The Opportunity
An organisation in Auckland is at the very beginning of a meaningful digital transformation led by a newly appointed CTO who’s building the function properly from the ground up.
To give you a sense of timing: the CTO is currently looking for office space, and the wider operating model is being shaped in real time. If you enjoy getting in early, influencing how things are done, and leaving a clear “before and after” in an environment, this is that kind of role.
This is a senior, high-trust position where you’ll own and uplift cloud operations in an AWS environment, while also playing a key part in strengthening the organisation’s security assurance and compliance posture (ISO 27001 / SOC 2 Type II).
There’s already dedicated DevOps capability - this role is intentionally focused on cloud/platform engineering, operational reliability, and governance, rather than being a pure DevOps delivery role.
Why Join
- Be there at the start: this is transformation right from day one you’ll help shape the foundations, not inherit them.
- A CTO who leads with ownership: a practical leadership style that values clarity, accountability, and people taking real responsibility for outcomes.
- Real autonomy: you’ll have the mandate to improve “how we run cloud” and lift operational maturity.
- Commercially meaningful security work: contribute to and help mature ISO 27001 / SOC 2 Type II programmes that matter to customers and growth.
- Engineering partnership (without being the DevOps person): work closely with Engineering/DevOps to ensure controls and production readiness are strong.
- Build what scales: implement practical patterns, documentation and tooling that reduce friction and improve security posture over time.
What You’ll Be Doing
- Cloud / Platform Engineering & Operational Reliability (primary focus)
- Own and improve AWS platform foundations (identity, networking, governance, reliability and operational readiness)
- Design and operate secure, scalable AWS components and patterns (e.g. IAM, VPC, DNS, load balancing, logging/metrics, backup and DR)
- Lift operational maturity through improved monitoring/alerting, runbooks, incident response and post-incident follow-through
- Reduce toil by automating repeatable operational work (scripting and infrastructure-as-code practices where appropriate)
- Partner with Engineering/DevOps to improve production readiness and ensure controls are met, without owning all DevOps execution
- Information Security Compliance & Assurance (key mandate)
- Maintain practical security documentation (access control, incident response, vendor due diligence, data handling/retention)
- Support customer security questionnaires and assurance requirements with confident written responses
- Coordinate remediation actions and help embed secure-by-default practices into cloud operations
- Corporate IT / Identity & Access (supporting scope)
- Administer identity and access across core tools (e.g. Google Workspace, Slack, GitHub and key systems)
- Contribute to device security posture (patching, encryption, baseline controls) and scalable internal support practices
- Maintain asset registers and clear internal documentation / knowledge base
About You (Ideal Background)
You’ll likely thrive here if you’ve worked in environments where reliability and security aren’t theoretical, they’re business-critical, and you’ve had the trust to own outcomes.
This could look like:
- B2B SaaS scale-ups or PE-backed SaaS going through growth and modernisation, where you’ve worn a few hats and built maturity as you go
- SaaS product companies selling into enterprise and/or regulated customers, where security reviews, questionnaires and evidence are part of BAU
- Cloud platform / SRE / infrastructure teams where you’ve owned AWS foundations and supported production operations
- AWS-focused consultancies/MSPs (only if you’ve had genuine ongoing ownership: incidents, monitoring, runbooks, continuousnot just project delivery)
What You’ll Bring
- 3–6+ years’ experience in cloud/platform engineering, infrastructure engineering, SRE-style operations or security-minded ops roles
- Strong hands-on experience operating in AWS (production exposure matters)
- Confidence with automation and operational tooling; scripting capability is highly valued
- Interest in (and ideally exposure to) ISO 27001 and/or SOC 2
- Strong written communication documentation, controls, evidence and clear technical responses are a key part of this role
- A calm, pragmatic style: you can prioritise, improve maturity and keep momentum in a lean environment
Nice to have
- Security certifications (ISO Lead Implementer, CISSP, CISM)
- MDM tooling exposure (JAMF / Intune / Kandji)
- B2B SaaS and/or regulated environment experience
Next Steps
To keep things simple, please submit your application through this advert. We’ll review applications as they come in and be in touch.
For any questions, call Teresa Jordan on 027 376 4884 and quote Job ID: 17789 for a confidential chat. Due to high volume, feel free to apply and follow up in a couple of days if you haven’t heard anything.
To apply for this vacancy, you MUST be a New Zealand citizen, resident, or have already secured the right to work in New Zealand and therefore hold a valid visa.
At the appropriate stage we will request your references, we ask that you do not include them on your CV when applying.
Tribe is a group of specialist teams. Each of who truly understand their world, and together they partner to understand yours. Whether you’re looking for your next opportunity or recruiting, we’re all about bringing people together for a shared purpose. Find your people.