20 Sep
|
Client 1
|
Canberra
Role Title
Cyber Security Assessor
Location
Canberra, ACT OR Melbourne, VIC (Yallambie)
Working Arrangement
Hybrid arrangements available. Travel to Defence sites may be required.
Clearance Required
Negative Vetting 2 (NV2) Security Clearance.
Company Overview
Our client supports the Australian Defence sector by delivering independent cyber security assessment and assurance services across a range of ICT capabilities. The organisation plays a critical role in identifying cyber security risks and providing evidence-based recommendations that support informed risk management and system authorisation decisions.
Job Description
We are seeking an experienced Cyber Security Assessor (SFIA SCTY Level 5) to conduct independent cyber security assessments across Defence ICT environments. This position is responsible for evaluating security controls, identifying cyber risks, providing assurance activities, and delivering high-quality assessment reports to technical and senior stakeholders.
The successful candidate will bring solid cyber security assessment experience, exceptional stakeholder engagement skills, and a sound understanding of Defence and Australian Government security frameworks.
Duties and Responsibilities
- Conduct cyber security assessments in accordance with Defence and Australian Government security policies, frameworks and methodologies.
- Assess the effectiveness of security controls and identify threats, vulnerabilities and risks.
- Produce clear, evidence-based assessment reports, risk briefs and recommendations.
- Engage with project teams, system owners, authorising delegates and senior stakeholders.
- Support assessment prioritisation, assurance activities and reporting requirements.
- Provide cyber security advice and risk-based recommendations.
- Maintain independence, objectivity and professional integrity throughout assessment activities.
- Identify and declare any actual, perceived or potential conflicts of interest.
Education/Certifications Required
Candidates should ideally hold certifications from both leadership and risk/audit disciplines, including:
Security Leadership and Management
- CISSP
- CISM
- GSLC
Audit, Assessment and Risk
- CISA
- CRISC
- GSNA
- ISO 27001 Lead Auditor
- PCI QSA
Additional desirable certifications include:
- ASD IRAP Assessor
- OSCP
Applicants without certifications may still be considered where they can demonstrate equivalent experience and expertise.
Knowledge/Skills Required
- Experience conducting ICT security assessments, security audits, assurance reviews or cyber risk engagements.
- Experience assessing complex ICT systems, networks, cloud platforms and emerging technologies.
- Strong cyber risk assessment and reporting capabilities.
- Knowledge of the Australian Government Information Security Manual (ISM).
- Knowledge of the Protective Security Policy Framework (PSPF).
- Knowledge of the Defence Security Principles Framework (DSPF).
- Understanding of Defence assessment and authorisation processes.
- Strong understanding of cyber security risk management methodologies and contemporary cyber threats.
- Excellent written and verbal communication skills.
- Ability to communicate technical risks to both technical and non-technical audiences.
- High attention to detail and report writing capability.
Employment Benefits
- Opportunity to contribute to critical Defence cyber security initiatives.
- Work alongside highly skilled cyber security professionals.
- Exposure to complex and nationally significant ICT environments.
- Flexible and hybrid working arrangements where approved.
- Ongoing professional development and certification support opportunities.
Diversity and Inclusion
We are committed to building diverse teams that reflect the communities we serve. We encourage applications from people of all backgrounds, cultures, abilities, genders and experiences.
Veterans
Veterans and ex-serving members of the Australian Defence Force are strongly encouraged to apply. Your experience, leadership and understanding of Defence environments will be highly regarded.
#J-18808-Ljbffr
📌 Cyber Security Assessor (Canberra)
🏢 Client 1
📍 Canberra