Defence Cyber Security Certification Consultant

Business Review Group

Canberra

On-site

AUD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Business Review Group is seeking a Defence Cyber Security Certification Consultant to work embedded in the Land C4 Systems Branch supporting the CA31 capability. The role involves assessment, authorisation, risk management and assurance across CA31 capability systems in a Defence environment.

The candidate will apply ICT architecture knowledge, conduct CSAA-aligned audits, prepare SARs and ATO briefs, and provide advisory support to CA31 stakeholders while complying with ASD ISM, PSPF and

Qualifications

  • Qualifications, certifications and/or professional experience eligible for DCIA B-CSAA endorsement.
  • Strong understanding of ICT architectures, networks and platforms.
  • Experience leading cyber security audits and delivering assessment reports.

Responsibilities

  • Provide System Assessment and Authorization (IS, PSPF, CSAA).
  • Conduct security assessments using OER as default approach.
  • Develop SARs, ATO briefs, risk statements and remediation actions.
  • Support Change Control Boards and governance activities.
  • Provide cyber security advisory to CA31 stakeholders.

Skills

Cybersecurity assessment
Security governance
Risk management
Stakeholder engagement

Education

CISSP
CISM
ISO 27001 Lead Auditor
IRAP accreditation

Tools

ICT architectures
CSAA framework

Job description

Defence Cyber Security Certification Consultant
  • Program / Project: CA31 – Land Communications & Specialist Systems SPO (LCSS SPO)
  • Business Area: Land C4 Systems Branch (LC4S Branch), Joint Systems Division
  • Discipline: 2.6 Systems and Software Engineering – System Security
  • Skill Level: Level 3
  • FTE: 1.0
  • Security Clearance: Minimum NV1
  • ITAR Requirement: Yes
  • Start Date: ASAP
  • End Date: 31 March 2027
  • Extension: Opportunity for extension
  • Location: No location restrictions within Australia
  • Travel: Occasional travel may be required
  • On-Site Requirement: Candidates based in Melbourne or Canberra must be able to work on-site a minimum of 3 days per week
Role Overview

Land Communications & Specialist Systems SPO (LCSS SPO) is seeking a suitably qualified and experienced Cybersecurity Certification Consultant to operate as an embedded member of the Land C4 Systems Branch supporting the CA31 capability.

CA31 sustains and enhances Land Command, Control, Communications and Computing (C4) systems at the operational and tactical levels, providing communications capabilities essential to the conduct of operations in the Land Domain.

The program sustains core communications capabilities and delivers capability enhancement work packages across:

  • Tactical Communications Network (TCN)
  • Battlefield Telecommunications Network (BTN)
  • Battlefield Management System (BMS)
  • Deployable Information Environment (DIE) – Protected and Secret

The successful candidate will provide specialist cyber security assessment, authorisation, assurance and risk management support across CA31 capability systems. The role requires a Cybersecurity professional who can operate effectively in a complex Defence environment, think critically, solve complex problems and manage competing priorities while maintaining a strong focus on risk mitigation and capability outcomes.

Key Responsibilities
Assessment and Authorisation

The Cybersecurity Certification Consultant will:

  • Provide System Assessment and Authorisation activities as directed by the CA31 Engineering Manager.
  • Conduct assessment and authorisation activities in accordance with:
    • ASD Information Security Manual (ISM).
    • Protective Security Policy Framework (PSPF).
    • Defence Security Policy Framework.
    • Cyber Security Assessment and Authorisation (CSAA) Charter, assessment methodology, templates and guidance.
  • Conduct security assessments using Operational Effectiveness Reviews (OER) as the default assessment approach.
  • Undertake Design Effectiveness Reviews (DER) where justified.
  • Audit the effectiveness of security controls implemented across CA31 capability systems.
  • Develop and deliver security assessment artefacts, including:
    • Security Assessment Reports (SAR).
    • Authority to Operate (ATO) briefs.
    • Risk statements.
    • Recommended remediation actions.
Cyber Security Risk and Threat Assessment

The successful candidate will:

  • Identify, analyse, evaluate and elevate cyber security and business risks.
  • Identify and assess vulnerabilities resulting from:
    • Security exceptions.
    • Software defects.
    • Architecture or design weaknesses.
  • Assess system security architectures and services using structured threat-modelling methodologies.
  • Support protection of the Confidentiality, Integrity and Availability (CIA) of Defence information and systems.
  • Assess risks and develop practical mitigation and remediation recommendations.
  • Support security risk decision-making across the CA31 capability environment.
Governance, Compliance and Assurance

The Cybersecurity Certification Consultant will:

  • Review system security documentation, policies and procedures for alignment with Defence and Australian Government requirements.
  • Ensure systems comply with applicable mandatory cyber security requirements.
  • Provide assurance regarding implementation and ongoing effectiveness of security controls.
  • Support configuration governance activities, including Change Control Boards (CCBs).
  • Provide assessment input covering risks, mitigations and options for consideration and acceptance by the relevant Executive Authority.
  • Support ongoing cyber security governance and assurance across capability systems.
Cyber Security Advisory

The successful candidate will:

  • Provide specialist cyber security advice within the defined CA31 assessor scope.
  • Support CA31 stakeholders in understanding cyber security risks affecting capability delivery and operations within the LC4 domain.
  • Provide clear and defensible advice regarding security risks, treatment options and remediation activities.
  • Apply relevant Australian and international standards, Defence requirements and industry best practice when delivering services.
Stakeholder Engagement

The Cybersecurity Certification Consultant will build and maintain effective working relationships with:

  • CA31 and LCSS SPO stakeholders.
  • Sustainment product teams.
  • Original Equipment Manufacturers (OEMs).
  • Operational stakeholders.
  • Security stakeholders.
  • Defence and industry partners.

