Acknowledgement of Country
CSIRO acknowledges the Traditional Owners of the land, sea and waters, of the area that we live and work on across Australia. We acknowledge their continuing connection to their culture and pay our respects to their Elders past and present. View our vision towards reconciliation.
Role highlights
- Shape CSIRO’s cyber security for major transformation programs
- Drive secure-by-design technology outcomes
- Influence security architecture and cyber resilience
About CSIRO
As Australia's national science agency, CSIRO is solving the greatest challenges through innovative science and technology. Many of our iconic innovations were once considered impossible until someone, just like you, joined us and took on the challenge.
Visit CSIRO.au for more information.
The opportunity
Join CSIRO as a Cyber Security Architect and play a key role in securing two of our largest technology transformation programs. Working closely with program teams, delivery partners, architects and technology specialists, you'll provide expert security architecture advice and hands-on guidance to ensure solutions are secure by design.
You'll translate complex cyber security requirements into practical controls, risk treatments and assurance activities, while helping strengthen CSIRO's broader cyber resilience capability through security standards, architecture patterns and best-practice ways of working across the organisation.
High-level duties include
- Provide hands-on cyber security architecture and secure-by-design delivery support for the Cyber for CSIRO and Enterprise Service Transformation programmes.
- Act as the primary cyber security architecture and advisory contact for the two programmes, providing timely, practical and risk-based advice to programme teams, delivery partners, enterprise architects and platform owners.
- Review solution designs, architecture artefacts, technology proposals, procurement inputs and implementation approaches to identify security risks, control gaps and improvement opportunities.
- Develop and document security architecture guidance, design decisions, control requirements, threat models, risk assessments, assurance activities and recommended treatments to support programme delivery.
- Translate cyber security requirements, standards and better practice guidance into practical delivery actions that can be implemented by project and technical teams.
- Embed security controls and assurance requirements across design, procurement, build, implementation, transition and operational handover activities.
- Support cyber security governance, architecture review and delivery checkpoint forums by providing clear advice on security risks, architecture decisions, exceptions, treatment plans and residual risk.
Role particulars
Location and office arrangements: Sydney (Lindfield),
Melbourne (Clayton), Canberra (Black Mountain), Hobart (Sandy Bay), Adelaide (Waite), Brisbane – preferred location (St Lucia).
Salary: AU$135,571 – AU$158,863 per annum (pro rata for part-time), plus 15.4% superannuation
Tenure & work schedule: Specified Term of 12 months
Reference: 103890
As the successful candidate, you will bring:
Essential criteria
- Tertiary qualifications in cyber security, information technology, computer science, engineering or a related discipline, or equivalent professional experience.
- Extensive experience as a cyber security architect or senior security consultant delivering hands-on security architecture outcomes in complex technology environments.
- Current Australian Government NV1 security clearance.
- Demonstrated experience providing secure-by-design advice across major transformation programmes, including solution design review, control definition, risk assessment, threat modelling, assurance planning and security architecture documentation.
- Strong working knowledge of relevant cyber security frameworks and better practice guidance, such as the Australian Government Information Security Manual, Essential Eight, NIST Cybersecurity Framework, ISO/IEC 27001 and PSPF.
- Demonstrated ability to engage effectively with programme teams, enterprise architects, vendors, platform owners, cyber specialists and senior stakeholders to influence secure outcomes in a complex delivery environment.
- Strong written and verbal communication skills, including the ability to explain cyber security risks, design implications and recommended treatments clearly to technical and non-technical audiences.
- Ability to work with autonomy, manage competing priorities and deliver quality architecture artefacts and advice within programme timelines.
- Demonstrated commitment to respectful collaboration, safety, inclusion and CSIRO’s values.
Desirable
- Relevant professional certifications such as CISSP, CISM, SABSA, TOGAF, CCSP, CRISC or equivalent.
- Experience working within Australian Government, research, higher education or other complex federated environments.
- Experience applying Zero Trust architecture and principles, and embedding DevSecOps practices and tools into secure design, delivery, automation and assurance activities.
- Experience supporting cyber security architecture for identity, cloud, network, endpoint, data protection, service management,
operational technology or enterprise platform transformation initiatives.
- Experience developing reusable security architecture patterns, guardrails, standards, templates or assurance processes.
For full details about this role, and other criteria, please review the Position Description.
Not sure if you meet all the criteria?
While it is CSIRO policy that the successful candidate must meet all the essential criteria, there are many ways to demonstrate this. Don’t let the list discourage you. If you are unsure about applying, please reach out to the contact person in the Position Description.
Setting you up for success
We are committed to providing a recruitment process that is fair, equitable and accessible to everyone. We recognise that it may be helpful for us to adjust our process to make it equitable for your individual situation. Please contact
[email protected] and let us know how we can support you.
Life at CSIRO and flexible work arrangements
We work flexibly at CSIRO, offering a range of options for how, when and where you work. We can discuss flexible work arrangements with you during the recruitment process. CSIRO also offers a range of leave entitlements, benefits and career development opportunities. To find out more, visit Careers at CSIRO.
Inclusion and belonging
Solving Australia's greatest challenges takes a diversity of minds and lived experiences. We know diverse teams are more effective and deliver more creative outcomes. As an equal employment opportunity organisation, we are committed to creating diverse and inclusive teams where people feel they belong.
We recognise true diversity encompasses all ages, abilities, cultures, faiths, levels of education, genders, sexualities, diversity of thought and much more. We focus on hiring people who share our values of People First, Further Together, Making it Real and Trusted.
CSIRO holds Platinum Status for the Australian Workplace Equality Index for LGBTQIA+ inclusion, and a Science in Australia Gender Equity Bronze Award.
Eligibility
This is a security assessed position, applications for this position are open to Australian Citizens only with the successful candidate being required to be able to obtain and maintain a security clearance at the Negative Vetting 1 level. Appointment to this role is subject to provision of a national police check and may be subject to other security/medical/character requirements.
Child safety
CSIRO is committed to the safety and wellbeing of all children and young people involved in our activities and programs. View our Child Safe Policy.
How to apply
Please apply online and submit a cover letter (maximum 2 pages) and CV that demonstrate your motivation and ability to meet the essential requirements of this role.
Applications close
Sunday 6th of August, 11pm AEST
📌 Security Architect (Sydney)
🏢 CSIRO
📍 Sydney