Australian women in cybersecurity are doing work that most people never see: securing the networks that hospitals run on, setting the protocols that protect financial data, and advising governments on threats that don't yet have names. The field has historically been male-dominated, but that's changing. Not slowly, either. Women now lead some of the country's most consequential security functions.
Why this list matters now
Cybersecurity in Australia sits at a genuinely high-stakes moment. The federal government has allocated significant funding to critical infrastructure protection following a string of high-profile breaches across the retail, health, and telecommunications sectors. The people in charge of the response are, increasingly, women. This list captures the practitioners and executives who are shaping that response at the organisational and policy level.
It's also a deliberately practical list. The names below hold real roles with real mandates. Their work connects directly to the Australian women in technology policy who are drafting the legislative frameworks, and to the data leaders covered separately in our roundup of Australian women in data and analytics. The ecosystem is interconnected.
The practitioners and executives
Abigail Bradshaw CSC leads the Australian Cyber Security Centre (ACSC) as head of the agency within the Australian Signals Directorate. Bradshaw has shaped Australia's national cybersecurity posture through the Essential Eight mitigation strategies and the Cyber Threat Report, which the ACSC publishes annually. Her public communications work has lifted the baseline understanding of threat categories across both government and the private sector.
Rachel Noble PSM served as Director-General of the Australian Signals Directorate, the intelligence agency that houses the ACSC. Noble's tenure oversaw the agency's transition to a fully statutory body in 2018 and the significant expansion of its workforce. Few people in Australian public life have had more direct responsibility for the country's offensive and defensive cyber capabilities.
Troels Oerting notwithstanding, the most consequential cybersecurity decisions at major Australian banks in recent years have increasingly run through women. Lynwen Connick served as Chief Information Security Officer at ANZ for an extended period and helped build the institutional security function that the bank relies on today. Her work at ANZ placed her among the most senior CISOs at any ASX-listed financial institution during her tenure.
Margie Benbow leads security consulting at a major professional services firm and has built one of the larger cybersecurity practices in the country. Her work spans incident response, risk advisory, and board-level governance uplift. Clients include listed companies across the energy, financial services, and government sectors.
Narelle Devine has served as Chief Information Security Officer for the Department of the Prime Minister and Cabinet, one of the most sensitive security environments in Australian government. Devine's background spans both technical architecture and executive leadership. She's been a visible advocate for lifting cybersecurity literacy at the senior leadership level, arguing that boards need to treat security as a governance issue, not just an IT one.
Jane Morgan runs the security practice at a major consulting firm and focuses specifically on operational technology security, which covers the industrial control systems that underpin power grids, water treatment facilities, and transport infrastructure. It's a narrower specialty than enterprise IT security, but the consequences of failure are correspondingly higher.
Educators and researchers
Not all the relevant work happens inside organisations. Several Australian women are building the next cohort of security professionals through academic and training roles.
Professor Jill Slay AM is one of Australia's most decorated cybersecurity researchers. Slay spent years at the University of South Australia and later at La Trobe University, where she ran the Australian Centre for Cyber Security. Her research into digital forensics and critical infrastructure protection has influenced both academic curriculum and government policy. She's one of the few people in the country whose work has shaped both the practitioner and regulatory sides of the field.
Associate Professor Suranga Seneviratne at the University of Sydney conducts research on network security and privacy, with a particular focus on mobile systems. Her work has been published in the top-tier venues in her field and shapes how engineers think about privacy risk in connected devices.
What these careers have in common
Across the practitioners, executives, and researchers on this list, three things repeat. First, most of them moved into cybersecurity from adjacent fields: law, engineering, intelligence, mathematics. The field didn't produce them directly; they arrived and reshaped it. Second, nearly all of them are active in public communication. Cybersecurity as a field suffers from a communication gap between practitioners and decision-makers. The women here are closing it. Third, most hold or have held roles where failure has genuine national consequences. These aren't advisory positions. They're operational ones.
Cybersecurity sits at the intersection of technology, governance, and risk. The women here are evidence that the most consequential work in that intersection is not reserved for any single demographic. The field is broader and more varied than its public image suggests, and the leaders shaping it reflect that.
feisty