Job Description
Defence Cyber Security Certification Consultant - Level 3 Indigitise Pty Ltd • Canberra, ACT, au
n
NO LOCATION RESTRICTIONS WITHIN AUSTRALIA. Occasional travel may be required. *If Melbourne or Canberra based, part time office attendance will be expected.
n
The successful candidate will be a Cybersecurity professional who works effectively in a complex setting, thinks critically, applies excellent problem-solving skills and manages competing priorities with a focus on mitigating risks.
n
Responsibilities
n
n
Assessment and Authorisationn
n
Provide System Assessment and Authorisation activities as directed by the CA31 Engineering Manager.
n
Conduct system Assessment and Authorisation activities in accordance with:n
n
ASD Information Security Manual (ISM)
n
Protective Security Policy Framework (PSPF)
n
Defence Security Policy Framework
n
Cyber Security Assessment and Authorisation (CSAA) Charter, assessment methodology, templates, and guidance.
n
n
Perform security assessments using Operational Effectiveness Reviews (OER) as the default approach, with Design Effectiveness Reviews (DER) conducted where justified.
n
Audit the effectiveness of system security controls implemented across CA31 capability systems.
n
Develop and deliver assessment artefacts including:n
n
Security Assessment Reports (SAR)
n
ATO briefs
n
Risk statements and recommended remediation actions.
n
n
n
Risk Identification and Analysisn
n
Identify,
analyse, evaluate, and elevate cyber security and business risks.
n
Identify and assess vulnerabilities associated with:n
n
Security exceptions
n
n
Assess system security architecture and services using structured threat modelling methodologies.
n
Protect the Confidentiality, Integrity, and Availability (CIA) of Defence information and systems Governance, Compliance, and Assurance.
n
Review system security documentation, policies, and procedures to ensure alignment with Defence and Australian Government requirements.
n
Ensure system compliance with mandatory cyber security requirements.
n
Support configuration governance processes including the Change Control Boards (CCB) and provide assessment input with risks, mitigations and options for the Executive Authority (EA) to accept.
n
n
Advisory and Stakeholder Engagementn
n
Provide cyber security advice within the defined assessor scope of the CA31.
n
Support CA31 in understanding and mitigating cyber security risks impacting capability delivery and operations within the LC4 domain.
n
Build and maintain effective working relationships with:n
n
OEM
n
Operational and security stakeholders
n
n
n
n
Services are to be provided commensurate with relevant Australian and International Standards, regulations, and Defence requirements. Service providers are to employ industry best practice when undertaking the Services.