Andy Evans

Andy Evans Email and Phone Number

Head of Cyber Security Operations | CISSP | Executive Cyber Leadership | Cyber Security Risk | ISO 27001 | Essential Eight | Strategic Planning | Identity and Access Management| Threat & Vulnerability Management @ Metcash
Andy Evans's Location
Sydney, New South Wales, Australia, Australia
Andy Evans's Contact Details

Andy Evans personal email

n/a

Andy Evans phone numbers

About Andy Evans

I am a seasoned Cybersecurity Executive Leader with a CISSP certification and a proven track record of success in guiding organisations through complex security challenges. With extensive experience in Cybersecurity Operations and Executive Leadership Management, my leadership ethos centers around values such as Integrity, Developing Others, and Strategic Vision.I am known for my meticulous attention to detail, logical problem-solving, and measured precision, I excel in driving cybersecurity initiatives that align with business objectives. With a focus on fostering cross-functional collaboration, I consistently delivers measurable outcomes by leveraging a diverse skill set that includes research, analysis, and effective communication.My expertise spans a range of critical areas, including Security Operations Center (SOC) Management, Cybersecurity Policy and Compliance, and Security Incident Investigation. Moreover, my transferable skills in empathy, active listening, and strategic planning further enhance his ability to foster collaboration and drive impactful cybersecurity strategies.With a steadfast commitment to ongoing learning and professional excellence, I am prepared to lead organisations towards robust cybersecurity postures while upholding the highest standards of integrity and ethical conduct.CISO | Chief Information Security Officer | Head of Security | Cybersecurity Executive | Security Leadership | Information Security Management | Security Strategy |Risk Management | Security Governance | Compliance Management | Security Operations | Incident Response | Threat Intelligence | Vulnerability Management | Identity and Access Management (IAM) | Security Awareness Training | Security Policy Development | Data Protection | Security Assessment | Security Auditing | Security Technology Evaluation and Implementation | Business Continuity and Disaster Recovery | Vendor Risk Management | Cloud Security

