This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The ICT Cyber Security Advisor will work within the Integrated Air and Missile Defence (IAMD) AIR6500 Series program. The program consists of AIR6500-1 Joint Battle Management System, AIR6502-1 Medium Range Ground Based Air Defence Capability with AIR6503 -1 (emerging) Advanced High Speed Missile Defence (AHSMD). The ICT Security Advisor will work within the AIR6500 Series Chief Engineer team reporting to the System-of-Systems Security Manager and will be required to liaise and engage with other functions within the broader IAMD program and Industry members.
Job Responsibility:
Ensuring the ICT systems are designed, developed, operated and maintained in accordance with the Australian Government Information Security Manual (ISM), Defence Security Principles Framework (DSPF), the Australian Communications Security Instructions (ACSI) suite of publications and other relevant Defence security instructions
Ensuring appropriate security measures and controls are implemented for ICT systems on the Program to ensure risks to the confidentiality, integrity or availability of those ICT systems and their information are managed as per Defence Security requirements
Identifying threats and vulnerabilities arising from the design of ICT systems in the Program
ensuring that they are appropriately managed and mitigated as per the respective system’s Security Risk Management Plans
Ensuring that system Standard Operating Procedures (SOP) and any other additional required artefacts are developed and maintained in accordance with applicable security policies and ICT system certification and accreditation requirements
Reviewing and providing advice on Defence security documentation for ICT systems
Working with peers and team members to educate them on their responsibilities and ensure compliance with the ICT Security documentation package approved for the Program
Advising Project Engineering Managers and C4ISR Leads, within the Program, on development of ICT Security documentation, certification and accreditation requirements
Liaising with other Defence Groups and Agencies to obtain advice and guidance for ICT Security implementation in support of the Program
Requirements:
Minimum 10 years of experience in an information technology role specialising in information security
Technical knowledge of Defence IT Security principles
Experience working with the Australian Signals Directorate, Chief Information Officer Group or Capability Acquisition and Sustainment Group, within the Department of Defence Portfolio
Recent experience in authoring Defence ICT Security documentation
Experience in the Certification, Risk Management, Vulnerability Assessment and Management (CRVM) and Information Assurance (IA) of Defence and National Security ICT and Operational Technology (OT) systems
Nice to have:
Experience working with DevSecOps and Agile delivery methodologies would be highly regarded
Qualified Defence IRAP Assessor
Certified Defence Information Security Registered Assessor (DRAP)
In-depth understanding of: Australian Government cyber and protective security requirements in the Information Security Manual (ISM), Defence Security Policy Framework (DSPF), Industry standards including National Institute of Science and Technology (NIST), Common Criteria and ISO 27000