Job description
- Minimum 6–10 years of experience across cyber risk, security architecture preferably within energy / critical infrastructure.
- Sound knowledge and experience in information governance, including records and information management, data sovereignty frameworks, and working with business classification schemes.
- Developing and refining frameworks and assurance documents and assessing their effectiveness.
- Hands-on familiarity or strong understanding in AESCSF and Operational Technology (OT) cyber practices and standards and is comfortable working with various security frameworks such as Australian ISM and PSPF.
- Understanding of regulatory and legal obligations for critical infrastructure, strong cyber risk management background will be highly regarded.
- Preparing, updating monitoring of key security documents, such as SSP, SSP Annex, ISM Statement of Applicability (SoA), and SRMP documents.
- Collaborate with senior stakeholders and leadership.
- Strong team management skills and the ability to influence senior stakeholders.
- Structured thinker with strong written and verbal communication skills.
- Highly adaptable and able to manage multiple priorities in a fast-paced environment.
Desirable skills
- A relevant tertiary qualification and experience in cyber security, IT governance, and/or risk management.
- Industry certifications such as CISSP, CISM, CRISC, or GIAC, and working knowledge of frameworks including ISO/IEC 27001, NIST CSF, and NIST SP 800-53, Australian ISM, PSPF and AESCSF.
- Strong stakeholder engagement, communication, and project coordination skills.
- Good understanding of regulatory requirements including the Privacy Act 1988, SoCI Act 2018, and Cyber Security Act 2024.
- You’re a proactive and experienced cyber security professional with a strong understanding of governance, risk, and compliance. You thrive in collaborative environments and are passionate about using technology and innovation to drive secure, efficient outcomes.
Australia
Singapore
India