Defence Cyber Security Certification Consultant (Canberra)

Defence Cyber Security Certification Consultant (Canberra)

08 Sep
|
Business Review Group
|
Canberra

08 Sep

Business Review Group

Canberra

Program / Project: CA31 –

- Land Communications &
- Specialist Systems SPO (LCSS SPO)

Business Area: Land C4 Systems Branch (LC4S Branch), Joint Systems Division

Discipline: 2.6 Systems and Software Engineering –

- System Security

Skill Level: Level 3

FTE: 1.0

Security Clearance: Minimum NV1

ITAR Requirement: Yes

Start Date: ASAP

End Date: 31 March 2027

Extension: Opportunity for extension

Location: No location restrictions within Australia

Travel: Occasional travel may be required

On-Site Requirement: Candidates based in Melbourne or Canberra must be able to work on-site a minimum of 3 days per week

Role Overview

Land Communications &

- Specialist Systems SPO (LCSS SPO) is seeking a suitably qualified and experienced Cybersecurity Certification Consultant to operate as an embedded member of the Land C4 Systems Branch supporting the CA31 capability.

CA31 sustains and enhances Land Command, Control, Communications and Computing (C4) systems at the operational and tactical levels, providing communications capabilities essential to the conduct of operations in the Land Domain.

The program sustains core communications capabilities and delivers capability enhancement work packages across:

- Tactical Communications Network (TCN)
- Battlefield Telecommunications Network (BTN)
- Battlefield Management System (BMS)
- Deployable Information Environment (DIE) –
- Protected and Secret

The successful candidate will provide specialist cyber security assessment, authorisation, assurance and risk management support across CA31 capability systems. The role requires a Cybersecurity qualified who can operate effectively in a complex Defence environment, think critically, solve complex problems and manage competing priorities while maintaining a strong focus on risk mitigation and capability outcomes.

Key Responsibilities

Assessment and Authorisation The Cybersecurity Certification Consultant will:
- Provide System Assessment and Authorisation activities as directed by the CA31 Engineering Manager.
- Conduct assessment and authorisation activities in accordance with:
- ASD Information Security Manual (ISM).
- Protective Security Policy Framework (PSPF).
- Defence Security Policy Framework.
- Cyber Security Assessment and Authorisation (CSAA) Charter, assessment methodology, templates and guidance.

- Conduct security assessments using Operational Effectiveness Reviews (OER) as the default assessment approach.
- Undertake Design Effectiveness Reviews (DER) where justified.
- Audit the effectiveness of security controls implemented across CA31 capability systems.
- Develop and deliver security assessment artefacts, including:

- Security Assessment Reports (SAR).
- Authority to Operate (ATO) briefs.
- Risk statements.
- Recommended remediation actions.





Cyber Security Risk and Threat Assessment The successful candidate will:
- Identify, analyse, evaluate and escalate cyber security and business risks.
- Identify and assess vulnerabilities resulting from:
- Security exceptions.
- Software defects.
- Architecture or design weaknesses.

- Assess system security architectures and services using structured threat-modelling methodologies.
- Support protection of the Confidentiality, Integrity and Availability (CIA) of Defence information and systems.
- Assess risks and develop practical mitigation and remediation recommendations.
- Support security risk decision-making across the CA31 capability environment.

Governance, Compliance and Assurance The Cybersecurity Certification Consultant will:
- Review system security documentation, policies and procedures for alignment with Defence and Australian Government requirements.
- Ensure systems comply with applicable mandatory cyber security requirements.
- Provide assurance regarding implementation and ongoing effectiveness of security controls.
- Support configuration governance activities, including Change Control Boards (CCBs).
- Provide assessment input covering risks, mitigations and options for consideration and acceptance by the relevant Executive Authority.
- Support ongoing cyber security governance and assurance across capability systems.

Cyber Security Advisory The successful candidate will:
- Provide specialist cyber security advice within the defined CA31 assessor scope.
- Support CA31 stakeholders in understanding cyber security risks affecting capability delivery and operations within the LC4 domain.
- Provide clear and defensible advice regarding security risks, treatment options and remediation activities.
- Apply relevant Australian and international standards, Defence requirements and industry best practice when delivering services.

Stakeholder Engagement The Cybersecurity Certification Consultant will build and maintain effective working relationships with:
- CA31 and LCSS SPO stakeholders.
- Sustainment product teams.
- Original Equipment Manufacturers (OEMs).
- Operational stakeholders.
- Security stakeholders.
- Defence and industry partners.

The role requires the ability to work under broad direction and influence stakeholders across both Defence and industry.

Mandatory Experience And Qualifications

Candidates must demonstrate

- Relevant qualifications,



industry certifications and/or professional experience assessed as suitable for eligibility to obtain DCIAB-CSAA endorsement as a Cyber Security Assessor.
- Relevant certifications may include, but are not limited to:
- CISSP.
- CISM.
- ISO 27001 Lead Auditor.
- IRAP accreditation.

- Strong understanding of ICT architectures, networks and platforms.
- Strong understanding of cyber security compliance and governance within a Defence environment.
- Demonstrated ability to lead cyber security audits, document outcomes and deliver formal assessment reports.
- Understanding of modern networking technologies, computer systems and operating systems.
- Ability to work effectively as part of a multidisciplinary team.

Highly Desirable Experience And Skills The following would be highly regarded:

- Comprehensive understanding of Defence systems, particularly C4 capabilities.
- Previous experience within Defence, Army or CASG.
- Experience assessing and evaluating cyber security risk.
- Experience supporting Defence capability acquisition or sustainment environments.
- Ability to apply creative and innovative solutions that provide practical benefits to stakeholders.

Additional Requirements

Candidates should demonstrate

- Understanding of the One Defence Capability System, formerly the Capability Lifecycle.
- Ability to operate effectively under broad direction.
- Ability to influence stakeholders across Defence and industry.
- Commitment to ongoing career development.
- Willingness to mentor and support colleagues.
- Effective time management.
- Strong written and verbal communication skills.
- Strong interpersonal and stakeholder engagement capability.

Security and Working Arrangements The successful candidate must hold a current Australian Government security clearance of at least NV1. The role has no location restrictions within Australia, although occasional travel may be required to Defence facilities and program locations.

Candidates based in Melbourne, Victoria or Canberra, ACT must be able to attend the office for a minimum of three days per week.

The engagement is subject to ITAR requirements.

Candidate Profile

This opportunity would suit an experienced Cyber Security Assessor, Cybersecurity Certification Consultant, Security Assurance Engineer or System Security Engineer with strong Defence cyber security assessment and authorisation experience.

The strongest candidates will combine practical knowledge of Defence C4 systems, ICT architecture and networks with demonstrated expertise in CSAA, OER/DER assessments, security control auditing, risk assessment, SAR development and ATO support.

Experience working within Army, CASG or Defence capability acquisition and sustainment environments, together with eligibility for DCIAB-CSAA Cyber Security Assessor endorsement, would be particularly relevant.

📌 Defence Cyber Security Certification Consultant (Canberra)
🏢 Business Review Group
📍 Canberra

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: defence cyber security certification consultant (canberra) / canberra

Subscribe to this job alert:

Get the latest job offers by email for: defence cyber security certification consultant (canberra) / canberra