Skip to content
careertips

Home IT & Software

Chief Information Security Officer

A chief information security officer heads an organisation's security function at executive level, setting the strategy, policy and budget that keep its data and systems safe.

Illustration of a person working as a chief information security officer
Median salary*
$200,200

3.6%vs last year, before tax

People employed
6,800

1.5%vs last year

Projected growth*
+14%

to 2035

AI exposure*
Moderate
automation risk
Average hours*
45/wk

+5h vs all jobs

Shortage status*
In shortage

national

A chief information security officer sits at executive level, usually reporting to the chief executive or the board, and carries final responsibility for how an organisation manages cyber risk. The scope separates it from a security manager or architect: governance, regulatory obligations and budget take up as much of the week as technology does, and the job turns on translating technical risk into decisions a board can act on. Most work in larger organisations or regulated sectors such as financial services, government and health, where a dedicated security executive is expected rather than optional.

How much do chief information security officers earn?

The median full-time salary for a chief information security officer is $200,200 per annum, before tax, up $42,700 since 2018.

Pay at this level depends on the size of the organisation, the scope of the security function and whether the role reports to the chief executive or the board. Packages usually combine base salary with short and long term incentives, so the base figure can understate total earnings. Interim and consulting work is common at the top of the market, where rates are set per engagement rather than per year.

Median annual salary, 2018–2028
Salaries rose $42,700 a year to 2024; the dashed line shows a projection to 2028 based on the real ABS Wage Price Index growth rate, not a role-specific forecast.
Full chief information security officer salary breakdown →

What does a chief information security officer do day to day?

The list below is what fills most weeks; the exact mix shifts with seniority and whatever stage the current work is at.

  • Setting information security strategy and policy that line up with business goals and the organisation's stated risk appetite
  • Leading the response when a breach or critical vulnerability hits, from containment through to notifying regulators and the board
  • Running risk assessments, vulnerability programs and compliance audits against frameworks such as ISO 27001 and the Essential Eight
  • Hiring, structuring and mentoring the security team, including deciding who owns which risk across the business
  • Briefing executives and the board on security posture, regulatory obligations and the trade-offs behind each spending decision

What skills do chief information security officers need?

Employers look for cyber security, risk and internal controls, regulatory compliance, backed by Security Information and Event Management (SIEM) platforms fluency and strong stakeholder management.

Specialist skills

  • Cyber security
  • Risk and internal controls
  • Regulatory compliance
  • Strategy development

Software and tools

  • Security Information and Event Management (SIEM) platforms
  • Identity and Access Management (IAM) systems
  • Vulnerability scanning and patch management tools
  • Risk management frameworks (NIST, ISO 27001)

General skills

  • Stakeholder management
  • People leadership
  • Written communication
  • Problem solving

Is the job growing?

About 6,800 people work as chief information security officers in Australia, and employment is projected to grow 14% over the decade to 2035. That's healthy, above-average growth, and the role should stay in solid demand.

Employment, 2015–2024, projected to 2035
Employment grew 700 to 2024; the dashed line shows the official projection to 2035.

How do you become a chief information security officer?

Here's the path most chief information security officers take, step by step.

  1. 1
    Build a technical or risk foundation

    A bachelor degree in information technology, computing, cyber security or a related field is the usual starting point, and 52% of the people in the role today hold one. Degrees in IT audit, risk or compliance can lead here too, because the job is as much about governance as technology.

  2. 2
    Work in hands-on security or assurance roles

    Security analyst, engineer, architect and IT auditor positions teach you how controls behave in practice, which is the evidence you draw on later when you argue for a control at executive level. Expect several years here, ideally including a stint in incident response or a major uplift program.

  3. 3
    Move into security management

    Leading a team, owning a budget and reporting to a chief information officer or a risk committee is the step that separates operational work from executive work. It is also where you learn to brief people who do not want technical detail.

  4. 4
    Add a postgraduate qualification or certification

    A master's degree in cyber security or an MBA is common at this level, and 26% of the workforce holds a postgraduate qualification. Certifications such as CISSP or CISM carry weight in hiring, though they rarely substitute for leadership experience.

  5. 5
    Take on board and regulator exposure

    Presenting to an audit and risk committee, answering to a regulator such as APRA or the OAIC, and working closely with the executive team is the experience a search panel is usually testing for. It is the difference between managing security and being accountable for it.

Ready to apply as a chief information security officer?

Whether you're working toward becoming a chief information security officer or already are one and want a hand with the next step (sharpening your resume for ATS screening, tightening your cover letter, or knowing what you'll actually be asked at interview), here are examples grounded in this specific role, not generic templates.

What jobs can a chief information security officer move to?

None of the roles chief information security officers typically move into pay more than the role itself. Chief Technology Officer is the closest match. If a bigger salary is the goal, moving up into a senior or principal position within the role is usually the faster route than moving sideways.

Move toTypical pay changeOverlapRetraining
Chief Technology Officer

A chief information security officer brings technology risk and resilience insight to the top technology strategy role.

+$0
41%reskill
Chief Information Officer

A chief information security officer brings security strategy and risk oversight to broader IT leadership.

$28,100
42%reskill
Non-Executive Director

A chief information security officer brings board-level cyber risk and governance expertise to a non-executive director role.

$54,600
68%minimal

Moves are chosen from Jobs and Skills Australia's Data on Occupation Mobility, which follows income tax records between 2011-12 and 2020-21, together with entry requirements and skill overlap. A known move is one people were seen making in that data. Pay change compares median full-time pay for the two roles.

Who works as a chief information security officer?

The typical chief information security officer is 45 years old; 88% are men, 97% work full-time, and full-timers average 45 hours a week.

