Technology Specialist Cyber GRC
Core
Support secure and compliant outcomes for Defence and government programs through ICT Assessment and Authorisation (A&A), risk management, and security assurance.
Role type
Cyber Security GRC Specialist
Builds
Security documentation, risk assessments, and governance practices for Defence systems
Domain
Defence, Government, Cyber Security
Required skills
ICT Assessment and Authorisation (A&A), risk management, security assurance, knowledge of ISM/PSPF/DSPF/NIST frameworks, Defence CyberWorthiness System (DCwS) operations, Authority to Operate (ATO) workflows, security artefact development (SAP, BIL, SSP, SRMP, IRP, CMP, SCCG, POA&M), OT/ICT network integration
Preferred skills
CISSP, CISM, ISO 27001 Lead Auditor, classified Defence project experience, NV1 clearance
Technologies
ISM, PSPF, DSPF, NIST, Essential Eight (E8), DCwS, CSAAF
Responsibilities
Manage cyber security governance and compliance frameworks; Lead CSAAF processes to achieve ATO; Engage with Defence stakeholders to support ATO workflows; Develop and maintain core security artefacts; Drive continuous improvement in governance and policy; Conduct risk identification, mitigation, and reporting
Seniority
Mid-level, hands-on IC
