Risk Management Analyst

cubic

Sydney

On-site

AUD 140,000 - 200,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Cubic Transportation Systems (CTS) is expanding its information security team in Australia. You will provide security compliance support for production environments, evaluate control posture, and align with policies and controls.

The role partners with auditors to drive PCI-DSS, ISO 27001, and other audits, often with substantial decision-making authority. Typically operating under limited supervision, you will identify risks, develop mitigation plans, and coordinate remediation with

Qualifications

  • Experience implementing PCI-DSS, ISO 27001, SOC 1 & SOC 2 in enterprise environments.
  • Ability to coordinate audits with internal and external auditors.

Responsibilities

  • Perform as the security SME on risk assessment methodology, policy, and processes.
  • Coordinate security audit operations, including scheduling and stakeholder coordination.
  • Liaise with internal/external auditors and IT teams to complete periodic audits and tracking follow-ups.
  • Lead design and control reviews to sustain continuous compliance with security standards.
  • Manage security review processes for solutions to meet PCI-DSS, ISO 27001, SOC 1 & SOC 2 and regional requirements.
  • Identify and report information security risks across applications, data centers, cloud, and vendors.
  • Develop remediation plans and escalate issues to owners for timely resolution.
  • Document controls monitoring in systems like OneTrust and ensure proper governance.
  • Engage with customers and Cubic Security Teams to build positive outcomes.

Job description

Business Unit:

Cubic Corporation

Company Details:

When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people's lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners.

We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). Explore more on Cubic.com.

Job Details:

Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.

Job Summary:

As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating environment to ensure compliance with organization security policies and controls. Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develop mitigation plans. Partners with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts. This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.

RESPONSIBILITIES
Essential Job Duties and Responsibilities
  • Perform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.
  • Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.
  • Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits. Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilities
  • Lead the design and control reviews and assessments to support continuous compliance with security policies and standards
  • Manage security review processes for all solutions to ensure they their design and implementation meets compliance requirements - including: PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements like the Australian Essential 8 and New Zealand NZ-ISM. Document and actively communicate any areas where the solutions and processes are not fully compliant.
  • Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.
  • Identify stakeholders in remediation of compliance gaps and actively elevate issues to them in a constructive manner that helps them understand the actions required. Work to gain acceptance of responsibility and track progress towards remediation. Actively manage escalation as needed if solutions are not resolved in a timely manner.
  • Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.
  • Capture compliance gaps and remediation plans in the OneTrust GRC system. Plans, reviews, and performs (as needed) controls monitoring around complex customer facing systems using the One Trust.
  • Liaise\engage with Cubic customers and Security Teams to build positive relationships and outcomes
  • Supports efforts to educate Security Management and Security Team Members in compliant IT processes and controls. Prepare and maintain process and control documentation
  • Aid in the development of solutions to problems identified during audits and translates these solutions into practical recommendations. Partner with Operations and Engineering Teams to ensure timely and acceptable remediation of issues.
  • Follow up on recommendations and appraises corrective actions taken to improve deficient conditions. To the greatest extent possible, ensure all Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.
  • Review vendor contracts and SOC reports to evaluate the impact on the company's controls. Coordinates with third party vendors where appropriate.
General Duties and Responsibilities:
  • Reliably demonstrate accountability for work assignments and proactive communications about issues and status. A strong history of proactively identifying effective solutions for challenges.
  • Able to reliably demonstrate ethical behavior and accurate communications even when complex factors are involved.
  • Able to operate in a professional manner, even in tense or continuous settings
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk Management Analyst
Risk Management Analyst

Cubic Corporation • Sydney

On-site
AUD 120,000 - 180,000
Security Compliance Risk Analyst
Security Compliance Risk Analyst

Cubic Corporation • Sydney

On-site
AUD 120,000 - 180,000
Security Risk & Compliance Analyst
Security Risk & Compliance Analyst

cubic • Sydney

On-site
AUD 140,000 - 200,000
Senior Tax Manager APAC
Senior Tax Manager APAC

Cubic Corporation • Sydney

On-site
AUD 180,000 - 240,000
Integrated Communications Manager
Integrated Communications Manager

Cubic Corporation • Townsville City

On-site
AUD 120,000 - 160,000
Lead Engineer - Expression of Interest
Lead Engineer - Expression of Interest

Cubic Defence • Canberra

On-site
AUD 180,000 - 240,000
Senior Engineering Manager
Senior Engineering Manager

Cubic Corporation • Townsville City

On-site
AUD 150,000 - 210,000
Level 3 Engineer
Level 3 Engineer

Cubic Corporation • Canberra

On-site
AUD 110,000 - 160,000
Lead Engineer
Lead Engineer

Cubic Corporation • Canberra

On-site
AUD 140,000 - 200,000
Senior Security Consultant
Senior Security Consultant

CSO Group • Sydney

On-site
AUD 120,000 - 180,000