Defence Cyber Security Certification Consultant - Level 3
- Hiring from
- Australia
- Work type
- Hybrid
- Posted
- Oct 1, 2026
Working Arrangements
NO LOCATION RESTRICTIONS WITHIN AUSTRALIA Occasional travel may be required. *If Melbourne or Canberra based, part time office attendance will be expected
Essential criteria
Mandatory Experience and / or qualifications Demonstrated relevant qualifications, industry certification, and/or professional experience assessed as suitable for eligibility to obtain DCIAB –CSAA endorsement as a Cyber Security Assessor, including (but not limited to) CISSP, CISM, ISO 27001 Lead Auditor, and IRAP accreditation; Strong understanding of ICT architectures, networks, platforms, cyber/security compliance and governance within the Defence environment Demonstrated ability to lead security cyber audits, documenting outcomes and delivering reports of outcomes. Understanding of modern networking, computers and operating systems; and Ability to work in a team
Job Description
NO LOCATION RESTRICTIONS WITHIN AUSTRALIA Occasional travel may be required. *If Melbourne or Canberra based, part time office attendance will be expected
This role is responsible for the conduct of following tasks
and activities:
a. Assessment and Authorisation:
1) Provide System Assessment and Authorisation activities as
directed by the CA31 Engineering Manager.
2) Conduct system Assessment and Authorisation activities in
accordance with:
a) ASD Information Security Manual (ISM)
b) Protective Security Policy Framework (PSPF)
c) Defence Security Policy Framework
d) Cyber Security Assessment and Authorisation (CSAA)
Charter, assessment methodology, templates, and guidance.
3) Perform security assessments using Operational
Effectiveness Reviews (OER) as the default approach, with Design Effectiveness
Reviews (DER) conducted where justified.
4) Audit the effectiveness of system security controls
implemented across CA31 capability systems.
5) Develop and deliver assessment artefacts including:
a) Security Assessment Reports (SAR)
b) ATO briefs
c) Risk statements and recommended remediation actions.
b. Risk Identification and Analysis:
1) Identify, analyse, evaluate, and escalate cyber security
and business risks
2) Identify and assess vulnerabilities associated with:
a) Security exceptions
b) Software defects
c) Architecture or design weaknesses
4) Protect the Confidentiality, Integrity, and Availability
(CIA) of Defence information and systems Governance, Compliance, and Assurance.
5) Review system security documentation, policies, and
procedures to ensure alignment with Defence and Australian Government
requirements.
6) Ensure system compliance with mandatory cyber security
requirements.
7) Support configuration governance processes including the
Change Control Boards (CCB) and provide assessment input with risks,
mitigations and options for the Executive Authority (EA) to accept.
c. Advisory and Stakeholder Engagement:
1) Provide cyber security advice within the defined assessor
scope of the CA31.
2) Support CA31 in understanding and mitigating cyber
security risks impacting capability delivery and operations within the LC4
domain.
3) Build and maintain effective working relationships with:
a) Applicable sustainment products
b) OEM
c) Operational and security stakeholders
Services are to be provided commensurate with relevant
Australian and International Standards, regulations, and Defence requirements.
Service providers are to employ industry best practice when undertaking the
Services