Job Description
Remote is seeking an experienced Cyber Advisor to join a team within ASD and help strengthen the security of its ICT systems, projects and services. The successful candidate will provide expert cyber security and secure-by-design advice, review solution architectures against the ISM and Essential Eight, and support delivery teams to embed appropriate security controls throughout the system lifecycle.
The role will also conduct cyber security and risk assessments, develop and maintain security documentation, and support system authorisation, accreditation and IRAP-related activities. (LH-07265)
Role Description
Key duties and responsibilities
-
Conduct reviews and provide input into the development of the entire Security suite.
-
Provide expert advice on secure by design architecture principles and cyber security best practice.
-
Review ICT solution designs for alignment with the ISM and Essential Eight maturity requirements.
-
Support architecture and engineering teams to embed cyber security controls into solution designs.
-
Conduct cyber security assessments and risk assessments across services.
-
Review and update system security documentation including - System Risk Management Plans (SRMPs), System Security Plans (SSPs) and SSP Annexes, Incident Response Plans (IRPs), and Disaster Recovery Plans (DRPs).
-
Support system accreditation and IRAP related documentation.
Technical skills
-
Experience working within an Australian Government agency in a cyber security or security architecture role.
-
Demonstrated experience conducting cyber security risk assessments and producing security artefacts required for system authorisation.
-
Strong understanding of networking infrastructure.
-
Ability to analyse network architectures and assess cyber security risks.
Essential criteria
-
Information Assurance level 6: Develops information assurance policy, standards and guidelines. Contributes to the development of organisational strategies that address the evolving business risk and information control requirements. Drives adoption of and adherence to policies and standards. Ensures architectural principles are followed, requirements are defined and rigorous security testing is applied. Ensures accreditation processes support and enable organisational objectives. Monitors environmental and market trends and assesses any impact on organisational strategies, benefits and risks.
-
Vulnerability Assessment level 5: Plans and manages vulnerability assessment activities within the organisation. Evaluates, selects and reviews vulnerability assessment tools and techniques. Provides expert advice and guidance to support the adoption of agreed approaches. Obtains and acts on vulnerability information and conducts security risk assessments, business impact analysis and accreditation on complex information systems.
-
Information Security level 5: Provides advice and guidance on security strategies to manage identified risks and ensure adoption and adherence to standards. Contributes to development of information security policy, standards and guidelines. Obtains and acts on vulnerability information and conducts security risk assessments, business impact analysis and accreditation on complex information systems. Investigates major breaches of security and recommends appropriate control improvements. Develops new architectures that manage the risks posed by new technologies and business practices.