11 Sep
|
Business Review Group 2
|
Australia
11 Sep
Business Review Group 2
Australia
About the job Cyber Security Lead
CYBER SECURITY LEAD
Reference Number: 6213
SPO: MIWS SPO
Project: SEA4000 Phase 6
Skill Level: Level 3
Location: Canberra, ACT
Working Arrangements: On-site only (No remote or hybrid available)
Start Date: ASAP
Indicative Duration: 3 months
Security Clearance Required
Role Overview
The Cyber Security Lead will provide senior subject matter expertise, oversight and advice across System Security accreditation activities supporting the SEA4000 Phase 6 Combat Management System (CMS) workplace.
The role acts as the Head of Discipline for System Security across the engineering team and is the primary point of contact for external and platform stakeholders in relation to CMS System Security matters.
The successful candidate will coordinate cyber security assessment and authorisation activities, provide assurance over security program outputs, and support stakeholders across Cyber Security, Physical Security and Emission Security (EMSEC).
Key Responsibilities
The Cyber Security Lead will:
- Act as Head of Discipline for System Security across the engineering team.
- Coordinate System Security activities across engineers, project teams and the Combat System Integration Integrated Product Team (CSI-IPT).
- Liaise with MIWS product directorates, CASG projects and stakeholders to obtain relevant product and security information.
- Provide guidance to the CSI-IPT security and cyber security organisation.
- Provide assurance over the CSI-IPT cyber security program and associated outputs.
- Facilitate engagement between MIWS and DCE stakeholders regarding:
- Cyber Security.
- Physical Security.
- Emission Security (EMSEC).
- Manage and coordinate Cyber Security Assessment and Authorisation activities within the Hobart CMS scope.
- Act as the primary System Security point of contact for CEIP/DCE.
- Provide System Security SME support to MIWS Directorates, including OEM engagement.
- Guide MIWS personnel through cyber security assurance processes.
- Co-chair relevant DDG CSI-IPT and DCE System Security and Software Working Groups.
- Provide SME input to Saab EPA System Security Working Groups.
- Participate in broader DCE engineering, security, interface, integration and Test & Evaluation working groups.
- Support Test and Evaluation Working Group (TEWG) and Verification & Validation activities as required.
Security Assessment and Assurance
The successful candidate will:
- Advise on or conduct security risk assessments within the SEA4000 scope.
- Contribute to Cyber Security Assessment and Authorisation documentation, including:
- System Security Plans (SSP).
- SSP-A documentation.
- Security Risk Management Plans (SRMP).
- Review stakeholder information supporting updates to the Hobart Whole-of-System threat model using the Cyber Evaluation and Management Toolkit (CEMT).
- Review engineering documents and deliverables from a security perspective.
- Provide security input to Whole-of-System design reviews and other relevant reviews.
- Support System Security activities associated with commissioning activities.
- Provide advice regarding the security capabilities and features of Defence and industry-approved hardware and software.
- Provide security liaison and guidance to DCE stakeholders.
Key Stakeholders
The role will engage extensively with stakeholders including:
- AusCMS Product Directorate – MIWS.
- AEGIS Product Directorate – MIWS.
- DDG CSI-IPT.
- Saab.
- DCE stakeholders.
- CASG project and product teams.
- Engineering, software, Test & Evaluation and security personnel.
Essential Experience and Qualifications
Candidates must demonstrate:
- At least 5 years' experience as a Defence Systems Engineer.
- Detailed understanding of the Defence Security Principles Framework (DSPF).
- Detailed understanding of the Australian Government Information Security Manual (ISM).
- Familiarity with the Defence Cyber Security Assessment and Authorisation Framework.
- At least one relevant information security certification, such as:
- CISSP.
- CISM.
- GSLC.
- CISA.
- Or equivalent.
- Familiarity with recognised information security frameworks such as:
- ISO 27001.
- CMMC.
- Comparable security frameworks.
Desirable Experience
Highly relevant experience includes:
- Conducting Security Risk Assessments within a Defence environment.
- Defence cyber security accreditation and assurance.
- Combat Management Systems.
- Maritime or naval combat systems.
- Security engineering within complex Defence acquisition or sustainment environments.
- Physical Security and EMSEC.
- Security support to engineering design, integration, Test & Evaluation and Verification & Validation activities.
📌 Cyber Security Lead (Australia)
🏢 Business Review Group 2
📍 Australia