The Opportunity: You’ll assess ICT systems, platforms and services across on-premises, hybrid cloud, cloud, SaaS and AI-enabled environments, ensuring alignment with Australian Government security frameworks including the PSPF, ISM and Essential Eight.
Working closely with technical teams and senior stakeholders, you’ll review security documentation and architecture, identify risks and control gaps, and deliver clear, practical assessment reports and remediation advice.
Key Requirements
- 5+ years’ experience
in cyber security risk assessments, security assurance or ICT governance
- Strong working knowledge of
PSPF, ISM and Essential Eight
- Demonstrated experience supporting ATO or equivalent security authorisation processes
- Experience assessing systems across on-prem, hybrid and cloud (Azure/AWS)
- Ability to assess
AI-enabled systems or apply assurance skills to AI governance and data risks
- Strength in reviewing security documentation, architecture, risk artefacts and control evidence
- Proven ability to translate findings into clear, concise risk advice and recommended treatments
- Strong communication skills, stakeholder engagement capability and the ability to work independently
- Certifications such as CISSP, CISM, CRISC, CISA, Azure Security, AWS Security
- IRAP assessor experience or experience supporting IRAP assessments
- Background in Australian Government cyber security, ICT assurance, risk management or security authorisation environments
We are an inclusive employer committed to fostering a diverse and accessible workplace. We encourage applications from Aboriginal and Torres Strait Islander peoples, people with disabilities, LGBTQIA+ individuals, people of all ages, and those from culturally and linguistically diverse backgrounds.
