
Security Consultant
- Canberra, ACT
- Permanent
- Full-time
- Assesses risk at the technical or system process level, delivered through the assessment of systems for compliance against defined security control frameworks
- Drafts high-quality risk assessments and reports detailing security issues, technical and governance control improvements, and recommendations to address identified security risks
- Provides an accurate categorisation of threats, threat actors and vulnerabilities, delivered through the completion of security threat and risk assessments of ICT and / or OT systems
- Develops security policies, procedures and plans, to ensure effective governance
- Collaborates with peers across the Digital Intelligence business, both in Australia and overseas, to look for ways to continuously add value to the business, build your professional network, and share experiences
- Understands business and information risk context (typical business drivers, cyber security threats and implementation challenges) of our customers
- Judges risk at a technical and business process level and clearly articulate both verbally and in writing to key stakeholders.
- Reviews effectiveness of controls (in relation to known controls frameworks as appropriate) and proposing proportionate security improvements.
- Analyses and research security technologies to support the development of innovative solutions.
- Measures effectiveness of controls in place
- Measures business impact associated with systems or processes, via document review or structured questionnaires
- Supports interviews or investigations, including on-site visits and stakeholder workshops
- Communicates and works with our customers to assist them in effectively managing cyber security risk
- Familiar with information security standards, such as the Australian Government Information Security Manual (ISM) and 27001
- Familiar with information security frameworks, such as NIST Cybersecurity Framework
- Ideally hold at least one relevant industry certification, such as SANS ICS515, SANS ICS410, CISA, CRISC, GICSP, or CompTIA Security + (or demonstrate on track to achieving)
- Hold a national security clearance, or be willing to obtain.
- Possess strong written and verbal communication skills
- Have demonstrated stakeholder management experience
- Demonstrate attention to detail, be proactive and organised
- Be able to respond to setbacks in an agile and resilient manner