Andy Evans's Current Company Details
Metcash

Metcash

View
Head of Cyber Security Operations | CISSP | Executive Cyber Leadership | Cyber Security Risk | ISO 27001 | Essential Eight | Strategic Planning | Identity and Access Management| Threat & Vulnerability Management
Andy Evans Work Experience Details
  • Metcash
    Head Of Security Operations
    Metcash Nov 2024 - Present
    Macquarie Park, Nsw, Au
    Reporting to the Group CISO, MetcashAs Head of Security Operations at Metcash, I lead the strategic and operational functions of the Security Operations Team with a focus on strengthening incident detection, response, and continuous security improvement across our cloud and on-premise environments. My role spans managing the SOC in collaboration with our Managed Security Service Provider (MSSP) and directly overseeing a Security Engineering team (3rd level analyst, DevSecOps and Security Engineers for IT/OT).Key Responsibilities• Azure Cloud Security Management: Oversee the full Azure security stack, including Defender for Cloud XDR, Sentinel, APIM, and Key Vault, ensuring alignment with best practices and compliance across Metcash’s cloud infrastructure.•Incident Response Leadership: Lead and refine incident response protocols, including MSSP, IT teams, business units, and external vendors, to ensure coordinated, rapid responses that safeguard Metcash's critical assets.•MSSP Performance & SLA Oversight: Continuously monitor and manage MSSP performance against SLAs, ensuring accountability and continuous alignment with Metcash's security objectives.•Continuous Improvement & Compliance: Drive SOC alignment with NIST CSF and ASD8 standards through continuous enhancement and compliance initiatives. Champion process automation and response optimization across teams.•Red Team Collaboration: Execute security exercises, integrating findings to strengthen SOC detection and response.•High-Performance Team Development: Collaborate with the CISO to implement a forward-looking operating model that supports maturity. Build and mentor a high-performing security team focused on strategic security outcomes.Through these initiatives, my role at Metcash focuses on embedding a proactive security posture that strengthens operational resilience and fosters a culture of security excellence across the organization.
  • Alpha Trading
    Co-Founder
    Alpha Trading Mar 2021 - Present
    Online, Oo
    Alpha Trading is a community of volatility traders. We provide tools and educational resources to help people learn to trade volatility. Our community is found on Twitter, Reddit, Facebook, web sites, and in our world-class discord server.We use proper maths, statistics and probabilities in order to trade volatility. Our products include innovative, disruptive, best of class volatility trading indicators (Projection Boss, STDEV Trading Ranges, Variance, Volatility Radar, and many more) available even to Retail Traders directly on Trading View.
  • Monetari
    Managing Director
    Monetari Jul 2019 - Present
    Part Time Trader ( Options, and Volatility, Entropy, Probability and Statistics based delta trading)
  • Career Break
    Jun 2024 - Oct 2024
    During my career break, I am focused on personal development and skill enhancement after two decades in Information Technology and over a decade in senior management roles within operations and security (too many 60+ hour weeks to count!). I dedicated time to: • Caring for my ill wife • Travel • Professional Learning: Completing various courses and currently studying for my ISC2 CCSP certification to enrich my knowledge. • Reflection and Recharge: Taking this opportunity to recharge for future challenges. This enriching experience provided me with renewed insights and a fresh perspective, positioning me to contribute effectively to my next professional endeavor.
  • Downer
    Head Of Cyber Security Operations
    Downer Sep 2021 - May 2024
    North Ryde, Nsw, Au
    Head of Cyber Security Operations | Reporting to Group CIO | Led Operations across Australia, NZ & InternationalAs the Head of Cyber Security Operations, I was responsible for leading day-to-day security operations, incident response, identity management, and threat analysis, ensuring alignment with Downer's strategic goals across Australia, NZ, and international sites. I directed a team of 9 direct reports and 30+ MSSP resources, managing an OPEX budget of over $9M and CAPEX of $3-10M.Key Achievements:• Cyber Security Strategy: Spearheaded the development of Downer's Cyber Security Operating Model, seamlessly integrating Security Operations, Incident Response, Vulnerability & Threat Management, and Identity and Access Management (IAM), resulting in a high-performing team with all members earning CISSP certification.• Strategic Leadership: Co-led the Cyber Security Strategy, focusing on PAM, MFA, IAM, cyber awareness, governance, and cloud security. Prioritized solutions aligned with best practices to safeguard against evolving cyber threats.• Azure Cloud Security: Led the deployment of Microsoft Defender for Cloud, Endpoint, Azure Entra, MFA, Conditional Access Policies, Azure Key Vault, and Purview, enhancing Azure cloud security. Integrated Entra with Defender for Identity and Okta, implementing MFA and risk-based policies for robust identity management.• ISO27001 Certification: Implementation of ISO27001, coordinating stakeholder engagements, training, and audits to secure certification and strengthen Downer's information security posture. • Essential Eight Controls: Led the implementation of the ACSC Essential Eight Controls, significantly reducing vulnerability exposure and strengthening Downer’s cyber defence posture.• Governance & Risk Management: Ensured robust governance frameworks were in place, engaging with General Counsel and Internal Audit on areas such as DFIR, insider risk management, and fraud controls.
  • Downer
    Head Of Service Delivery (Inc Sec Ops)
    Downer Sep 2016 - Sep 2021
    North Ryde, Nsw, Au
    As the Head of Service Delivery (Run) at Downer, reporting directly to the Group CIO, I led all day-to-day operations for Infrastructure (Cloud & On-Prem), EUC, Network, Security and applications supporting the business. With accountability for a budget exceeding $100 million and leadership over a diverse team of over 70 full-time and fixed-term staff, along with 350 vendor staff across multiple locations, I drove operational excellence and efficiency.Team Size 70 (300+ MSP) | Budget 100+ (OPEX) / 3-10 (CAPEX) Million Achievements• My executive engagement with the Group CFO and Group CIO was pivotal in driving transformational initiatives focused on refining operating models and strategic sourcing strategies. Through collaborative discussions and strategic planning sessions, we identified opportunities to streamline processes, optimize resource allocation, and drive cost efficiencies across the organization. • I orchestrated the overhaul of the IT Operating Model, yielding over $30 million in savings over five years while enhancing operational efficiency and service delivery. Through strategic vendor management and process optimisation, we achieved significant cost savings, invested in critical areas like Cyber Security and Service Integration, and streamlined operations with ServiceNow implementation. •As directing sponsor I migrated workloads to Azure, deploying tools like Intune, Azure Virtual Desktop, VMware, and Linux workloads for improved scalability.•Achieved 60-70% cloud adoption at Downer, enhancing infrastructure efficiency and reducing reliance on on-premises systems.• I fostered a culture of performance-based management and continuous improvement, resulting in a remarkable increase in staff engagement to 91%.
