Proficient in conducting security risk assessments of ICT systems and applications in accordance with the Protective Security Policy Framework (PSPF) and the Information Security Manual (ISM), with a robust focus on accuracy and attention to detail. The resource will review and contribute to the development of the full suite of security documentation, including System Security Plan Annexes (SSP-As) and System Security Plans (SSPs).
The applicant must have:
- 3-5 years’ experience working within Government conducting security risk assessments in a cyber team.
- Demonstrated experience in conducting security risk assessments with Azure Cloud, Legacy ICT systems, AI Technology and complex systems.
- Current knowledge and experience providing guidance on application and system designs relating to PSPF, ISM and Essential Eight.
- Experience in liaising with non-technical and technical stakeholders in relation to cyber security issues, system risks and recommendations.
- Demonstrated strong written and verbal communication skills, including experience preparing and delivering executive-level briefings. Assist in identifying opportunities to strengthen the security posture of the department’s environment.
- Strong understanding of networking infrastructure.
- Understanding of Operational Technologies will be an advantage.