Job Description
Senior Cyber Security Governance Analyst – Federal Government
n
Security Requirement: Current NV1 Security Clearance or higher required
n
About the Opportunity
n
Hatchit Studios is seeking an experienced Senior Cyber Security Governance Analyst for a long-term labour hire opportunity supporting a major Australian Federal Government agency.
n
The successful candidate will support cyber security Governance, Risk and Compliance (GRC) activities as part of a significant resilience uplift program. The role will work closely with cyber security teams, business stakeholders and external assurance providers to strengthen security governance, assurance and compliance outcomes.
n
This is a Canberra-based role requiring an onsite presence. Temporary work-from-home arrangements may be considered on a case-by-case basis.
n
Key Responsibilities
n
n
Support cyber security Governance, Risk and Compliance (GRC) activities
n
Contribute security considerations and requirements to solution design
n
Review and provide recommendations for the development of security requirements
n
Develop formal security and GRC documentation
n
Prepare communications, reports and documentation to support senior executive decision-making
n
Coordinate security assurance activities,
including IRAP assessments and penetration testing undertaken by external providers
n
Support the management of assurance findings and remediation activities
n
Develop security documentation supporting IRAP and security authorisation processes, including System Security Plans (SSPs), Security Risk Management Plans (SRMPs), SSP Annexes and authorisation documentation
n
Engage with technical teams, business stakeholders and external security providers to achieve security and compliance outcomes
n
Support additional cyber security requirements during key operational and electoral event periods
n
n
Skills & Experience Required
n
n
Strong knowledge of the Australian Government Information Security Manual (ISM)
n
Strong understanding of the Protective Security Policy Framework (PSPF)
n
Knowledge and practical application of the Essential Eight
n
Demonstrated experience performing a Cyber Security GRC role
n
Experience developing formal cyber security governance, risk, assurance and compliance documentation
n
Solid stakeholder and client engagement skills with demonstrated ability to drive outcomes
n
Experience supporting security assurance, accreditation or authorisation activities
n
#J-*****-Ljbffr