The department is seeking to engage an experienced Cyber Security Governance, Risk, and Compliance (GRC) Officer to strengthen its cybersecurity posture and risk management capability. The Cyber Security GRC Officer will be responsible for ensuring that the Departmental cybersecurity framework aligns with relevant industry standards, regulatory requirements, and internal governance objectives. This role will oversee the implementation and monitoring of cybersecurity controls, support compliance initiatives, and ensure effective risk management across systems, data, and operations. In addition to core GRC responsibilities, the Officer will also be required to conduct or participate in travel-related cyber risk assessments, deliver tailored cybersecurity awareness briefings, and provide practical guidance to staff and executives traveling domestically or internationally. The Successful candidate needs to be able to:
|
Key duties and responsibilities
The applicant will have the below duties and responsibilities:
|
Technical skills
Certifications such as ASD citified IRAP assessor CISSP, CISM, ISO 27001 Auditor are desirable.
Essential criteria
1.Demonstrated experience in authoring ICT system authorisation documentation including but not limited to: Security Risk Management Plans (SRMPs), System Security Plans (SSPs), Authority to Operate Minute and Standard Operating Procedures (SOPs)
2.Exposure to travel security or cyber risk advisory for personnel working in high-risk or international environments and In-depth knowledge of Australian Government cyber security standards, such as the Protective Security Policy Framework (PSPF) and Information Security Manual (ISM) and ability to tailor briefings to the audience, including senior officials and operational staff.
3.Supporting and contributing to IRAP preparation activities, Gap analysis and ensuring accurate documentation in the management and implementation of IT security strategies. Completing technical reviews and endorsements of technical solution designs and identifying opportunities to improve the security posture of the department's network and information.