About Us
CEA is an Australian Commonwealth company that designs, develops, manufactures and sustains advanced active phased array radar systems. The company’s design principles and commitment to investment in research and development ensures innovative thinking, technological skill, and quality fabrication.
Our programs include the ANZAC and Hunter Class frigates and air defence applications for Army and Air Force, and Range applications. Through our longstanding and ongoing collaboration with Defence, CEA Technologies has undertaken research and development into all aspects of active electronically scanned array technologies. This has resulted in the creation of a highly modular and scalable product suite, which have become integral to a wide range of critical Defence capabilities.
The Position
This position is responsible for leading the governance, risk and compliance outcomes for CEA cyber security. Oversees, evaluates, and supports the documentation, validation, assessment, and authorisation processes necessary to assure that existing and new information technology (IT) systems meet the organisation's cybersecurity and risk requirements. Ensures appropriate treatment of risk, compliance, and assurance from internal and external perspectives.
This position works within the CEA Cyber Security team and will need to engage with various stakeholders as a cyber-security governance, risk and compliance expert and trusted advisor.
Key Responsibilities:
- Enhance CEA’s cyber security posture through leadership in the governance, risk and compliance domains.
- Plan, implement and manage cyber security governance, risk and compliance systems and outcomes.
- Support cyber security policy, procedure and other compliance documentation development.
- Lead system authorisation activities including internal and external engagements.
- Support the design and implementation of architecture for security operations.
- Conduct risk assessments and administer cyber security risk information within the CEA Enterprise Risk Management Framework and authorising body frameworks where required.
- Document performance metrics for corporate reporting cycles
- Liaise with stakeholders and vendors to support the implementation of security solutions
Our Benefits
- Six weeks of paid annual leave per year
- Superannuation of 14.0%
- Free car parking
- Paid parental, compassionate, defence reserve & voluntary emergency services leave
- Employee assistance and wellbeing programs
- Health insurance for defence supporters and their families
- Salary packaging for novated leasing
- Opportunities for professional growth and development
Our Ideal Candidate
- Demonstrated experience and knowledge of contemporary cyber-security governance, risk and compliance methodologies and frameworks.
- Sound knowledge of cyber-security principles.
- Sound knowledge of networking principles.
- Ability to develop and implement solutions to reduce risk to networks and systems.
- An ability to engage and work productively with the IT Operations team.
- Knowledge of implementing the controls found within Defence Security Principles Framework (DSPF), Information Security Manual (ISM) and the Essential Eight (E8).
- Sound abilities in analysis and critical thinking.
- Sound verbal and written communication skills with ability to interact with technical and non-technical stakeholders.
- Sound interpersonal skills, with an ability to participate within and contribute to a small team environment.
- Knowledge of the MITRE ATT&CK; Framework is desirable.
Eligibility
- An Australian Citizen;
- Eligible to obtain and maintain an AGSVA clearance – Negative Vetting 2.
- ITAR – This position requires employees to access equipment and data that is subject to U.S International Traffic and Arms Regulation (ITAR). As such, applicants must disclose the following information at the time of application.
- Place of Birth
- Countries of current or past citizenship (including any dual citizenship or nationality) and residence,
- Countries of issue for current and past passports and
- Other information related to their nationality for security and ITAR compliance purposes.
To find out more about our Citizenship and Nationality requirements, please visit www.cea.com.au
How to apply
Click on the 'Apply Now' button below. Please include a current copy of your resume and complete the screening questions. Applications without these elements will not be considered.
CEA encourages the submissions of early applications as we may review, short-list and/or conduct interviews for this role prior to the closing date.
Diversity, Equality and Inclusion at CEA
CEA is committed to fostering a diverse, equitable and inclusive environment. As an Equal Opportunity Employer, we strive to create a culture where all employees are respected and empowered to contribute positively to our organisation, regardless of their cultural background, age, gender identity, neurodiversity, disability, family and carer commitments, religion or sexuality. We welcome applications from veterans, those returning from a career break, people with disabilities and those who identify as Aboriginal and Torres Strait Islander.
For information on Equal Employment Opportunity & Privacy or Security & Citizenship requirements please visit www.cea.com.au/opportunities-at-cea
Should you require any adjustments throughout the recruitment process, please let us know. You can also email
[email protected] for a confidential discussion.
Unsolicited resumes from recruitment agencies will not be accepted
📌 Governance, Risk and Compliance Cyber Lead (Canberra)
🏢 CEA Technologies Pty
📍 Canberra