Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.
Job Summary:
As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating setting to ensure compliance with organization security policies and controls. Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develop mitigation plans. Partners with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts. This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.
RESPONSIBILITIES
Essential Job Duties and Responsibilities
Perform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.
Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.
Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits. Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilities
Lead the design and control reviews and assessments to support continuous compliance with security policies and standards
Manage security review processes for all solutions to ensure they their design and implementation meets compliance requirements – including: PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements like the Australian Essential 8 and New Zealand NZ-ISM. Document and actively communicate any areas where the solutions and processes are not fully compliant.
Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.
Identify stakeholders in remediation of compliance gaps and actively escalat
#J-18808-Ljbffr
📌 Cyber Security Risk Analyst (Sydney)
🏢 Cubic Transportation Systems
📍 Sydney
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.