10 Sep
|
Pinaka Technology Solutions
|
Canberra
10 Sep
Pinaka Technology Solutions
Canberra
Cybersecurity Certification Consultant
Australian citizenship required. Must have an active Negative Vetting Level 1 (or higher) security clearance.
Location:
Australia-wide (Hybrid).
What to Submit
A tailored resume in docx format (maximum four pages).
RFQ Details
RFQ ID:
********-Joint-LC4S-RFQ
Agency:
Department of Defence
Closing Date:
18th Sep ****
Estimated Start Date:
ASAP
Initial Contract Duration:
Until 31 March ****
Extension Term:
Opportunity for extension
Number of Extensions:
Not specified
Experience Level:
L3
Security Clearance:
NV1
Location of Work:
No location restrictions within Australia; occasional travel may be required
Working Arrangements:
Minimum three days per week onsite; if Melbourne or Canberra based, part time office attendance is expected
Maximum Hours:
Not specified
Job Details
Land Communications & Specialist Systems SPO is seeking a suitably qualified and experienced Cybersecurity Certification Consultant to work as an embedded member of the Land C4 Systems Branch. The role sits within CASG and supports the CA31 fleets, which sustain and enhance Land C4 systems at the operational and tactical level, including the Tactical Communications Network, Battlefield Telecommunications Network, Battlefield Management System and Deployable Information Environment Protected and Secret.
The successful candidate will work effectively in a complex environment, think critically, apply excellent problem-solving skills and manage competing priorities with a focus on mitigating risk. Services are to be delivered in accordance with relevant Australian and international standards, regulations,
Defence requirements and industry best practice.
Key Duties and Responsibilities
Provide System Assessment and Authorisation activities as directed by the CA31 Engineering Manager.
Conduct system Assessment and Authorisation activities in accordance with the ASD Information Security Manual, Protective Security Policy Framework, Defence Security Policy Framework, and Cyber Security Assessment and Authorisation Charter, methodology, templates and guidance.
Perform security assessments using Operational Effectiveness Reviews as the default approach, with Design Effectiveness Reviews where justified.
Audit the effectiveness of system security controls implemented across CA31 capability systems.
Develop Security Assessment Reports, ATO briefs, risk statements and recommended remediation actions.
Identify, analyse, evaluate and elevate cyber security and business risks.
Identify and assess vulnerabilities arising from security exceptions, software defects, and architecture or design weaknesses.
Assess system security architecture and services using structured threat-modelling methodologies.
Protect the confidentiality, integrity and availability of Defence information and systems.
Review security documentation, policies and procedures for alignment with Defence and Australian Government requirements.
Ensure system compliance with mandatory cyber security requirements.
Support configuration governance, including Change Control Boards, and provide risks, mitigations and options for Executive Authority acceptance.
Provide cyber security advice within the defined CA31 assessor scope.
Help CA31 understand and mitigate cyber security risks affecting capability delivery and operations within the LC4 domain.
Build and maintain effective relationships with applicable sustainment products, OEM, operational and security stakeholders.
Technical Skills
Relevant qualifications, industry certification and/or professional experience suitable for eligibility to obtain DCIAB-CSAA endorsement as a Cyber Security Assessor, including CISSP, CISM, ISO ***** Lead Auditor and IRAP accreditation.
Strong understanding of ICT architectures, networks, platforms, cyber/security compliance and governance within the Defence environment.
Demonstrated ability to lead security cyber audits, document outcomes and deliver reports.
Understanding of modern networking, computers and operating systems.
Comprehensive understanding of Defence systems, including C4 capabilities, is highly desired.
Previous Defence, Army or CASG experience is highly desired.
Experience in assessing and evaluating risk is highly desired.
Understanding of the One Defence Capability System is required.
Selection Criteria
Essential
Have an Australian Government security clearance of at least NV1.
Ability to work on site for a minimum of 3 days a week
Qualifications / experience as per above
#J-*****-Ljbffr
📌 Cybersecurity Certification Consultant | Nv1 | Canberra, Melbourne, Remote
🏢 Pinaka Technology Solutions
📍 Canberra