21 Sep
|
Talent
|
Canberra
Job Description
An opportunity is available for an experienced
n
Cyber Security Assessors to support the independent assessment of cyber security risks across complex Defence ICT capabilities. You will provide evidence-based assurance and risk advice that enables senior stakeholders to make informed decisions about the security and operation of critical technology environments.
n
n
Start ASAP through to 30 June ****
n
Canberra strongly preferred, with Melbourne also considered. Work will primarily support Defence environments and will include attendance at Defence sites.
n
Current NV2 security clearance required.
n
Key experience: Cyber security assessments, ICT security assurance, risk analysis, security control assessment and strong knowledge of Australian Government and Defence security frameworks.
n
n
Your Duties Will Include
n
n
Conduct independent cyber security assessments in accordance with Defence and Australian Government security policies, frameworks and assessment methodologies.
n
Assess the effectiveness of security controls and identify security threats, vulnerabilities and associated risks.
n
Prepare clear, evidence-based security assessment reports and risk briefs for technical teams and senior decision-makers.
n
Engage with project teams, system owners, technical specialists and senior stakeholders throughout assessment activities.
n
Provide practical cyber security advice,
guidance and risk-based recommendations.
n
Support assessment prioritisation, assurance activities and broader security reporting requirements.
n
Maintain independence and objectivity throughout assessments, including identifying and declaring potential conflicts of interest.
n
n
Skills And Experience We Are Looking For
n
n
Demonstrated experience conducting ICT security assessments, security audits, assurance reviews or cyber risk engagements.
n
Experience assessing complex ICT environments including networks, cloud services, enterprise systems or emerging technologies.
n
Strong understanding of the Australian Government Information Security Manual (ISM), Protective Security Policy Framework (PSPF) and Defence Security Principles Framework (DSPF).
n
Ability to communicate complex security risks clearly through high-quality written assessments and executive-level reporting.
n
Solid stakeholder engagement skills, ideally gained within Defence or Australian Government environments.
n
Relevant security certifications such as CISSP, CISM, CISA, CRISC, ISO ***** Lead Auditor or IRAP Assessor are highly regarded; equivalent practical experience will also be considered.
n
Solid professional judgement, attention to detail and the ability to provide independent, evidence-based security advice.
n
📌 Cyber Security Assessor (Canberra)
🏢 Talent
📍 Canberra