Why This Role Stands Out
As a Cyber Security Consultant at Harvey Norman, you'll leverage your expertise to embed security-by-design principles across a global organization, developing practical solutions and enhancing security frameworks. This on-site role offers significant growth potential within a reputable company, alongside opportunities for continuous learning and employee discounts, making it an ideal position for a proactive security professional looking to make a substantial impact.
Quick Overview
Job Description
e.g. "Service Desk Analyst Homebush West"
Work type- Full Time 1
Australia
CategoriesFranchisor Office
Cyber Security ConsultantJob no: 577083
Work type: Full Time
Location: Homebush West
Categories: Information Technology
- Opportunities to make discounted purchases on a great range of products.
- Access to Udemy an online training platform with over 5,500 courses.
- Experience working within a diverse, unique, and successful global organisation.
As one of Australia's largest retailers of lifestyle products, with more than 300 complexes worldwide, Harvey Norman has been a part of almost every Australian's shopping experience. Whether getting the latest electronic gadgets, or furnishing your first home, Harvey Norman is the place where you can shop with confidence.
About the role
Reporting to the Cyber Security Assurance Manager and based onsite at the Silverwater Corporate Office, you will work closely with security leaders, project teams, solution architects, business stakeholders and vendors to embed security-by-design principles across business and technology initiatives. Acting as a trusted security advisor, you will assess proposed solutions, identify security risks and recommend practical controls that support secure business outcomes.
This role will involve conducting security and third-party risk assessments, reviewing solution designs, coordinating security testing and managing identified risks through to remediation or formal acceptance. You will also contribute to improving the organisation's information security assurance frameworks, processes and standards.
You will
- Conduct Information Security Assurance reviews across business and technology initiatives, ensuring security-by-design principles are embedded throughout the project lifecycle from initiation through to implementation and closure.
- Develop, maintain and communicate security requirements, assessment criteria, standards and assurance guidance to support the consistent application of security controls across projects and third-party engagements.
- Partner with solution architects, project teams, business stakeholders and vendors to identify security risks, assess potential business impact and recommend pragmatic security controls and risk treatment options.
- Perform Third Party Risk Assessments (TPRA) of vendors, products and services, including the review of security questionnaires, certifications, audit reports and supporting evidence to support informed risk-based decision-making.
- Review solution architectures, designs, integrations, data flows and technology implementations to ensure alignment with organisational security requirements, standards and industry best practices.
- Coordinate and perform security assessment activities including vulnerability assessments, security configuration reviews, web application security testing, external penetration testing engagements etc.
- Review security assessment findings and work with project teams, vendors and stakeholders to ensure identified vulnerabilities, weaknesses and security risks are appropriately remediated or formally accepted.
- Perform Information Security Risk Assessments (ISRA) for projects, technology implementations and business initiatives in accordance with Harvey Norman's risk management framework.
- Document, track, monitor and escalation of identified security risks through established governance processes, ensuring remediation activities, mitigation plans and risk acceptance decisions are managed through to closure.
- Contribute to the continuous improvement and maturity of the Information Security Assurance function through the adoption of industry best practices and enhancement of assurance methodologies, templates and processes.
About you
You are a proactive cyber security professional who can balance security requirements with business needs and provide practical, risk-based advice to stakeholders. With strong analytical skills, sound judgement and attention to detail, you take a risk-based approach and remain current with emerging cyber threats, technologies and industry practices.
You will have
- At least 5 years' experience in cyber security, information security assurance, risk management or a related area.
- Experience reviewing solution architectures, technology implementations, integrations and data flows.
- Experience conducting information security and third-party risk assessments.
- Exposure to vulnerability assessments, security reviews and penetration testing activities.
- Sound knowledge of security frameworks and practices such as ISO 27001, NIST Cybersecurity Framework, OWASP, Identity and Access management, Zero Trust etc
- An understanding of security principles across cloud, infrastructure, networks, applications and integrations.
- Strong stakeholder engagement, communication and influencing skills.
- The ability to manage multiple projects and competing priorities in a fast-paced environment.
Qualification:
- Degree qualification in Information Technology, Computer Science, Cyber Security or a related discipline, or equivalent industry experience.
- Industry-recognised Information Security certifications such as CISSP, CISM, CRISC, CCSP or equivalent certifications (preferred).
- Relevant security architecture, cloud security, risk management or security assurance certifications will be highly regarded.
This opportunity will provide:
- Salary packaging and novated leasing options for eligible employees.
- Company paid parental leave for eligible employees.
- Access to Udemy an online training platform with over 5,500 courses.
- Professional development and career progression.
- Experience working with an Iconic Australian Brand with global success in NZ, Asia, and Europe.
- A supportive team environment that celebrates diversity and promotes a healthy work and family life balance.
- Opportunities to make discounted purchases on a great range of products and services.
Please note that only people with the right to work in Australia should apply for this position.
Similar jobs
- NE
Backend Technical Lead (Golang)
NewNine Entertainment
New South Wales🇦🇺Hybrid56 minutes agoMicroservicesAWSAgile+1Technology - XE
Engineer - Salesforce
NewXero
Melbourne, Victoria🇦🇺Hybrid4 hours agoSalesforceAgileGong+1Technology - IN
Senior Software Engineering Manager, Maritime Autonomy
NewInvestedintheMission
Sydney🇦🇺Hybrid4 hours agoTechnology - HY
Software Engineer
NewHypex
Melbourne, Victoria🇦🇺Hybrid8 hours agoNext.jsNode.jsJavaScript+3Technology - XA
Copy of Mobile Developer
NewXapply
Sydney🇦🇺Hybrid8 hours agoSQLAndroid SDKJetpack Compose+4Technology - XE
Salesforce Platform Engineer - Hybrid, Scalable & AIDriven
NewXero
Melbourne, Victoria🇦🇺Hybrid11 hours agoTechnology