Job Description
Senior Cyber Security Governance Analyst | Canberra
n
Eligibility: Australian Government environment; candidate must be eligible to obtain the required clearance
n
Security Clearance: Must be able to obtain Negative Vetting Level 1 (NV1)
n
Work Arrangement: Full-time onsite; temporary work-from-home arrangements may be considered case-by-case
n
Experience: Senior level / APS6 equivalent; 5+ years of relevant experience desirable
n
Hours: Up to 45 hours per week; extended hours and weekend work may be required during key operational periods
n
About the Role
n
A senior Cyber Security Governance, Risk and Compliance (GRC) qualified is required to support a major Australian public-sector cyber resilience uplift program.
n
The role will contribute to cyber security governance and assurance activities, with additional support for high-priority operational requirements during key event periods.
n
n
Contribute to security considerations within solution design
n
Review and recommend appropriate cyber security requirements
n
Develop high-quality communications and documentation for senior executive decision-making
n
Support the coordination of security assurance activities, including IRAP assessments and penetration testing
n
Lead the development and maintenance of formal cyber security and GRC documentation
n
Support cyber governance, risk and compliance activities across the program
n
Work closely with technical teams, business stakeholders and assurance functions
n
Provide practical security advice and recommendations to support program outcomes
n
Strong knowledge of the Information Security Manual (ISM)
n
Strong understanding of the Protective Security Policy Framework (PSPF)
n
Knowledge and practical understanding of the Essential Eight
n
Demonstrated experience performing a Cyber Security GRC role
n
Demonstrated capability managing stakeholder and client relationships to achieve outcomes
n
Demonstrated experience developing GRC and cyber security documentation
n
Strong written and verbal communication skills
n
Ability to work effectively in a senior, complex and delivery-focused environment
n
Minimum 5 years' experience in cyber security, GRC, risk, assurance or related roles
n
Experience within Australian Government or similarly regulated environments
n
Experience supporting security assurance activities such as IRAP and penetration testing
n
Experience working on cyber resilience or security uplift programs
n
Experience supporting high-priority operational or event-driven environments
n
#J-*****-Ljbffr