Cyber Security Adviser - Risk and Compliance Analyst at Clicks IT Recruitment (NSW)
Australia, Saxony, Australia -
Full Time


Start Date

Immediate

Expiry Date

29 Nov, 26

Salary

0.0

Posted On

31 Aug, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Technology & Services

Description

About the job

Cyber Security Adviser | Governance, Risk & Compliance (GRC)


Role based in VIC, NSW, ACT, QLD

12 months with 12-month extension 

Baseline clearance Required 

About the Role


We are seeking experienced Cyber Security Advisers to lead and support the delivery of governance, risk, and compliance activities.

Working in close collaboration with the Cyber Operations branch and project and program stakeholders, the Cyber Governance Risk and Compliance teams play a critical role in meeting community expectations by ensuring digital services are secure, reliable, and accessible.



Key Responsibilities

  • Conduct Security Risk Assessments (SRAs) for new and existing systems.
  • Assess threats, vulnerabilities, and Foreign Ownership, Control and Influence (FOCI) risks.
  • Develop risk treatment strategies and security control baselines.
  • Perform Security Impact Assessments (SIAs) to determine appropriate security assessment pathways.
  • Review and analyse IRAP assessments, penetration testing reports, SOC 1 and SOC 2 reports.
  • Evaluate security documentation including Security Risk Assessments (SRA) and Security Risk Management Plans (SRMPs).
  • Support security authorisation and ongoing compliance activities.
  • Issue, review, and reassess Security Approval to Operate (SATO) outcomes.
  • Prepare reports, briefings, and presentations for executive-level audiences.

 

Skills & Experience Essential

  • Demonstrated experience conducting Security Risk Assessments (SRAs) and Security Impact Assessments (SIAs).
  • Strong understanding of information security principles, risk management frameworks, and governance practices.
  • Knowledge of security standards and frameworks including:
    • ISO 27001
    • NIST Cybersecurity Framework
    • Information Security Manual (ISM)
    • Protective Security Policy Framework (PSPF)
  • Experience supporting security authorisation and accreditation processes.
  • Ability to review and interpret security assurance reports including IRAP, penetration testing, SOC 1, and SOC 2 assessments.
  • Strong knowledge of information security principles, risk management frameworks, and standards such as ISO 27001, ISM, NIST, and PSPF.
  • Demonstrated experience conducting SRAs and SIAs, including threat modelling, risk treatment planning, and control effectiveness evaluation.
  • Familiarity with government and enterprise authorisation frameworks, including security accreditation processes and compliance in multi-vendor and cloud environments.
  • Extensive knowledge of Artificial Intelligence (AI) focusing on emerging risks and best practices
  • Extensive knowledge of Mainframe environment focusing on emerging risks and best practices
  • Extensive knowledge of Cloud technologies (AWS, Azure, SaaS etc) focusing on emerging risks and best practices
  • Anticipate regulatory changes and shifting threat and vulnerability landscapes to plan and execute on improvement opportunities to system authorisation and cyber risk management practices.

Please note to apply for this role you must have a minimum of an Active Baseline security clearance 


Responsibilities
Loading...