07 Sep
|
Indigitise
|
Canberra
07 Sep
Indigitise
Canberra
NO LOCATION RESTRICTIONS WITHIN AUSTRALIA Occasional travel may be required.
*If Melbourne or Canberra based, part time office attendance will be expected The successful candidate will be a Cybersecurity skilled who works effectively in a complex environment, thinks critically, applies excellent problem-solving skills and manages competing priorities with a focus on mitigating risks.
This role is responsible for the conduct of following tasks and activities:
a. Assessment and Authorisation: 1) Provide System Assessment and Authorisation activities as directed by the CA31 Engineering Manager.
2) Conduct system Assessment and Authorisation activities in accordance with:
a) ASD Information Security Manual (ISM)
b) Protective Security Policy Framework (PSPF)
c) Defence Security Policy Framework
d) Cyber Security Assessment and Authorisation (CSAA) Charter, assessment methodology, templates, and guidance.
3) Perform security assessments using Operational Effectiveness Reviews (OER) as the default approach, with Design Effectiveness Reviews (DER) conducted where justified.
4) Audit the effectiveness of system security controls implemented across CA31 capability systems.
5) Develop and deliver assessment artefacts including:
a) Security Assessment Reports (SAR)
b) ATO briefs
c) Risk statements and recommended remediation actions.
b. Risk Identification and Analysis: 1) Identify, analyse, evaluate, and escalate cyber security and business risks 2)
Identify and assess vulnerabilities associated with:
a) Security exceptions
b) Software defects
c) Architecture or design weaknesses 3) Assess system security architecture and services using structured threat modelling methodologies.
4) Protect the Confidentiality, Integrity, and Availability (CIA) of Defence information and systems Governance, Compliance, and Assurance.
5) Review system security documentation, policies, and procedures to ensure alignment with Defence and Australian Government requirements.
6) Ensure system compliance with mandatory cyber security requirements.
7) Support configuration governance processes including the Change Control Boards (CCB) and provide assessment input with risks, mitigations and options for the Executive Authority (EA) to accept.
c. Advisory and Stakeholder Engagement: 1) Provide cyber security advice within the defined assessor scope of the CA31.
2) Support CA31 in understanding and mitigating cyber security risks impacting capability delivery and operations within the LC4 domain.
3) Build and maintain effective working relationships with:
a) Applicable sustainment products
b) OEM
c) Operational and security stakeholders Services are to be provided commensurate with relevant Australian and International Standards, regulations, and Defence requirements.
Service providers are to employ industry best practice when undertaking the Services
📌 Defence Cyber Security Certification Consultant - Level 3 (Canberra)
🏢 Indigitise
📍 Canberra