
Cyber Security Engineer
Commonwealth Superannuation Corporation
- Canberra, ACT
- Permanent
- Full-time
- Design, implement, and manage cyber security infrastructure, toolsets & rulesets including areas of Cloud security (Azure and AWS), Microsoft Defender & InTune , firewalls, SIEM, Application Control, PAM, email security, etc.
- Support, maintain and provide advice on uplift and enhancement activities, including ACSC's Essential Eight.
- Review existing security configurations and provide recommendations on improvements.
- Produce security documentation, plans, and procedures on tooling and processes.
- Assess the relevance of new and emerging Cyber Security Suppliers and Technologies.
- Contribute to the Security team meeting its overall responsibilities including where required.
- Assist with cyber security incident response by completing Investigations and remediations.
- Assist with Security Threat & Risk Assessments and relevant tasks.
- Specific duties, deliverables and reporting lines may vary from time-to-time dependent on business needs and priorities. Key objectives and measurements will be captured in the Performance & Development planning cycle, established annually and adapted as needed
- Tertiary qualifications in Cyber Security, Computer Science or equivalent work experience
- AGSVA clearance is desirable
- Hands on experience implementing, configuring, and managing Microsoft Defender (for endpoint, email, Cloud, identities and Cloud apps) and Intune
- Extensive experience in cybersecurity areas including Cloud security, SIEM (Splunk or Sentinal), application control, PAM, email security, network security (firewall and web proxy), etc.
- Security compliance in financial and government environments e.g. APRA 231/234 and ISM.
- Demonstrated knowledge of multiple security frameworks (e.g. NIST, PSPF) and of security best practices for cloud services (IaaS, PaaS & SaaS) particularly AWS and Azure security configuration.
- Demonstrated knowledge of industry good practices such as OWASP, PCI DSS, ISO27001/2, ASD E8, NIST CSF
- Desirable experience in the enterprise design of contemporary technologies such as Identity and Access Management, End Point Protection, DDoS Protection, Data Loss Prevention.
- Demonstrated ability to provide expert security advice, develop quality cyber security controls, processes and policies.
- Excellent interpersonal, liaison and negotiation skills
- Permanent role with flexible and hybrid work options
- Expand your technical expertise with exposure to a breadth of experience
- Tailored learning and career pathways, from advanced technical training to leadership development
- Collaborative, diverse and supportive culture where knowledge-sharing is valued