45
Median age
12%
Female share
97%
Full-time
+5h
vs all-jobs avg

What's it like being a chief information security officer?

The job has two rhythms: a steady cycle of reporting, risk reviews and committee papers, and the sudden disruption of an incident that overrides everything else. Much of the work is persuasion, because a control only holds if the business units agree to live with it. It suits someone who can hold a firm position in front of senior people and stay measured when the news is bad.

What people like

  • You see how the whole organisation works. Security touches finance, operations, HR and legal, so the view is broader than in almost any other technical role.
  • The mandate comes from the top. Reporting to the chief executive or the board means the argument gets heard without passing through three layers of management first.
  • The field keeps moving. Threats, cloud architectures and regulation all shift, so the strategy you set two years ago rarely survives untouched.
  • Building a function that holds up. Hiring analysts and engineers, then watching them catch something before it becomes an incident, is the clearest measure of whether the work is landing.

What people find hard

  • You carry the consequences. When a breach happens, the security executive is in the room, even if the root cause sits in a business unit that declined a control.
  • Funding is a fight every year. Security competes for budget against projects that generate revenue, and justifying spend against incidents that never happened is a difficult case to make.
  • Incidents do not keep office hours. Escalations arrive at night and on weekends, and full-time chief information security officers average about 45 hours a week.
  • Regulation keeps shifting. Obligations differ across jurisdictions and industries, and keeping the compliance map current is ongoing work that rarely feels finished.

Based on our synthesis of professional-body surveys and public accounts of the role, not first-person verified reviews.

Which industries employ chief information security officers?

Professional, Scientific and Technical Services employs the largest share of chief information security officers, followed by Financial and Insurance Services.

Top employing industries

  1. 1Professional, Scientific and Technical Services
  2. 2Financial and Insurance Services
  3. 3Public Administration and Safety
  4. 4Health Care and Social Assistance
  5. 5Information Media and Telecommunications

Ranked by employment share; the source doesn't publish an exact percentage per industry.

Highest qualification held
Bachelor degree
52%
Postgraduate
26%
Diploma / Advanced Diploma
13%
Other
9%

Will AI replace chief information security officers?

AI and automation reach a moderate part of this job. SIEM platforms already correlate and triage alerts, identity tools handle routine access changes, and control mapping against frameworks such as ISO 27001 is increasingly generated from live system data, which shifts how the team spends its time. The harder calls, how much risk to accept, what to fund first and when to notify a regulator, are argued out between people.

high · 30%
moderate · 20%
low · 50%

Share of typical working time by exposure level

  • Compliance and audit reporting against frameworks
    Evidence collection and control mapping against ISO 27001 or the Essential Eight are increasingly generated from live system data, which trims the paperwork but not the judgement behind it.
    30%
    high
  • Leading incident response
    Automated correlation and triage speed up the investigation, though someone still has to decide whether to shut a system down, notify a regulator and brief the board.
    25%
    low
  • Managing the security team and its budget
    Rostering, workload data and vendor comparison tools help, but hiring decisions, retention conversations and the funding pitch to the chief financial officer remain human work.
    25%
    low
  • Setting security strategy and risk appetite
    AI can summarise threat intelligence and draft policy wording, but the call on how much risk the organisation will accept and what it will pay to reduce it is the executive's.
    20%
    moderate

Moves least exposed to AI

These career moves from chief information security officer work are rated low for AI exposure:

  • Non-Executive Director

    High skill overlap (68%), little retraining to get there, and a low automation-risk profile.

Common questions about becoming a chief information security officer

Straight answers to the questions people ask most.

How much does a chief information security officer earn?

$200,200 per year before tax, though at this level the figure is often a base salary rather than the whole package. Total pay usually includes short and long term incentives, and interim or consulting work is priced per engagement.

How do you become a chief information security officer?

Most arrive after a decade or more in security, IT risk or IT audit. A common path runs from analyst or engineer work into security management, then into a role accountable for the whole function, with a postgraduate qualification or a certification such as CISSP or CISM supporting the step up. 52% of the current workforce holds a bachelor degree and 26% holds a postgraduate qualification.

Are chief information security officers in demand?

Chief information security officers are currently in shortage nationally, and employment is projected to grow 14% over the decade to 2035. The openings that exist sit at the top of a long career path, so they are reached through years of security leadership rather than direct entry.

Will AI replace chief information security officers?

No, but it is changing how the work gets done. Log analysis, alert triage and the mapping of controls to frameworks such as ISO 27001 are increasingly automated, so a smaller team covers more ground. Deciding whether to take a payment system offline during an attack, or telling the board that a known gap will not be fixed this year, is still argued out in the room rather than generated by a tool.

What can a chief information security officer move into?

The most direct move is into broader technology leadership as a chief information officer, which pays $28,100 less and draws on 42% of the same skill set. A chief technology officer role is similar in scope, while a non-executive director position pays $54,600 less and leans on governance and audit committee experience instead of day to day operations. Independent advisory work is another common route at this stage, and often where earnings grow.

How many hours do chief information security officers work?

Full-time chief information security officers average about 45 hours a week, and an incident makes those weeks longer. The role is usually salaried, so extra hours during an escalation are rarely paid separately.

Related roles

Not sure this is you? Take the career quiz and get a ranked shortlist of roles that fit how you like to work.

careertips is an independent, data-first guide to Australian careers, built to help you understand what a role actually pays and where it can take you, not to sell you something.

Where available, figures are sourced from Jobs and Skills Australia and the Australian Bureau of Statistics (CC BY 4.0). Figures marked * are our own analysis. How we source and label our data. Last updated 2026-09-01.