Cyber Security Product Assessor
Core
Conduct detailed security evaluations of hardware, software, and security products to determine suitability for Defence environments.
Role type
Senior IC security product assessor
Builds
Evidence-based security assessment reports and risk decisions for Defence stakeholders
Domain
Defence / Cyber Security Assurance
Required skills
Security product evaluation and assurance, Security architecture review and analysis, Security control testing and validation, Technical risk assessment and reporting, Information security governance, risk and compliance, Vulnerability assessment and security research
Preferred skills
Application, platform or infrastructure security, Network, endpoint, cloud or enterprise security solutions, Familiarity with Australian Government Information Security Manual (ISM)
Technologies
None explicitly listed
Responsibilities
Conduct independent security evaluations of hardware, software and security products proposed for use within Defence environments, Assess the effectiveness of security controls, security-enforcing mechanisms and protective capabilities within products and technologies, Review architecture documentation, design specifications, implementation guidance and vendor-supplied security material, Analyse product risks, security weaknesses and potential impacts to Defence systems and operations, Produce comprehensive technical and risk assessment reports for senior risk owners and decision-makers, Provide expert advice on product suitability, security limitations, mitigations and recommended risk treatments
Seniority
Senior, hands-on IC