17 Sep
|
Indigitise
|
Canberra
17 Sep
Indigitise
Canberra
Job Description
Defence Cyber Security Certification Consultant - Level 3 Indigitise Pty Ltd • Canberra, ACT, au
n
NO LOCATION RESTRICTIONS WITHIN AUSTRALIA. Occasional travel may be required. *If Melbourne or Canberra based, part time office attendance will be expected.
n
The successful candidate will be a Cybersecurity professional who works effectively in a complex setting, thinks critically, applies excellent problem-solving skills and manages competing priorities with a focus on mitigating risks.
n
Responsibilities
n
n
- Assessment and Authorisationn n
- Provide System Assessment and Authorisation activities as directed by the CA31 Engineering Manager.
n
- Conduct system Assessment and Authorisation activities in accordance with:n n
- ASD Information Security Manual (ISM)
n
- Protective Security Policy Framework (PSPF)
n
- Defence Security Policy Framework
n
- Cyber Security Assessment and Authorisation (CSAA) Charter, assessment methodology, templates, and guidance.
n
n
- Perform security assessments using Operational Effectiveness Reviews (OER) as the default approach, with Design Effectiveness Reviews (DER) conducted where justified.
n
- Audit the effectiveness of system security controls implemented across CA31 capability systems.
n
- Develop and deliver assessment artefacts including:n n
- Security Assessment Reports (SAR)
n
- ATO briefs
n
- Risk statements and recommended remediation actions.
n
n
n
- Risk Identification and Analysisn
n
- Identify, analyse,
evaluate, and elevate cyber security and business risks.
n
- Identify and assess vulnerabilities associated with:n n
- Security exceptions
n
n
- Assess system security architecture and services using structured threat modelling methodologies.
n
- Protect the Confidentiality, Integrity, and Availability (CIA) of Defence information and systems Governance, Compliance, and Assurance.
n
- Review system security documentation, policies, and procedures to ensure alignment with Defence and Australian Government requirements.
n
- Ensure system compliance with mandatory cyber security requirements.
n
- Support configuration governance processes including the Change Control Boards (CCB) and provide assessment input with risks, mitigations and options for the Executive Authority (EA) to accept.
n
n
- Advisory and Stakeholder Engagementn
n
- Provide cyber security advice within the defined assessor scope of the CA31.
n
- Support CA31 in understanding and mitigating cyber security risks impacting capability delivery and operations within the LC4 domain.
n
- Build and maintain effective working relationships with:n n
- OEM
n
- Operational and security stakeholders
n
n
n
n
Services are to be provided commensurate with relevant Australian and International Standards, regulations, and Defence requirements. Service providers are to employ industry best practice when undertaking the Services.
📌 Defence Cyber Security Certification Consultant - Level 3 (Canberra)
🏢 Indigitise
📍 Canberra