Haystack
← Back to Jobs
Full time
Technology
IP

Defence Cyber Security Certification Consultant - Level 3

Indigitise Pty LtdCanberra, Australian Capital Territory🇦🇺AustraliaPosted 16 Sept 2026

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Canberra, Australian Capital Territory, Australia

Job Description

Defence Cyber Security Certification Consultant - Level 3 Indigitise Pty Ltd • Canberra, ACT, au

NO LOCATION RESTRICTIONS WITHIN AUSTRALIA. Occasional travel may be required. If Melbourne or Canberra based, part time office attendance will be expected.

The successful candidate will be a Cybersecurity professional who works effectively in a complex environment, thinks critically, applies excellent problem-solving skills and manages competing priorities with a focus on mitigating risks.

Responsibilities
  • Assessment and Authorisation
    • Provide System Assessment and Authorisation activities as directed by the CA31 Engineering Manager.
    • Conduct system Assessment and Authorisation activities in accordance with:
      • ASD Information Security Manual (ISM)
      • Protective Security Policy Framework (PSPF)
      • Defence Security Policy Framework
      • Cyber Security Assessment and Authorisation (CSAA) Charter, assessment methodology, templates, and guidance.
    • Perform security assessments using Operational Effectiveness Reviews (OER) as the default approach, with Design Effectiveness Reviews (DER) conducted where justified.
    • Audit the effectiveness of system security controls implemented across CA31 capability systems.
    • Develop and deliver assessment artefacts including:
      • Security Assessment Reports (SAR)
      • ATO briefs
      • Risk statements and recommended remediation actions.
  • Risk Identification and Analysis
    • Identify, analyse, evaluate, and elevate cyber security and business risks.
    • Identify and assess vulnerabilities associated with:
      • Security exceptions
    • Assess system security architecture and services using structured threat modelling methodologies.
    • Protect the Confidentiality, Integrity, and Availability (CIA) of Defence information and systems Governance, Compliance, and Assurance.
    • Review system security documentation, policies, and procedures to ensure alignment with Defence and Australian Government requirements.
    • Ensure system compliance with mandatory cyber security requirements.
    • Support configuration governance processes including the Change Control Boards (CCB) and provide assessment input with risks, mitigations and options for the Executive Authority (EA) to accept.
  • Advisory and Stakeholder Engagement
    • Provide cyber security advice within the defined assessor scope of the CA31.
    • Support CA31 in understanding and mitigating cyber security risks impacting capability delivery and operations within the LC4 domain.
    • Build and maintain effective working relationships with:
      • OEM
      • Operational and security stakeholders

Services are to be provided commensurate with relevant Australian and International Standards, regulations, and Defence requirements. Service providers are to employ industry best practice when undertaking the Services.

Similar jobs