The role requires the ability to work under broad direction and influence stakeholders across both Defence and industry.

Mandatory Experience and Qualifications

Candidates must demonstrate:

  • Relevant qualifications, industry certifications and/or professional experience assessed as suitable for eligibility to obtain DCIAB-CSAA endorsement as a Cyber Security Assessor.
  • Relevant certifications may include, but are not limited to:
    • CISSP.
    • CISM.
    • ISO 2701 401 Lead Auditor.
    • IRAP accreditation.
  • Strong understanding of ICT architectures, networks and platforms.
  • Strong understanding of cyber security compliance and governance within a Defence environment.
  • Demonstrated ability to lead cyber security audits, document outcomes and deliver formal assessment reports.
  • Understanding of modern networking technologies, computer systems and operating systems.
  • Ability to work effectively as part of a multidisciplinary team.
Highly Desirable Experience and Skills

The following would be highly regarded:

  • Comprehensive understanding of Defence systems, particularly C4 capabilities.
  • Previous experience within Defence, Army or CASG.
  • Experience assessing and evaluating cyber security risk.
  • Experience supporting Defence capability acquisition or sustainment environments.
  • Ability to apply creative and innovative solutions that provide practical benefits to stakeholders.
Additional Requirements

Candidates should demonstrate:

  • Understanding of the One Defence Capability System, formerly the Capability Lifecycle.
  • Ability to operate effectively under broad direction.
  • Ability to influence stakeholders across Defence and industry.
  • Commitment to ongoing professional development.
  • Willingness to mentor and support colleagues.
  • Effective time management.
  • Strong written and verbal communication skills.
  • Strong interpersonal and stakeholder engagement capability.
Security and Working Arrangements

The successful candidate must hold a current Australian Government security clearance of at least NV1.

The role has no location restrictions within Australia, although occasional travel may be required to Defence facilities and program locations.

Candidates based in Melbourne, Victoria or Canberra, ACT must be able to attend the office for a minimum of three days per week.

The engagement is subject to ITAR requirements.

Candidate Profile

This opportunity would suit an experienced Cyber Security Assessor, Cybersecurity Certification Consultant, Security Assurance Engineer or System Security Engineer with strong Defence cyber security assessment and authorisation experience.

The strongest candidates will combine practical knowledge of Defence C4 systems, ICT architecture and networks with demonstrated expertise in CSAA, OER/DER assessments, security control auditing, risk assessment, SAR development and ATO support.

Experience working within Army, CASG or Defence capability acquisition and sustainment environments, together with eligibility for DCIAB-CSAA Cyber Security Assessor endorsement, would be particularly relevant.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Certification Consultant | NV1 | Canberra, Melbourne, Remote
Cybersecurity Certification Consultant | NV1 | Canberra, Melbourne, Remote

Pinaka Technology Solutions • Canberra

Hybrid
AUD 120,000 - 160,000
Cybersecurity Certification Consultant | NV1 | Canberra, Melbourne, Remote
Cybersecurity Certification Consultant | NV1 | Canberra, Melbourne, Remote

pinaka • Canberra

Hybrid
AUD 120,000 - 160,000
Defence Cyber Security Certification Consultant - Level 3
Defence Cyber Security Certification Consultant - Level 3

Indigitise Pty Ltd • Canberra

On-site
AUD 120,000 - 160,000
Systems Engineer – Tactical Communications | NV1 | Melbourne
Systems Engineer – Tactical Communications | NV1 | Melbourne

Pinaka Technology Solutions • City of Melbourne

On-site
AUD 120,000 - 150,000
Systems Engineer – Tactical Communications | NV1 | Melbourne
Systems Engineer – Tactical Communications | NV1 | Melbourne

pinaka • City of Melbourne

On-site
AUD 120,000 - 180,000
Defence Cyber Security Assessor – Onsite Sydney
Defence Cyber Security Assessor – Onsite Sydney

C4I Solutions Pty • Sydney

On-site
AUD 150,000 - 190,000
Long Service Leave
Health & wellbeing allowance
Higher Education Subsidy
Cyber Security Specialist
Cyber Security Specialist

Talent Corp • Canberra

On-site
AUD 120,000 - 160,000
Cyber Security Assessor
Cyber Security Assessor

Client 1 • Canberra

Hybrid
AUD 120,000 - 160,000
Cyber Security Lead
Cyber Security Lead

Business Review Group • Canberra

On-site
AUD 180,000 - 240,000
Defence Cybersecurity Certification & Assurance Consultant
Defence Cybersecurity Certification & Assurance Consultant

Business Review Group • Canberra

On-site
AUD 140,000 - 190,000