Snowy Hydro is a dynamic, integrated energy business that has been providing on-demand, reliable energy to Australia for generations. Snowy Hydro owns and operates a powerful combination of generation assets, including the mighty Snowy Mountains Scheme, gas and diesel plants, and contracted wind and solar energy. We also provide electricity and gas to about 1 million retail customers through our retail brands Red Energy and Lumo Energy.
About the position:
We are seeking a mid-level operational Cyber Security Analyst to join our team at Snowy. This hands-on "doer" role sits on the operational side of the team, focusing on vulnerability management, assurance, and risk management activities.
You will be responsible for protecting the organisation's information systems, networks, and data by monitoring, identifying, analysing, and responding to security vulnerabilities, while supporting the ongoing improvement of cybersecurity controls across our IT and Operational Technology (OT) environments.
Key Responsibilities:
- End-to-End Vulnerability Management (60% Focus): Lead and execute the full vulnerability management lifecycle, encompassing discovery, risk assessment, prioritisation, and remediation across technology teams and the business.
- Compliance & Risk Assessments: Support ongoing internal and external security audits, ensuring alignment and compliance against key industry frameworks and standards, such as the Australian Energy Sector Cyber Security Framework (AESCSF), ISO 27001 and the Security of Critical Infrastructure.
- Project Security Alignment: Collaborate with project teams to establish clear cybersecurity requirements, ensuring all projects deliver in accordance with established security controls and standards.
- Cyber Security Assurance: Conduct security assessments and assurance activities across systems, applications, and third-party vendors, identify control gaps, and provide recommendations to strengthen the organisation's overall security posture.
- Risk Assessments: Conduct security risk assessments across systems, processes, and third parties; identify, evaluate, and document risks; and work with stakeholders to define appropriate treatment plans and residual risk acceptance.
About the location:
This role can be based in Sydney or Melbourne.
About you:
- Functional Leadership & Autonomy: High degree of self-sufficiency, self-management, and ability to think on your feet. Proven ability to independently lead and drive the vulnerability management function to its next iteration with minimal supervision.
- Technical Experience & Capability: Strong hands-on background across vulnerability management lifecycle tools, as well as technical toolsets in two or more cybersecurity domains (e.g., Tenable, Qualys, EDR, SIEM, PAM, SASE/Netskope, Firewalls, IDAM). A background transitioning from systems engineering or systems administration is highly regarded.
- Communication & Stakeholder Management: Excellent communication skills to work effectively across all levels of the organisation, build constructive relationships with business teams to drive remediations, and present technical concepts clearly.
- Framework Familiarity (Favourable): Knowledge or experience with industry cybersecurity frameworks and legislation—such as the AESCSF, ISO 27001, NIST, IEC 62443, and the Security of Critical Infrastructure Act (SOCI)—is considered a favourable addition.
- Discretion & Safety Focus: Ability to act with absolute discretion when handling sensitive company information, coupled with a commitment to demonstrate and drive the highest level of focus on workplace safety.
Incase you would like to apply to this job directly from the source, please click here