← all opportunities

LH-07939

buyict×3

Principal Cyber Analysts

3 Principal Cyber Analysts

Department of Health, Disability and AgeingInvited sellersHybridQLD, WA, ACT, VIC, NSW, NT, SA, TAScloses in 9 days

3 agency ads are matched to this contract. Sign up free to see which agency is advertising it, why it matched, and the ad itself.

Sign up free

Your CVs matching this role

0

Sign in to see which of your uploaded CVs match this role.

Candidate Search

Find candidates for this role externally, then cache them here.

Sign in to search candidates for this role.

Job description

The Cyber Security Analyst will deliver cyber governance, risk, assurance and compliance services across a portfolio of departmental ICT systems, cloud environments and strategic digital initiatives. The role is responsible for undertaking cyber security assessments, providing risk-based advice, supporting system authorisation and accreditation activities, overseeing security assurance outcomes and ensuring alignment with Australian Government cyber security requirements. The Cyber Security Analyst will work closely with project teams, system owners, business owners, service providers and senior executives to identify, assess and manage cyber security risks throughout the system lifecycle. The role requires the ability to analyse complex technical and business issues, translate cyber security requirements into practical outcomes and support informed risk-based decision making. The successful candidate will contribute to the Department's governance, risk and assurance capability through the delivery of security reviews, risk assessments, compliance activities, assurance reporting, policy uplift initiatives, cyber security uplift programs and continuous improvement activities. The position requires demonstrated experience in the following key capability areas: Security assurance and authorisation activities, including development, review and maintenance of Authority to Operate (ATO) and Authority to Process (ATP) artefacts, security assessments, risk treatment activities and assurance evidence required to support risk-based authorisation decisions. Cloud security governance across Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP), including security architecture reviews, cloud risk assessments, governance oversight, security advisory services and assessment of cloud-hosted solutions against departmental security requirements. Artificial Intelligence (AI) governance, risk and assurance activities, including assessment of cyber security, privacy, compliance and operational risks associated with AI-enabled technologies and supporting the secure adoption and governance of emerging technologies. Key duties and responsibilities Required Skills and Experience The successful candidate should demonstrate experience and capability in the following areas: Essential – Experience delivering Cyber Governance, Risk and Assurance (GRA) activities within large and complex ICT environments. Demonstrated experience conducting cyber security risk assessments and providing risk-based advice to technical and business stakeholders. Experience supporting Authorisation to Operate (ATO) and Authority to Proceed (ATP) activities, including development and review of accreditation artefacts. Experience applying and interpreting the Australian Government Information Security Manual (ISM), Protective Security Policy Framework (PSPF) and Essential Eight. Experience undertaking security assurance reviews, compliance assessments and control validation activities. Experience assessing cloud-hosted environments including AWS, Azure and/or GCP. Strong written communication skills, including development of executive briefings, security reports, risk assessments and governance documentation. Strong stakeholder engagement skills, with the ability to communicate effectively with both technical and non-technical audiences. Demonstrated ability to manage multiple competing priorities across a diverse portfolio of work. Desirable Experience supporting or preparing for Information Security Registered Assessors Program (IRAP) assessments. Experience coordinating penetration testing and vulnerability remediation activities. Experience with Integrated Risk Management (IRM) or similar Governance, Risk and Compliance (GRC) platforms. Experience supporting AI governance, risk management and assurance activities. Experience developing or maintaining cyber security policies, standards, procedures and governance frameworks. Experience within Australian Government environments. Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters. Essential criteria 1. The nominated evaluation members will evaluate the RFQ submissions using the following criteria: 1) Extent to which the response meets the Department requirements 2) The supplier's demonstrated capability & capacity to provide the requirements 3) Whole of life costs incurred by the Department Opportunity summary Sellers can submit Up to 2 candidates Number of sellers invited Between 5 and 10 Number of candidates submitted Fewer than 10 Send us feedback About Accessibility Privacy Terms of use Disclaimer and copyright An initiative of the Digital Transformation Agency The Australian Government acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present. © Commonwealth of Australia

3 matches locked

Sign up to see which agency is advertising for this contract, the match evidence, and the ad itself.

Other open contracts for Department of Health, Disability and Ageing

Related reading