Tim N | Security Governance, Risk & Compliance

I help organisations strengthen security through practical governance, risk management and assurance. Currently a Senior Security Compliance Analyst at Foodstuffs North Island, I lead third-party security assessments and support PCI DSS compliance, audit readiness, control validation and remediation across a complex retail and technology environment.

My earlier experience at RUSH spans ISO 27001, PCI DSS, security operations, vulnerability management and incident response. I combine this security expertise with more than 20 years of commercial leadership, analytical thinking and stakeholder management.

Professional Experience

Foodstuffs North Island | Senior Security Compliance Analyst

Feb 2026 - Present

Lead third-party security assessments and support PCI DSS compliance across a complex retail and technology environment. Coordinate audit evidence, control validation, risk treatment and remediation while partnering with technology teams, business stakeholders, Legal, Procurement, auditors and suppliers.

RUSH | Security Compliance & Operations Specialist

Nov 2023 - Jan 2026

Co-led ISO 27001 and PCI DSS compliance programmes, contributing to successful external audits. Also worked across security operations, vulnerability management, incident response, cloud and endpoint controls, and organisation-wide security awareness.

HF Holidays | Cyber Security Consultant

Oct-Nov 2023

Conducted remote penetration testing and vulnerability assessments of web infrastructure, producing clear findings and practical remediation guidance in collaboration with the organisation’s IT team.

Earlier Career | Commercial Leadership

2002-2023

Progressed through senior commercial planning and leadership roles at NZME, MediaWorks, The Radio Bureau and RadioWorks. Led specialist teams and developed extensive capability in strategic analysis, communication, stakeholder management and business decision-making.

Core Expertise

Security Governance, Risk & Compliance

PCI DSS, ISO 27001, NIST CSF, policies and control governance

Third-Party Security Assurance

Supplier assessments, security due diligence and risk treatment

Audit & Control Assurance

Audit readiness, evidence coordination, control validation and remediation

Technical & Commercial Foundation

Security operations, vulnerability management, cloud and endpoint security

I combine current GRC and assurance experience with a technical security background and more than 20 years of commercial leadership. This enables me to translate complex requirements, build strong stakeholder relationships and develop practical controls that reduce risk while supporting business objectives.

Professional Certifications

Validated expertise across leading industry certifications:

CompTIA Certifications

  • CompTIA PenTest+ certified
  • CompTIA Security+ certified
  • CompTIA ITF+ certified

ISC2 Certifications

  • ISC2 CC (Certified in Cybersecurity) certified
  • ISC2 Member

Microsoft Certifications

  • Microsoft SC-900 certified
  • Microsoft AZ-900 certified

ISACA Certifications

  • ISACA CCOA certified
  • ISACA Member & ISACA Auckland Chapter
  • Currently pursuing ISACA CRISC

Google Certifications

  • Google Cloud Cybersecurity Certificate
  • Google Cybersecurity Certificate

Other Certificates

  • TryHackMe Security Engineer
  • Microsoft Cybersecurity Analyst

Key Responsibilities at FSNI

Third-Party Risk Management

Leading supplier security assessments, evaluating security controls and coordinating appropriate risk treatment.

PCI DSS & Audit Readiness

Supporting PCI DSS compliance through audit preparation, evidence management, control validation and remediation tracking.

Governance & Control Assurance

Maintaining risk registers, policies, standards and compliance documentation to support effective security governance.

Security Risk Advisory

Partnering with technology teams, business stakeholders, Legal, Procurement, auditors and vendors to embed security requirements and support informed decisions.

At Foodstuffs North Island, I help strengthen enterprise security by connecting governance requirements with practical business decisions. My role brings together supplier assurance, PCI DSS compliance, control governance and cross-functional collaboration across a complex retail and technology environment.

Educational Background

AUT & Institute of Data

Cyber Security Program graduate, acquiring practical skills in security operations, risk management, and compliance through intensive training.

University of Southampton

BSc (Hons) in Environmental Science, providing strong analytical foundations and methodical research approaches.

Continuous Learning

Pursuing advanced certifications including ISACA CRISC to further enhance professional expertise.

Connect With Tim

LinkedIn

Connect professionally at www.linkedin.com/in/timncyber

Collaboration

Open to discussing security strategies and sharing industry insights

Tim is passionate about advancing cyber security practices and welcomes connections with fellow professionals interested in building more secure digital environments.

Made with