10 Sep
|
Azooa
|
Australia
? CYBER SECURITY GRC / ASSESSMENT & AUTHORISATION SOLUTION LEAD | DEFENCE | NV1+ | ONSITE
Are you a senior Cyber GRC specialist with an active NV1 clearance, current availability for a new contract, and the ability to work onsite at Defence-approved locations?
Azooa is preparing a response for RFQ 96895 – ETML34 DDG Cyber Assessment and Authorisation Digitisation and is seeking a suitably qualified contractor for a proposed Cyber Security GRC / Assessment & Authorisation Solution Lead opportunity supporting the Australian Department of Defence .
⚠️ This opportunity is onsite only. Remote working arrangements are not being considered.
This is a senior Defence cyber security role focused on:
? Governance, Risk & Compliance
? Assessment & Authorisation
? Defence security frameworks
? Security artefact assurance
? Control and compliance mapping
? Cyber risk assessment
? Evidence and gap analysis
? Security architecture and solution leadership
ABOUT THE OPPORTUNITY The successful specialist will provide senior cyber security leadership across the design, implementation, assurance and validation of a digital capability supporting Defence Assessment & Authorisation activities .
The broader capability is intended to analyse Defence documentation, assess security artefacts against applicable requirements, identify compliance and evidence gaps, generate draft cyber security artefacts, and maintain end-to-end traceability between:
Source Documentation → Requirements → Controls → Evidence → Risks → Findings → Recommendations → Security Artefacts A major focus will be ensuring assessment outputs remain explainable, auditable, traceable and subject to appropriate human oversight .
KEY RESPONSIBILITIES
You will provide senior Cyber GRC and Defence A&A; expertise across:
- Cyber security risk assessment
- Security control assessment
- Compliance mapping
- Security evidence review
- Gap and deficiency analysis
- Defence security requirement interpretation
- Security assurance and accreditation support
- Security artefact development and review
- Security architecture and solution design
- Engagement with Defence security stakeholders
You will work across applicable frameworks including:
- Information Security Manual – ISM
- Protective Security Policy Framework – PSPF
- Defence Security Principles Framework – DSPF
- Defence Cyber Security Architecture and Authorisation Framework – DCSAAF
- DDG Assessment and Authorisation Framework – DDG AAF
• Relevant NIST requirements where applicable
SECURITY ARTEFACTS The role will provide oversight and subject-matter expertise across the assessment, generation and review of security artefacts including:
• Security Authorisation Plans – SAP
• Security Risk Management Plans – SRMP
• System Security Plans – SSP
• Security Assessment Reports – SAR
You will help establish methodologies for identifying:
- Compliance gaps
- Missing or insufficient evidence
- Security control deficiencies
- Documentation gaps
- Unmet security requirements
- Cyber risk and assurance issues
• Remediation recommendations The role will also contribute to analysis of Defence material including RFQs, RFTs, Statements of Work, System Design Documents, CONOPS, architecture documentation, existing security artefacts and supporting evidence .
SECURITY ARCHITECTURE & ATO SUPPORT
You will contribute to areas including:
- Security requirements
- Security control design
- Authentication and authorisation
- Role-based access controls
- Information protection
- Audit and accountability
- Secure data handling
- Security incident management
- Defence systems integration
• Australian data sovereignty The successful specialist will also support technical and cyber assurance activities required for the capability to achieve its intended Defence Authorisation to Operate (ATO) .
Formal accreditation and authorisation decisions remain the responsibility of Defence.
KEY DELIVERABLES The role is expected to contribute substantially to:
Project Management Plan & Requirements Analysis
Security requirements, governance and delivery approach.
Solution Design Package
Architecture, security design, functional requirements and implementation approach.
Prototype Capability Demonstration
Document ingestion, analysis and information extraction.
Assessment & Artefact Generation Capability
Defence framework assessment, requirements mapping and SAP/SRMP/SSP generation.
Final Capability Demonstration
Successful end-to-end demonstration of the agreed capability.
Documentation & Knowledge Transfer
Security documentation, operating procedures, user guidance and knowledge transfer.
ESSENTIAL EXPERIENCE
We are particularly interested in specialists with:
✅ Active NV1 clearance or higher
✅ Robust Cyber GRC experience
✅ Australian Defence cyber security experience
✅ Assessment & Authorisation / accreditation / assurance experience
✅ Strong practical knowledge of the ISM
✅ Defence cyber security risk assessment experience
✅ Security control assessment and compliance mapping experience
✅ Experience developing or reviewing SAP, SRMP, SSP and/or SAR artefacts
✅ Strong evidence assessment and gap-analysis capability
✅ Experience interpreting Defence security requirements
✅ Strong stakeholder engagement skills
✅ High-quality technical and cyber security documentation skills
HIGHLY DESIRABLE
Experience in any of the following will be highly regarded:
- DCSAAF
- Defence ATO processes
- DSPF / PSPF
- Defence security accreditation
- Cyber security architecture
- Automated compliance assessment
- AI-assisted document analysis
- Security control/evidence traceability
- Defence systems integration
- PROTECTED / SECRET environments
- DISP environments
- NIST frameworks
- Security testing and UAT
ENGAGEMENT DETAILS
? RFQ: 96895
? Program: ETML34 DDG Cyber Assessment and Authorisation Digitisation
? Client Environment: Australian Department of Defence
? Clearance: Active NV1 minimum
? Classification: Services up to and including SECRET
? Contract End: 30 May 2027
? Work Arrangement: Onsite at Defence-approved locations – no remote work The underlying RFQ permits delivery from approved Commonwealth and supplier premises subject to Defence security requirements; however, Azooa is sourcing this proposed position on an onsite-only basis .
RATE GUIDANCE The RFQ does not currently provide a numerical maximum contractor rate. Defence will determine the applicable daily rate following nomination of the relevant SFIA category and level.
? Azooa recommended competitive range: $150–$180/hour including super
Equivalent 8-hour daily rate:
? $1,200–$1,440/day including super
Candidates toward the lower or middle part of the range are expected to present a stronger commercial position.
Higher rates may still be considered where candidates bring particularly strong capability across DCSAAF, Defence ATO, security architecture, higher-level security clearances or niche Defence cyber security experience .
Applications from suitably qualified NV1/NV2/TSPV-cleared Cyber GRC and Defence A&A; specialists are strongly encouraged.
📌 Cyber Security Architect (Australia)
🏢 Azooa
📍 Australia