Location: ACT QLD VIC WA
LH01720
Security clearance: Australian Citizen must be able to obtain Positive Vetting
I
Job Description:
ICT Security Specialists will work independently with the opportunity for reasonable autonomy and accountability for the achievement of outcomes of their work. They will exercise both initiative and judgement in the interpretation of policy and in the application of practices and procedures. They will provide detailed information security technical professional and policy advice in relation to complex work and contribute to strategic planning program and project management and policy development.
Job Duties and Responsibilities
- Accountable to conduct security risk assessments and provide advice and guidance on the application and operation of procedural security controls.
- Responsible for ensuring that all identified breaches in information security are promptly managed according to the Australian Signals Directorate policies and procedures.
- Understand the security features and capabilities of current Australian Signals Directorate and industry accepted hardware and software products and provide advice to stakeholders.
- Use experience to explain systems security and the strengths and weaknesses that are relevant across the Australian Signals Directorate.
- Tailor communication style and language to provide guidance on security strategies to manage identified risks.
- Facilitate appropriate direction for the team by clearly communicating goals and objectives.
- Interpret security policy and contribute to the development of standards and guidelines that comply with the Australian Signals Directorate policy and procedures.
- Analyse and resolve identified security incidents in accordance with established procedures and recommend any required actions.
- Lead the application and compliance of security operations procedures and review information systems for actual or potential breaches in security.
- Build and sustain effective working relationships with team members and actively participate in teamwork and group activities.
* Certification as an Infosec Registered Assessors Program (IRAP) Assessor * Experience ensuring technical systems adhere to Essential Eight ISM and PSPF frameworks * Proven ability to communicate complex technical systems to nontechnical audiences * Excellent organisational & communication skills * Proven record building managing & enhancing relationships with stakeholders * Experience developing managing and implementing SOPs & procedures in support of security accreditation frameworks
Requirements
Essential criteria
1. SCAD 3 Security operations: Level 3 (SFIA) Investigates minor security breaches in accordance with established procedures. Assists users in defining their access rights and privileges. Performs nonstandard operational security tasks. Resolves security events and operational security issues.
2. SCAD 4 Security operations: Level 4 (SFIA) Maintains operational security processes and checks that all requests for support are dealt with according to agreed procedures. Provides advice on defining access rights and the application and operation of elementary physical procedural and technical security controls. Investigates security breaches in accordance with established procedures and recommends required actions. Provides support and checks that corrective actions are implemented.
3. SCTY 4 Information security: Level 4 (SFIA) Provides guidance on the application and operation of elementary physical procedural and technical security controls. Explains the purpose of security controls and performs security risk and business impact analysis for medium complexity information systems. Identifies risks that arise from potential technical solution architectures. Designs alternate solutions or countermeasures and ensures they mitigate identified risks. Investigates suspected attacks and supports security incident management.
4. INAS 4 Information assurance: Level 4 (SFIA) Performs technical assessments and/or accreditation of complex or higherrisk information systems. Identifies risk mitigation measures required in addition to the standard organisation or domain measures. Establishes the requirement for accreditation evidence from delivery partners and communicates accreditation requirements to stakeholders. Contributes to planning and organisation of information assurance and accreditation activities. Contributes to development of and implementation of information assurance processes.
Essential criteria: 1. ITOP 5 - Provides technical leadership to optimise the performance of IT infrastructure. Investigates and manages the adoption of tools, techniques and processes (including automation) for the management of systems and services. Oversees the planning, installation, maintenance and acceptance of new and updated infrastructure components and infrastructure-based services. Aligns to service expectations, security requirements and other quality standards. Ensures that operational procedures and documentation are fit for purpose and kept up to date. Ensures that operational issues are identified, recorded, monitored and resolved. Provides appropriate status and other reports to specialists, users and managers. 2. DESN 5 - Designs large or complex systems and undertakes impact analysis on major design options and trade-offs. Ensures that the system design balances functional and non-functional requirements. Reviews systems designs and ensures that appropriate methods, tools and techniques are applied effectively. Makes recommendations and assesses and manages associated risks. Adopts and adapts system design methods, tools and techniques. Contributes to development of system design policies, standards and selection of architecture components. 3. HSIN 5 - Takes responsibility for installation and/or decommissioning projects. Provides effective team leadership, including information flow to and from the customer during project work. Develops and implements quality plans and method statements. Monitors the effectiveness of installations and ensures that appropriate recommendations for change are made. 4. SINT 5 - Plans and drives activities to develop organisational systems integration and build capabilities including automation and continuous integration. Identifies, evaluates and manages the adoption of tools, techniques and processes to create a robust integration framework. Provides authoritative advice and guidance on any aspect of systems integration. Leads integration work in line with the agreed system and service design. Assesses risks and takes preventative action. Measures and monitors applications of standards. Contributes to the development of organisational policies, standards, and guidelines for systems integration. Desirable criteria 1. Our ideal candidates will bring the following attributes: Strong written and verbal communication skills; Desire to be accountable for their actions; Strong stakeholder management skills; Demonstrate leadership behaviours; Willing to challenge the traditional ways of doing business; Thrive in dynamic environments and comfortable with ambiguity; Outcome-focused mindset; and Adaptability, resilience, flexibility and teamwork, including regionally dispersed teams, if applicable. Please provide a brief explanation of your experience covering these attributes. (Guide 300 to 400 words.)