An opportunity is available for an experienced
Cyber Security Assessors to support the independent assessment of cyber security risks across complex Defence ICT capabilities. You will provide evidence-based assurance and risk advice that enables senior stakeholders to make informed decisions about the security and operation of critical technology environments.
- Start ASAP through to 30 June 2027
- Canberra strongly preferred, with Melbourne also considered. Work will primarily support Defence environments and will include attendance at Defence sites.
- Current NV2 security clearance required.
- Key experience: Cyber security assessments, ICT security assurance, risk analysis, security control assessment and strong knowledge of Australian Government and Defence security frameworks.
Your Duties Will Include
- Conduct independent cyber security assessments in accordance with Defence and Australian Government security policies, frameworks and assessment methodologies.
- Assess the effectiveness of security controls and identify security threats, vulnerabilities and associated risks.
- Prepare clear, evidence-based security assessment reports and risk briefs for technical teams and senior decision-makers.
- Engage with project teams, system owners, technical specialists and senior stakeholders throughout assessment activities.
- Provide practical cyber security advice, guidance and risk-based recommendations.
- Support assessment prioritisation, assurance activities and broader security reporting requirements.
- Maintain independence and objectivity throughout assessments, including identifying and declaring potential conflicts of interest.
Skills And Experience We Are Looking For
- Demonstrated experience conducting ICT security assessments, security audits, assurance reviews or cyber risk engagements.
- Experience assessing complex ICT environments including networks, cloud services, enterprise systems or emerging technologies.
- Strong understanding of the Australian Government Information Security Manual (ISM), Protective Security Policy Framework (PSPF) and Defence Security Principles Framework (DSPF).
- Ability to communicate complex security risks clearly through high-quality written assessments and executive-level reporting.
- Strong stakeholder engagement skills, ideally gained within Defence or Australian Government environments.
- Relevant security certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor or IRAP Assessor are highly regarded; equivalent practical experience will also be considered.
- Strong professional judgement, attention to detail and the ability to provide independent, evidence-based security advice.
- Locations
- Canberra, Australian Capital Territory, Australia · Melbourne, Victoria, Australia
Categories
Skills
ICT Security AssessmentSecurity AuditsRisk AnalysisSecurity Control AssessmentCyber Risk ManagementInformation Security Manual (ISM)Protective Security Policy Framework (PSPF)Defence Security Principles Framework (DSPF)Cloud Services AssessmentNetwork SecurityCISSPCISMCISACRISCISO 27001 Lead AuditorIRAP Assessor