drjobs Multiple Senior Security Engineer

Multiple Senior Security Engineer

Employer Active

1 Vacancy
The job posting is outdated and position may be filled
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Canberra - Australia

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Location: ACT QLD VIC WA
LH01722
Security Clearance: Australian Citizen must be NV1 or higher

ASD is seeking candidates who hold active NV1 or TSPV security clearances. Please clearly indicate the level held within your responses.
ICT Security Engineers provide operational and system security management and administrative services.

Job Duties and Responsibilities may include:
Manage and develop ICT system security activities
  • Achieve an Authority to Operate (ATO)
  • Develop a System Security Plan (SSP)
  • Assess compliance with ICT security requirements
  • Lead the application and compliance of security operations procedures and review information systems for actual or potential security controls to achieve ATO
  • Negotiate with ICT engineers and ICT Security in the development and approval of Concept of Operations SSPs and Executive Briefs


Technical Skills:

  • At least 3 years experience as a security engineer or similar role.
  • Experience in identifying and/or applying security controls.
  • Experience with security controls in cloud computing systems.
  • Good knowledge of information security principles practices and technologies.
  • Demonstrable experience in ICT security activities with a focus on Linux and Windows operating systems
  • High level of knowledge on ICT security threat and risk assessments and the ability to recommend mitigation/remediation strategies
  • Experience in production of complex technical documentation

Technical skills

Desirable: Bachelor s degree in Information Technology or related field.


Requirements

Technical Skills:

  • At least 3 years experience as a security engineer or similar role.
  • Experience in identifying and/or applying security controls.
  • Experience with security controls in cloud computing systems.
  • Good knowledge of information security principles practices and technologies.
  • Demonstrable experience in ICT security activities with a focus on Linux and Windows operating systems
  • High level of knowledge on ICT security threat and risk assessments and the ability to recommend mitigation/remediation strategies
  • Experience in production of complex technical documentation
Essential criteria

1. SCAD 3 Security operations: Level 3 (SFIA) Investigates minor security breaches in accordance with established procedures. Assists users in defining their access rights and privileges. Performs nonstandard operational security tasks. Resolves security events and operational security issues.

2. SCAD 4 Security operations: Level 4 (SFIA) Maintains operational security processes and checks that all requests for support are dealt with according to agreed procedures. Provides advice on defining access rights and the application and operation of elementary physical procedural and technical security controls. Investigates security breaches in accordance with established procedures and recommends required actions. Provides support and checks that corrective actions are implemented.

3. SCTY 4 Information security: Level 4 (SFIA) Provides guidance on the application and operation of elementary physical procedural and technical security controls. Explains the purpose of security controls and performs security risk and business impact analysis for medium complexity information systems. Identifies risks that arise from potential technical solution architectures. Designs alternate solutions or countermeasures and ensures they mitigate identified risks. Investigates suspected attacks and supports security incident management.

4. INAS 4 Information assurance: Level 4 (SFIA) Performs technical assessments and/or accreditation of complex or higherrisk information systems. Identifies risk mitigation measures required in addition to the standard organisation or domain measures. Establishes the requirement for accreditation evidence from delivery partners and communicates accreditation requirements to stakeholders. Contributes to planning and organisation of information assurance and accreditation activities. Contributes to development of and implementation of information assurance processes.


Desirable criteria

1. PBMG 3 Problem management: Level 3 (SFIA) Investigates problems in systems processes and services. Assists with the implementation of agreed remedies and preventative measures.

Essential criteria: 1. ITOP 5 - Provides technical leadership to optimise the performance of IT infrastructure. Investigates and manages the adoption of tools, techniques and processes (including automation) for the management of systems and services. Oversees the planning, installation, maintenance and acceptance of new and updated infrastructure components and infrastructure-based services. Aligns to service expectations, security requirements and other quality standards. Ensures that operational procedures and documentation are fit for purpose and kept up to date. Ensures that operational issues are identified, recorded, monitored and resolved. Provides appropriate status and other reports to specialists, users and managers. 2. DESN 5 - Designs large or complex systems and undertakes impact analysis on major design options and trade-offs. Ensures that the system design balances functional and non-functional requirements. Reviews systems designs and ensures that appropriate methods, tools and techniques are applied effectively. Makes recommendations and assesses and manages associated risks. Adopts and adapts system design methods, tools and techniques. Contributes to development of system design policies, standards and selection of architecture components. 3. HSIN 5 - Takes responsibility for installation and/or decommissioning projects. Provides effective team leadership, including information flow to and from the customer during project work. Develops and implements quality plans and method statements. Monitors the effectiveness of installations and ensures that appropriate recommendations for change are made. 4. SINT 5 - Plans and drives activities to develop organisational systems integration and build capabilities including automation and continuous integration. Identifies, evaluates and manages the adoption of tools, techniques and processes to create a robust integration framework. Provides authoritative advice and guidance on any aspect of systems integration. Leads integration work in line with the agreed system and service design. Assesses risks and takes preventative action. Measures and monitors applications of standards. Contributes to the development of organisational policies, standards, and guidelines for systems integration. Desirable criteria 1. Our ideal candidates will bring the following attributes: Strong written and verbal communication skills; Desire to be accountable for their actions; Strong stakeholder management skills; Demonstrate leadership behaviours; Willing to challenge the traditional ways of doing business; Thrive in dynamic environments and comfortable with ambiguity; Outcome-focused mindset; and Adaptability, resilience, flexibility and teamwork, including regionally dispersed teams, if applicable. Please provide a brief explanation of your experience covering these attributes. (Guide 300 to 400 words.)

Employment Type

Full Time

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.