Director, Cyber Risk and Assurance (Northern Territory)

Director, Cyber Risk and Assurance (Northern Territory)

13 Aug
|
NT Government - Department of Corporate and Digital Development
|
Northern Territory

13 Aug

NT Government - Department of Corporate and Digital Development

Northern Territory

Agency Department of Corporate and Digital Development Work unit ICT Services - Cyber NT, Cyber Risk and Assurance

Job title Director, Cyber Risk and Assurance Designation Senior Administrative Officer 2

Job type Full time Duration Ongoing

Salary $152,751 - $166,487 Location All NT Regions

Position number 68260255 RTF 353921 Closing 25/08/2026

Contact officer Romi Peerzada on 08 8994 3844 or [email protected]

About the agency https://dcdd.nt.gov.au/

Apply online https://jobs.nt.gov.au/Home/JobDetails?rtfId=353921

APPLICATIONS MUST INCLUDE A ONE-PAGE SUMMARY ABOUT YOU, A DETAILED RESUME AND COPIES OF YOUR TERTIARY

QUALIFICATIONS.

Information for applicants – inclusion and diversity The NTPS values diversity. The NTPS encourages people from all diversity groups to apply for vacancies and accommodates people with disability by making reasonable workplace adjustments. If you require an adjustment for the recruitment process or job, please discuss this with the contact officer. For more information about applying for this position and the merit process, go to the OCPE website.

Primary objective

Provide expert capability in cyber security governance, risk and assurance management, leading a team managing cyber security risk and assurance across the NT Government’s technology workplace.

Context statement The Department of Corporate and Digital Development manages digital systems on behalf of NT Government agencies. The position operates within the Cyber NT unit providing expert cyber security governance, risk and assurance services and leadership of the cyber risk management program.The position has involvement in sensitive issues and out of hours work may be required.

Key duties and responsibilities

1. Lead and manage a cyber security risk and assurance function, systems and regulatory reporting, including working with internal and

external stakeholders and managing reporting to the Government CISO, governance committees and executives.
1. Oversee the cyber risk management program, developing and maintaining cyber security governance and risk management

frameworks, associated practices, tools and systems, including leading ISMS implementation.
1. Maintain the enterprise cyber risk and controls register and drive engagement with risk owners to review technology and cyber risk,

verify controls, collect evidence, advise risk treatments; and administer exemption and compliance reporting.
- Deliver cyber security controls assurance services including internal assessments and management of external reviews and audits against relevant laws, regulations, industry standards and cyber security policy and risk frameworks.
- Provision of expert advice to inform ICT policies and standards, security risk management plans, contractual and procurement documentation, supply chain cyber security risk assessments and regulatory compliance.
- Prepare and present reporting on cyber risk and assurance for the Government CISO, cyber security committees, ICT governance, risk and audit committees and client agencies to inform decision making on cyber risk management.

1. Maintain awareness of the internal and external cyber threat environment and legal, regulatory compliance and contractual obligations.
2. Operate as a senior leader within the Cyber NT unit and broader ICT Services division, supporting and guiding others and working

collaboratively across the Digital Services portfolio to ensure alignment with Digital activities and Agency initiatives and priorities.

Selection criteria

Essential

1. Demonstrated experience within a large organisation in cyber risk management and assurance, regulatory compliance and audit

processes, including undertaking technical controls and cyber risk assessments against industry-wide security standards and frameworks such as ISO/IEC 27001, NIST CSF, PCI-DSS, ASD’s ISM, Australian Government’s PSPF, etc.
1. Knowledge of the Security of Critical Infrastructure Act and associated regulations, Cyber Security Act and Privacy Act and Notifiable

Data Breach Scheme; and demonstrated analytical capability to interpret and apply legislation and policy requirements.




1. Experience in applying policy and processes to incorporate cyber risk management in enterprise risk management, procurement,

contractual processes and ongoing vendor management and attestation.
1. Experience in developing strategic plans, frameworks, policies and procedures, reports and technical documentation such as security

risk management plans and system security plans in alignment with industry and regulatory standards.
1. Highly developed written communication skills with the ability to convey complex concepts and translate technical information

concisely for diverse audiences and develop a range of materials including executive briefings, reports, policies, guidelines and procedures.
1. Highly developed leadership and interpersonal skills with demonstrated ability to present to executive audiences, manage and develop

teams, and build relationships, influence, negotiate and collaborate with internal and external stakeholders to direct and achieve outcomes.
1. Hold or have eligibility to obtain Negative Vetting 1 National Security Clearance. Desirable

2. Tertiary qualification in ICT, cyber security, law, risk management or a related discipline.
3. Industry certifications such as CISM, CISSP, ISO/IEC 27001 Lead Implementer/Auditor. Further information The recommended applicant will be required to undergo a criminal history check prior to commencement.

A criminal history will not

exclude an applicant from this position unless it is a relevant criminal history. When choosing to apply for this position, the applicant should consider the full requirements of the position in aligning to their work experience and capabilities to this role.

Please refer to the Capability Framework.