  • Downer
    General Manager Service Management & It Ops (Inc Sec Ops)
    Downer Oct 2014 - Sep 2016
    North Ryde, Nsw, Au
    As the General Manager of Service Management and IT Operations at Downer, I spearheaded a comprehensive overhaul of our team's approach, transitioning from a technology-centric model to one intricately aligned with our business divisions. Our primary objective was to optimize the delivery of critical business services across various sectors, including Mining, Rail, Infrastructure Services, Engineering, Construction & Maintenance, and internal group offices and shared services.Team Size 21 (45+ MSP) | Budget 15+ (OPEX) and 1-3 (CAPEX) Million Core areas of my team included:• Service Strategy• Service Transition – encompassing QA Testing, Release Management, Change Management, and Service Asset and Configuration Management• Service Operations – managing Incident, Problem, and Request Fulfillment processes• Service Management and Business Relationship Management• End User Technology • IT Purchasing – handling Procurement and IT Request Fulfillment•Security OperationsAchievements • Under my leadership, we restructured our service management and IT operations team, realigning its focus to prioritize the unique needs of each business division. By cultivating a culture of proactive problem-solving, we effectively minimized disruptions and ensured uninterrupted service delivery. Our team functioned as the first responders, swiftly addressing issues and implementing preventive measures to mitigate future incidents.• I led a transformative restructuring of our team, shifting focus to align with business divisions and emphasizing proactive problem-solving. This resulted in substantial cost savings, including a 33% reduction in managed print service costs and annualized savings of 5 million dollars. Additionally, we initiated a new operating model to further enhance efficiency and successfully shifted the perception of IT from a cost center to a strategic business enabler, driving value across the organisation.
  • Wesfarmers Insurance
    It Portfolio Manager
    Wesfarmers Insurance Nov 2013 - Oct 2014
    Au
    As the Portfolio Manager (Core Insurance) for Wesfarmers Insurance Australian Underwriting businesses, including Lumley, Affinity, and Direct channels (such as Coles Insurance and Wesfarmers Insurance), I held the pivotal role of overseeing the ongoing support and maintenance of all applications and technology platforms within the Core Insurance portfolio.Team Size 15 (45+ MSP) | Budget 15+ (OPEX) and 3 (CAPEX) MillionKey Responsibilities:• Oversaw mission-critical applications supporting various functions such as new business writing, underwriting, rating, and claims processing, ensuring seamless operations and adherence to business requirements.• Implemented and managed ITIL processes including Incident, Problem, Change, Configuration, Vendor, SLA, Capacity, Release, and Services Continuity management, fostering a culture of efficiency and compliance.• Led application lifecycle management, from inception to retirement, optimising performance and ensuring alignment with business objectives.•Actively engaged with business stakeholders to understand their needs, prioritise requirements, and provide tailored solutions to drive business success.Achievements:•Implemented a comprehensive ITIL framework, streamlining operations and enhancing service delivery efficiency through standardized processes and best practices.• Introduced automation solutions to streamline repetitive tasks, reducing manual effort and improving overall productivity.• Established strategic partnerships with vendors, negotiating favourable terms and ensuring alignment with business goals, resulting in improved service levels and cost savings.• Strengthened relationships with business stakeholders through regular communication, collaboration, and alignment of IT initiatives with business objectives, resulting in improved satisfaction and business outcomes.
  • Singtel
    Associate Director - Service Management
    Singtel Dec 2012 - Nov 2013
    Singapore, Sg
    As the Associate Director (Service Management) reporting to the Vice President of Infrastructure & Operations, I held a pivotal senior management position within the Group Information Technology division, tasked with overseeing governance of Group IT (GIT) assets across Australia and Singapore. My role emphasised the implementation of robust ITIL-based operational governance to ensure the integrity and separation of duties between Development and Production environments, encompassing a vast portfolio of 750+ applications and 10,000+ servers.Team Size 15 (30+ MSP) | Budget 3+ (OPEX)Achievements:• Established regional service management SLAs, enhancing transparency and accountability in service delivery.• Instituted a dedicated regional service management function, streamlining operations and improving service quality.• Recognised as a member of the Crisis Management Board, showcasing leadership and crisis preparedness.• Received an upward feedback score of 4.14, ranking in the top 20% of the company, reflecting strong leadership and employee satisfaction.
  • Optus
    Production Services Manager
    Optus Nov 2010 - Dec 2012
    Macquarie Park, Nsw, Au
    As the Production Services Manager reporting to the Head of Service Operations, this senior management role within the Information Technology Group encompassed various responsibilities. These included leading a team of subject matter experts across multiple ITILv3 life cycles, with PNL accountability exceeding 1.5 million AUD. The role involved championing and driving Service Management processes across IT, fostering effective relationships with senior leaders, implementing continuous improvement initiatives, and producing weekly production performance reports. Achievements included receiving an upward feedback management score above the company average, a personal development rating in the top 10% of the company, leading service management for a $30 million Web Transformation project, and selection for a future leaders program.Team Size 10 (30+ MSP) | Budget 1.5+ (OPEX)
  • Optus
    Service Manager
    Optus Feb 2007 - Oct 2010
    Macquarie Park, Nsw, Au
    As the IT Service Manager, I ensured clarity, definition, and transparency in service operation activities, with a focus on stewardship and compliance with established procedures and best practices. Key responsibilities included driving Service Management processes, serving as an escalation point during Critical Service Disruptions, and facilitating senior management conference calls. The role encompassed expertise across multiple ITIL methodology life cycles and fostering effective relationships within various units. Continuous improvement initiatives, non-functional requirement delivery for new services, and event management improvement initiatives were also key areas of focus.
  • Optus
    Systems Interface Analyst
    Optus Jan 2005 - Jan 2007
    Macquarie Park, Nsw, Au
    The systems interface role, was created to bridge the gap between the technical and business resources, to ensure that the technical solutions being provided to the business were fit for purpose.
  • Optus
    It Systems Analyst
    Optus Oct 2003 - Dec 2004
    Macquarie Park, Nsw, Au
    This role was a level 2 Systems Analyst role looking after applications such as Siebel CRM, Tibco Staffware ( I-Process) and Tuxedo Middleware.
  • Onetel And Optus
    Various Roles Within It Support And Service Management
    Onetel And Optus Jul 2001 - Oct 2003
    Incident Management and Problem Management

