About this role
Founded in Australia in 1917, Sims Limited (Sims) is a global leader in metal recycling and circular solutions for technology. We play a critical role in advancing circularity and decarbonisation by supplying recycled materials and re-purposed products that help preserve our planet.
At Sims, we believe in developing our people. With a strong promote-from-within philosophy and a range of programmes that support continuous learning, we offer opportunities for meaningful, long-term careers. Employing more than 4,100 people worldwide, we operate over 155 facilities across 13 countries. Sims provides the stability, transparency, and professional growth opportunities of a publicly traded organisation, all driven by our purpose: to create a world without waste.
Executive Summary
This role serves as the senior cybersecurity leader for Sims and acts as the organization's designated cybersecurity authority. Reporting to the VP, Infrastructure & Security, the Director is responsible for developing and executing the enterprise cybersecurity, technology risk, compliance, governance, resilience, and information security strategies while ensuring alignment with business objectives, operational realities, and regulatory obligations.
The Director leads cybersecurity operations, cyber risk management, governance, compliance, identity security, third-party risk, operational technology security, customer security assurance, incident response, cyber resilience, and AI security programs. The role provides an independent and transparent assessment of cyber risk while partnering closely with Infrastructure, Enterprise Applications, Data & AI, Legal, Compliance, Operations, and executive leadership.
The Director acts as Sims' day-to-day cybersecurity leader and primary security subject matter expert, providing meaningful risk reporting, strategic recommendations, and operational leadership while supporting executive and Board-level decision making.
Key Responsibilities
1. Cybersecurity Strategy, Governance & Risk Management
- Develop and execute a multi-year cybersecurity and technology risk strategy aligned to Sims' business objectives, risk appetite, operational environment, and regulatory obligations.
- Maintain and continuously improve enterprise cybersecurity governance frameworks, policies, standards, procedures, and security controls.
- Lead the Cybersecurity Governance, Risk, and Compliance (GRC) program.
- Establish and maintain cybersecurity governance forums, decision rights, risk escalation processes, and accountability models.
- Maintain enterprise cyber and technology risk registers, key risk indicators, treatment plans, and risk reporting.
- Provide an independent and transparent view of cyber risk while escalating material concerns through the VP, Infrastructure & Security and established governance channels.
- Support technology strategy, M&A activity, major technology investments, and business initiatives through cybersecurity risk assessments and recommendations.
2. Information Security & Cybersecurity Operations
- Lead enterprise cybersecurity operations, including security monitoring, detection engineering, vulnerability management, threat intelligence, security architecture, identity security, cloud security, data protection, and incident response.
- Establish and maintain technical and administrative controls to protect Sims' information assets.
- Oversee cybersecurity incident response activities and serve as Incident Commander during significant cybersecurity incidents.
- Ensure operational readiness through regular testing of response plans, ransomware playbooks, recovery exercises, and crisis management procedures.
- Drive continuous cybersecurity maturity improvements based on evolving threats and business requirements.
- Retain architecture authority, incident command, and cybersecurity decision-making within Sims regardless of sourcing arrangements.
3. Technology Governance, Compliance & Assurance
- Maintain enterprise technology and security governance standards and control frameworks aligned to NIST CSF, ISO 27001, CIS Controls, and applicable industry requirements.
- Coordinate technology control assessments and remediation activities.
- Partner with Internal Audit, Legal, Compliance, Privacy, and external auditors to support assessments and examinations.
- Maintain evidence demonstrating security control effectiveness.
- Ensure compliance with applicable laws, regulations, contractual obligations, privacy requirements, customer commitments, and reporting requirements.
- Manage interactions with regulators, auditors, cyber insurers, and major customers on cybersecurity matters.
4. Operational Technology (OT) & Industrial Security
- Establish and maintain appropriate cybersecurity capabilities across operational technology environments, including processing facilities, recycling yards, industrial equipment, site networks, sensors, and connected systems.
