Assessment and Authorisation
Core
Perform security risk management and assurance activities to guide systems through the A&A lifecycle and obtain/maintain Authority to Operate.
Role type
Security Assessment and Authorisation (A&A) Consultant
Builds
Security accreditation documentation, risk assessments, and audit evidence for government systems.
Domain
Australian Government Cybersecurity / GRC
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
security risk assessment, stakeholder risk workshops, security control assessment, authorisation process execution, accreditation documentation, security policy development, incident-response documentation, GRC tooling management, compliance gap tracking, continuous monitoring support
Preferred skills
knowledge of Australian Government ISM, Essential Eight, security accreditation processes, analytical skills, organisational skills
Technologies
ISM, Essential Eight, GRC tooling
Responsibilities
Conduct security risk assessments and facilitate stakeholder risk workshops; Monitor risks, treatment plans and residual risk; Assess the implementation and effectiveness of security controls; Execute authorisation processes in accordance with the ISM and client requirements; Prepare and maintain risk assessments, accreditation documentation and audit evidence; Develop security policies, procedures and incident-response documentation; Provide guidance on the ISM, Essential Eight and client-specific security controls; Liaise with Authorising Officers, system owners and project teams; Support the establishment and ongoing management of GRC tooling; Track authorisation status, deliverables and compliance gaps; Support continuous monitoring, audits and inspections; Assist managers and program leads with day-to-day activities