Andy Evans Skills

Vendor Management Itil Service Delivery Telecommunications It Service Management It Management Project Management Project Delivery Incident Management Change Management Stakeholder Management Business Process Problem Solving Process Improvement Team Leadership Business Analysis It Operations Management Team Management Sla It Strategy Outsourcing Infrastructure Business Process Improvement Production Systems Business Continuity Risk Management Crisis Management Operations Management Service Level Agreements Incident Analysis It Governance Kpi Continuous Improvement

Andy Evans Education Details

  • Charles Sturt University
    Charles Sturt University
    Information Technology

Frequently Asked Questions about Andy Evans

What company does Andy Evans work for?

Andy Evans works for Metcash

What is Andy Evans's role at the current company?

Andy Evans's current role is Head of Cyber Security Operations | CISSP | Executive Cyber Leadership | Cyber Security Risk | ISO 27001 | Essential Eight | Strategic Planning | Identity and Access Management| Threat & Vulnerability Management.

What is Andy Evans's email address?

Andy Evans's email address is an****@****oup.com

What is Andy Evans's direct phone number?

Andy Evans's direct phone number is +614019*****

What schools did Andy Evans attend?

Andy Evans attended Charles Sturt University.

What are some of Andy Evans's interests?

Andy Evans has interest in Football, Photography And Itil, Investing, Flying, Disaster And Humanitarian Relief, Animal Welfare, Fishing.

What skills is Andy Evans known for?

Andy Evans has skills like Vendor Management, Itil, Service Delivery, Telecommunications, It Service Management, It Management, Project Management, Project Delivery, Incident Management, Change Management, Stakeholder Management, Business Process.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.