advanced Diploma | 13% | |
| Other | 9% |
Will AI replace chief information security officers?
AI and automation reach a moderate part of this job. SIEM platforms already correlate and triage alerts, identity tools handle routine access changes, and control mapping against frameworks such as ISO 27001 is increasingly generated from live system data, which shifts how the team spends its time. The harder calls, how much risk to accept, what to fund first and when to notify a regulator, are argued out between people.
Share of typical working time by exposure level
- Compliance and audit reporting against frameworksEvidence collection and control mapping against ISO 27001 or the Essential Eight are increasingly generated from live system data, which trims the paperwork but not the judgement behind it.30%high
- Leading incident responseAutomated correlation and triage speed up the investigation, though someone still has to decide whether to shut a system down, notify a regulator and brief the board.25%low
- Managing the security team and its budgetRostering, workload data and vendor comparison tools help, but hiring decisions, retention conversations and the funding pitch to the chief financial officer remain human work.25%low
- Setting security strategy and risk appetiteAI can summarise threat intelligence and draft policy wording, but the call on how much risk the organisation will accept and what it will pay to reduce it is the executive's.20%moderate
Moves least exposed to AI
These career moves from chief information security officer work are rated low for AI exposure:
- Non-Executive Director
High skill overlap (68%), little retraining to get there, and a low automation-risk profile.
Common questions about becoming a chief information security officer
Straight answers to the questions people ask most.
How much does a chief information security officer earn?
$200,200 per year before tax, though at this level the figure is often a base salary rather than the whole package. Total pay usually includes short and long term incentives, and interim or consulting work is priced per engagement.
How do you become a chief information security officer?
Most arrive after a decade or more in security, IT risk or IT audit. A common path runs from analyst or engineer work into security management, then into a role accountable for the whole function, with a postgraduate qualification or a certification such as CISSP or CISM supporting the step up. 52% of the current workforce holds a bachelor degree and 26% holds a postgraduate qualification.
Are chief information security officers in demand?
Chief information security officers are currently in shortage nationally, and employment is projected to grow 14% over the decade to 2035. The openings that exist sit at the top of a long career path, so they are reached through years of security leadership rather than direct entry.
Will AI replace chief information security officers?
No, but it is changing how the work gets done. Log analysis, alert triage and the mapping of controls to frameworks such as ISO 27001 are increasingly automated, so a smaller team covers more ground. Deciding whether to take a payment system offline during an attack, or telling the board that a known gap will not be fixed this year, is still argued out in the room rather than generated by a tool.
What can a chief information security officer move into?
The most direct move is into broader technology leadership as a chief information officer, which pays $28,100 less and draws on 42% of the same skill set. A chief technology officer role is similar in scope, while a non-executive director position pays $54,600 less and leans on governance and audit committee experience instead of day to day operations. Independent advisory work is another common route at this stage, and often where earnings grow.
How many hours do chief information security officers work?
Full-time chief information security officers average about 45 hours a week, and an incident makes those weeks longer. The role is usually salaried, so extra hours during an escalation are rarely paid separately.
Related roles
- Chief Information Officer
- Chief Technology Officer
- Non-Executive Director
- Cyber Security Architect
- Cyber Security GRC Specialist
- IT Auditor
Not sure this is you? Take the career quiz and get a ranked shortlist of roles that fit how you like to work.