Approved: July 2026 Greg Connors – Deputy Chief Executive, Digital Services

Page 1 of 2

Agency Department of Corporate and Digital Work unit ICT Services - Cyber NT, Cyber Risk and

Development Assurance

Job title Director, Cyber Risk and Assurance Designation Executive Contract Officer 1

Job type Full time Duration Fixed for up to 4 years

Remuneration package $233,112 Location All NT Regions

Position number 68260255 RTF 353921 Closing 25/08/2026

Contact officer Romi Peerzada on 08 8994 3844 or [email protected]

About the agency https://dcdd.nt.gov.au/

Apply online https://jobs.nt.gov.au/Home/JobDetails?rtfId=353921

APPLICATIONS MUST INCLUDE A ONE-PAGE SUMMARY ABOUT YOU, A DETAILED RESUME AND COPIES OF YOUR TERTIARY

QUALIFICATIONS.

Information for applicants – inclusion and diversity The NTPS values diversity. The NTPS encourages people from all diversity groups to apply for vacancies and accommodates people with disability by making reasonable workplace adjustments. If you require an adjustment for the recruitment process or job, please discuss this with the contact officer. For more information about applying for this position and the merit process, go to the OCPE website.

Primary objective

Provide expert capability in cyber security governance, risk and assurance management, leading a team managing cyber security risk and assurance across the NT Government’s technology environment.

Context statement The Department of Corporate and Digital Development manages digital systems on behalf of NT Government agencies. The position operates within the Cyber NT unit providing expert cyber security governance, risk and assurance services and leadership of the cyber risk management program.The position has involvement in sensitive issues and out of hours work may be required.

Key duties and responsibilities

1. Lead and manage a cyber security risk and assurance function, systems and regulatory reporting, including working with internal and





external stakeholders and managing reporting to the Government CISO, governance committees and executives.
1. Oversee the cyber risk management program, developing and maintaining cyber security governance and risk management

frameworks, associated practices, tools and systems, including leading ISMS implementation.
1. Maintain the enterprise cyber risk and controls register and drive engagement with risk owners to review technology and cyber risk,

verify controls, collect evidence, advise risk treatments; and administer exemption and compliance reporting.
- Deliver cyber security controls assurance services including internal assessments and management of external reviews and audits against relevant laws, regulations, industry standards and cyber security policy and risk frameworks.
- Provision of expert advice to inform ICT policies and standards, security risk management plans, contractual and procurement documentation, supply chain cyber security risk assessments and regulatory compliance.
- Prepare and present reporting on cyber risk and assurance for the Government CISO, cyber security committees, ICT governance, risk and audit committees and client agencies to inform decision making on cyber risk management.

1. Maintain awareness of the internal and external cyber threat environment and legal, regulatory compliance and contractual obligations.
2. Operate as a senior leader within the Cyber NT unit and broader ICT Services division, supporting and guiding others and working

collaboratively across the Digital Services portfolio to ensure alignment with Digital activities and Agency initiatives and priorities.

Selection criteria

Essential

1. Demonstrated experience within a large organisation in cyber risk management and assurance, regulatory compliance and audit

processes, including undertaking technical controls and cyber risk assessments against industry-wide security standards and frameworks such as ISO/IEC 27001, NIST CSF, PCI-DSS, ASD’s ISM, Australian Government’s PSPF, etc.
1. Knowledge of the Security of Critical Infrastructure Act and associated regulations, Cyber Security Act and Privacy Act and Notifiable

Data Breach Scheme; and demonstrated analytical capability to interpret and apply legislation and policy requirements.
1. Experience in applying policy and processes to incorporate cyber risk management in enterprise risk management, procurement,

contractual processes and ongoing vendor management and attestation.
1. Experience in developing strategic plans, frameworks, policies and procedures, reports and technical documentation such as security

risk management plans and system security plans in alignment with industry and regulatory standards.
1. Highly developed written communication skills with the ability to convey complex concepts and translate technical information

concisely for diverse audiences and develop a range of materials including executive briefings, reports, policies, guidelines and procedures.
1. Highly developed leadership and interpersonal skills with demonstrated ability to present to executive audiences, manage and develop

teams, and build relationships, influence, negotiate and collaborate with internal and external stakeholders to direct and achieve outcomes.
1. Tertiary qualification(s) in a relevant discipline combined with relevant senior executive experience, or an equivalent combination of

substantial relevant senior executive experience and education and training
1. Hold or have eligibility to obtain Negative Vetting 1 National Security Clearance. Desirable

2. Relevant industry certifications such as CISM, CISSP, ISO/IEC 27001 Lead Implementer/Auditor. Further information The recommended applicant will be required to undergo a criminal history check prior to commencement.

A criminal history will not

exclude an applicant from this position unless it is a relevant criminal history. When choosing to apply for this position, the applicant should consider the full requirements of the position in aligning to their work experience and capabilities to this role.

Please refer to the Capability Framework.

📌 Director, Cyber Risk and Assurance (Northern Territory)
🏢 NT Government - Department of Corporate and Digital Development
📍 Northern Territory

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: director, cyber risk and assurance (northern territory) / northern territory

Subscribe to this job alert:

Get the latest job offers by email for: director, cyber risk and assurance (northern territory) / northern territory