The River City’s Watchtowers: Brisbane’s Cybersecurity Leaders to Watch

Related

Share

Brisbane defends institutions built for a state the size of a continent’s northeast corner. Queensland’s capital hosts one of Australia’s largest superannuation funds, a regional bank trading since 1874, the electricity distributor for the entire state, a major research university, and the state-owned manager of tens of billions in investment assets. Everything these cybersecurity leaders protect is large, dispersed, and essential. The five below work across finance, energy, higher education, and government investment.

Jon Coleman – CISO, Australian Retirement Trust

Jon Coleman came to superannuation from the power grid. He spent more than four years as general manager of cyber and information security at Energy Queensland, defending the electricity infrastructure of an entire state, before becoming Chief Information Security Officer of Australian Retirement Trust in August 2025. The fund holds the retirement savings of millions of members, which means it holds exactly the combination of identity data and money that attackers pursue hardest. Recent breaches across the sector have put its security leaders under national scrutiny. Coleman holds a GAICD credential, which rounds out the governance side of the role.

Hadi Rahnama – Chief Information Security & Technology Operations Officer, Bank of Queensland

Hadi Rahnama has spent more than twelve years at Bank of Queensland, taking on information security and technology operations in September 2024. BOQ is one of Australia’s oldest regional banks, headquartered in Brisbane since 1874, and its mix of branch banking, digital channels, and business finance gives the combined mandate unusual breadth. Holding security and technology operations in one portfolio means the defences and the systems they protect answer to the same leader, a structure more banks are adopting. Rahnama’s long tenure inside the institution gives him the working knowledge that arrangement requires.

Dion Mikkelsen – A/General Manager Cyber, Architecture and Technology, Energy Queensland

Energy Queensland runs the electricity distribution networks for the whole state, from Brisbane’s suburbs to communities thousands of kilometres away. Dion Mikkelsen has held the company’s top cyber mandate since mid-2025 and moved into the acting general manager role for cyber, architecture, and technology in April 2026. He has spent nearly five years at the company, rising through its security and architecture ranks. A year in the top cyber job at one of Australia’s largest energy distributors is meaningful time in a sector where nation-state interest is constant.

Jack Cross – CISO, Queensland University of Technology

Jack Cross has spent more than five years at Queensland University of Technology, becoming Chief Information Security Officer in May 2024. He works from the Brisbane campus. QUT enrols tens of thousands of students and maintains active research partnerships with industry and government, with a technology estate spanning teaching, research, and hospital-adjacent facilities. Higher education is among the most attacked sectors in Australia, and Cross moved into the role as someone who already knew the institution from the inside.

Grant Slender – CISO & Head of Technology, Queensland Investment Corporation

Grant Slender leads cybersecurity strategy, technology operations, and resilience at the Queensland Investment Corporation, the state-owned investment manager overseeing tens of billions of dollars across global infrastructure and asset portfolios. QIC’s holdings include airports, ports, and energy assets, which means Slender’s work sits inside the enterprise risk frameworks of an institution with physical infrastructure on its books. He is a regular on the conference circuit, including a Splunk .conf presentation on the co-managed security operations architecture he named the Goldilocks model.

Defending at Distance

Brisbane’s cybersecurity leaders protect institutions whose reach extends well past the city. Coleman and Rahnama guard the savings and banking of millions of Queenslanders. Mikkelsen keeps electricity flowing across a state where some networks run thousands of kilometres from the capital. Cross defends a research university, and Slender secures the capital behind airports, ports, and energy assets. Three of them built their careers inside the organisations they now protect, and Coleman brought a critical infrastructure background into mass-market finance. It is a small community for the scale of what it defends, which tends to mean its leaders know each other and the ground they are standing on.

Discover more CISOs securing their organizations:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.