Cyber Security Assessor

Rashi Joshi

City of Melbourne

On-site

AUD 120,000 - 150,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Victorian State Government Agency is seeking a Cyber Security Assessor to evaluate cyber risks, develop documentation, and advise stakeholders across diverse projects and technology environments.

You will conduct risk assessments using frameworks such as NIST, ISM, PSPF, and SOC2, develop SRMPs and SSPs, and provide security-by-design guidance.

Collaborate with project teams, owners, and governance bodies to monitor risk treatment and ensure compliance; CISSP/CISM preferred.

Qualifications

  • Experience conducting cyber security risk assessments and security assurance reviews.
  • Familiarity with VPDSS, PSPF, ISM, NIST, Essentials Eight, and SOC2.

Responsibilities

  • Conduct security risk assessments across projects and environments.
  • Develop Security Risk Assessment Reports and System Security Plans (SSPs).
  • Perform third-party risk assessments (TPRM) and report findings.
  • Review and update security controls, policies, and procedures.
  • Provide security-by-design guidance during project design.
  • Collaborate with stakeholders to track risk treatment plans.
  • Audit vulnerability management and privileged access controls.
  • Report on security governance, policies, and standards.

Skills

Cyber security risk assessments
Security frameworks
TPRM
Security reporting
Stakeholder communication
Security documentation

Education

Bachelor's degree in IT/Cybersecurity
CISSP/CISM/CRISC certifications

Tools

Azure
Microsoft 365
Entra ID

Job description

Your new company

Join a leading Victorian State Government Agency delivering a critical Cyber Resilience Program aimed at strengthening cyber security capabilities across a large and complex environment. This high-profile initiative supports strategic cyber resilience objectives and addresses the increasing cyber threats faced by educational institutions. You'll work alongside experienced security professionals to help drive security uplift across enterprise systems and services.

Your new role

As a Cyber Security Assessor, you will play a key role in assessing cyber security risks, developing security documentation, and providing expert security advice to stakeholders across a range of projects and technology environments.

Key responsibilities include:
  • Conduct security risk assessments using frameworks such as VPDSS, PSPF, ISM, NIST, Essentials Eight and SOC2.
  • Develop Security Risk Assessment Reports, Security Risk Management Plans (SRMPs), and System Security Plans (SSPs).
  • Perform third-party and vendor security risk assessments (TPRM) and produce risk assessment reports.
  • Review and update security controls, policies, standards, and procedures, ensuring alignment with industry and government frameworks.
  • Provide security-by-design guidance during project and solution design activities.
  • Work closely with project teams, system owners, and business stakeholders to develop and track risk treatment plans.
  • Audit and report on vulnerability management, privileged access controls, and remediation activities.
  • Provide expert advice on cyber security policies, standards, and best practices.
  • Support governance activities through risk reporting, mitigation tracking, and compliance monitoring.
What you'll need to succeed
  • Proven experience conducting cyber security risk assessments and security assurance reviews.
  • Strong knowledge of government and industry security frameworks including VPDSS, PSPF, ISM, NIST, Essentials Eight, and/or SOC2.
  • Experience developing security assessment reports, security management plans, and security documentation.
  • Demonstrated experience in third-party risk management (TPRM) and security reporting.
  • Strong understanding of security controls, risk management methodologies, and remediation planning.
  • Experience reviewing, developing, and maintaining cyber security policies, standards, and procedures.
  • Knowledge of vulnerability management and security governance practices.
  • Understanding of Microsoft technologies including Azure, Microsoft 365, and Entra ID from a security perspective.
  • Excellent stakeholder engagement, communication, and report-writing skills.
  • ICT or cyber security background with experience working across complex technology environments.
  • Certifications like CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor highly regarded.
What you'll get in return
  • Work within a highly visible and strategically important government initiative.
  • Collaborative and supportive team environment.
  • Flexible working arrangements and a strong focus on professional development.

Hays appreciates the importance of workforce diversity and inclusion. We are an equal-opportunities employer and have policies, procedures and relationships in place to promote our understanding of all forms of diversity.

LHS 297508 #3008205 - Prachi KalyanArora

Get your free, confidential resume review.

or drag and drop your file here.