Quick Overview
Job Description
Defence Cyber Security Certification Consultant - Level 3 Indigitise Pty Ltd • Canberra, ACT, au
NO LOCATION RESTRICTIONS WITHIN AUSTRALIA. Occasional travel may be required. If Melbourne or Canberra based, part time office attendance will be expected.
The successful candidate will be a Cybersecurity professional who works effectively in a complex environment, thinks critically, applies excellent problem-solving skills and manages competing priorities with a focus on mitigating risks.
Responsibilities- Assessment and Authorisation
- Provide System Assessment and Authorisation activities as directed by the CA31 Engineering Manager.
- Conduct system Assessment and Authorisation activities in accordance with:
- ASD Information Security Manual (ISM)
- Protective Security Policy Framework (PSPF)
- Defence Security Policy Framework
- Cyber Security Assessment and Authorisation (CSAA) Charter, assessment methodology, templates, and guidance.
- Perform security assessments using Operational Effectiveness Reviews (OER) as the default approach, with Design Effectiveness Reviews (DER) conducted where justified.
- Audit the effectiveness of system security controls implemented across CA31 capability systems.
- Develop and deliver assessment artefacts including:
- Security Assessment Reports (SAR)
- ATO briefs
- Risk statements and recommended remediation actions.
- Risk Identification and Analysis
- Identify, analyse, evaluate, and elevate cyber security and business risks.
- Identify and assess vulnerabilities associated with:
- Security exceptions
- Assess system security architecture and services using structured threat modelling methodologies.
- Protect the Confidentiality, Integrity, and Availability (CIA) of Defence information and systems Governance, Compliance, and Assurance.
- Review system security documentation, policies, and procedures to ensure alignment with Defence and Australian Government requirements.
- Ensure system compliance with mandatory cyber security requirements.
- Support configuration governance processes including the Change Control Boards (CCB) and provide assessment input with risks, mitigations and options for the Executive Authority (EA) to accept.
- Advisory and Stakeholder Engagement
- Provide cyber security advice within the defined assessor scope of the CA31.
- Support CA31 in understanding and mitigating cyber security risks impacting capability delivery and operations within the LC4 domain.
- Build and maintain effective working relationships with:
- OEM
- Operational and security stakeholders
Services are to be provided commensurate with relevant Australian and International Standards, regulations, and Defence requirements. Service providers are to employ industry best practice when undertaking the Services.
Similar jobs
- CS
Defence Cyber GRC Lead - Governance, Risk & ATO
NewC4I Solutions Pty
Penrith, New South Wales🇦🇺Hybrid1 minute agoComplianceTechnology - BM
AI Developer: LLM Agents, Async Python & FastAPI
NewBULLIT MANAGEMENT SERVICES LIMITED
Sydney🇦🇺Hybrid1 minute agoFastAPIGCPLLM+2Technology - TA
Senior Network Engineer
NewTalent
Melbourne, Victoria🇦🇺Hybrid1 minute agoTechnology - DT
Cloud Security & Incident Response Engineer (Automation & IaC)
NewDxc Technology Inc.
Melbourne, Victoria🇦🇺Hybrid1 minute agoAWSAzureTechnology - MA
Hybrid AI-Driven Data Engineer for HealthTech Platform
NewMagentus
Brisbane, Queensland🇦🇺Hybrid1 minute agoDatabricksTechnology - AN
Cyber Risk Analyst - Flexible Work & Impactful Security
NewAnglicare
Sydney🇦🇺Hybrid1 minute agoTechnology