Cyber Security Assurance Specialist – Government Client
Our agency is recruiting for a Cyber Security Assurance Specialist on behalf of a key government client. This role offers an exciting opportunity to contribute to high-priority ICT security initiatives and play a pivotal role in ensuring compliance with Australian Government security standards.
Key Responsibilities:
- Configure and utilize tools from the Cyber Toolbox (or equivalent), including the Essential Eight Maturity Verification Tool and Application Control Verification Tool.
- Complete ICT system authorizations in line with the Protective Security Policy Framework (PSPF) and the Information Security Manual (ISM).
- Conduct comprehensive cyber security risk assessments on enterprise systems.
- Author critical cyber security documentation, such as Statements of Applicability, Security Risk Management Plans (SRMP), and Security Assurance Reports.
- Identify, test, and assess security controls in alignment with the ISM, Essential Eight maturity model, and organizational policies.
- Develop and maintain security threat and risk assessments, mitigation strategies, and security assessment artefacts.
- Manage system risk and treatment registers, and provide advice on security risks and mitigation strategies aligned with policy and risk tolerances.
- Engage with globally dispersed stakeholders and effectively communicate security concepts to non-technical audiences.
- Prioritize workloads, attend meetings,
and report progress to key stakeholders.
- Provide mentorship, skills transfer, and capability uplift to team members.
- Educate staff to ensure understanding and adherence to security policies and processes.
Deliverables:
- Maturity Assessment Reports.
- Security Impact Assessment (SIA).
- System Security Plan + Annex (SSP-A).
- Security Risk Management Plan (SRMP).
- Security Assurance Reports.
- Vulnerability Assessment Report.
- (Interim) Authority to Operate.
Key Requirements:
- Demonstrated experience with cyber security tools, including the Essential Eight Maturity Verification Tool.
- Robust understanding of the PSPF, ISM, and Essential Eight maturity model.
- Proven track record in conducting risk assessments, developing mitigation plans, and authoring security documentation.
- Strong stakeholder management skills, with the ability to convey complex security concepts to non-technical audiences.
- Experience mentoring and supporting team members to enhance their skills and capabilities.
- Excellent analytical skills with the ability to prioritize workloads and meet deadlines.
This role offers a rare opportunity to be involved in critical government ICT projects, ensuring robust security measures and compliance. If you have the relevant experience and are looking for a challenging and rewarding role within a government environment, we would love to hear from you.