- Partner with Operations, Engineering, Plant Leadership, and OT vendors to secure environments without disrupting production.
- Establish standards for segmentation, remote access, monitoring, vendor access, and compensating controls for legacy equipment.
- Ensure cybersecurity requirements are incorporated into automation, IoT, and operational technology projects.
- Develop OT-specific incident response and recovery capabilities.
5. Identity, Cloud & Enterprise Platform Security
- Own identity security strategy, including privileged access management, workforce identities, service accounts, third-party access, and access recertification.
- Establish security architecture standards for cloud, infrastructure, networks, endpoints, applications, and SaaS platforms.
- Partner with Infrastructure teams to embed security by design into platform engineering and operational processes.
- Maintain cloud security guardrails for Microsoft Azure, Microsoft 365, SAP, Dynamics 365, and other strategic platforms.
- Ensure backup, recovery, and cyber-resilience controls can withstand destructive cyber events.
6. Application, Data & AI Security
- Establish security requirements for enterprise applications, integrations, APIs, and custom-developed solutions.
- Lead data protection initiatives covering classification, access controls, encryption, retention, and regulatory requirements.
- Partner with Data & AI teams to establish governance and security guardrails for AI, agents, copilots, and automation platforms.
- Conduct threat modeling and security reviews for major technology and AI initiatives.
- Ensure AI solutions are deployed responsibly with appropriate controls around identity, access, data exposure, monitoring, and vendor risk.
7. Third-Party Risk & Customer Security Assurance
- Lead enterprise third-party cybersecurity risk management.
- Establish vendor assessment methodologies, security requirements, ongoing monitoring processes, and remediation expectations.
- Partner with Procurement and Legal to embed cybersecurity requirements into contracts.
- Support customer security reviews, due diligence requests, audits, and security assessments.
- Act as a senior representative during major customer discussions involving cybersecurity, risk, compliance, and security assurance.
8. Cyber Resilience & Business Continuity
- Lead technology resilience, disaster recovery, cyber recovery, and cyber elements of business continuity planning.
- Define recovery objectives for critical business and operational services.
- Conduct technical and executive-level resilience exercises.
- Validate recovery capabilities through realistic testing and evidence-based performance metrics.
- Continuously improve resilience capabilities based on emerging threats, lessons learned, and operational experience.
9. Leadership, Executive Communication & Talent Development
- Lead and develop a high-performing global cybersecurity, risk, and compliance team.
- Manage managed security providers and specialized security partners through outcome-based governance.
- Develop cybersecurity roadmaps, investment recommendations, and staffing plans.
- Provide cybersecurity metrics, risk reporting, and executive briefings to leadership.
- Participate in Executive Leadership Team, Risk Committee, and Board reporting activities in partnership with the VP, Infrastructure & Security.
- Promote a strong enterprise culture of security, accountability, and risk ownership.
A career with Sims provides you with the opportunity to work with an organization whose goal is to be the world’s safest and most responsible recycling company. Our people achieve this by creating a zero-harm workplace, being exemplary members of the communities in which we operate, and being responsible stewards of the environment. We also offer competitive pay and a range of attractive benefits.
Sims is proud to be an equal opportunity employer. We value the diversity of all of our employees and are committed to creating an inclusive working environment where everyone can contribute, advance on merit, and realize their full potential. Sims does not discriminate with regard to race, sex, religion, color, national origin, citizenship status, disability, age, marital or familial status, sexual orientation, gender identity, gender expression, veteran status, housing status, source of income, or any other status protected by federal, state, or local laws. This applies to any employment decision, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Qualified applicants with a disability in need of a reasonable accommodation may request such without fear of reprisal or discrimination.
To achieve our purpose to create a world without waste to preserve our planet, we are guided by our Principles of Purpose: Be Safe + Well, Band Together, Be Accountable + Transparent, Consistently Innovate, Inspire with Purpose, Celebrate + Have Fun.