Cyber Security Assessor (multiple)
ocation: Canberra, ACT
Employment Type: Contract – Full Time
Start Date: ASAP
Contract Duration: Until 30 June 2027, with the possibility of extension (long-term engagement)
Security Clearance: NV1 preferred (Baseline clearance will be considered)
About the Role
We're seeking multiple experienced Cyber Security GRC Assessors to join a high-profile Federal Government cyber security program supporting security assurance and Authority to Operate (ATO) activities.
You'll play a key role in assessing ICT systems, platforms and services across a diverse technology landscape, including on-premises, hybrid cloud, cloud, SaaS and AI-enabled environments. Working as part of a collaborative cyber assurance team, you'll help ensure systems meet Australian Government security requirements while providing practical risk advice to support secure service delivery.
This is a long-term Canberra-based engagement with a strong preference for onsite work (hybrid).
Key Responsibilities
In this role, you will:
Conduct cyber security risk assessments for ICT systems, platforms and services
Support Authority to Operate (ATO) and security assurance activities
Assess environments spanning on-premises, hybrid cloud, cloud, SaaS and AI-enabled technologies
Review security documentation, technical architecture and control evidence
Identify security risks, compliance gaps and recommended remediation actions
Produce high-quality security risk assessment reports for senior stakeholders and authorising authorities
Provide practical cyber security advice to technical and business stakeholders
Collaborate with infrastructure, project and security teams to improve security outcomes
About You
You'll bring:
5+ years' experience in Cyber Security GRC, ICT security assurance or cyber risk assessment
Demonstrated experience applying the Australian Government Information Security Manual (ISM), Protective Security Policy Framework (PSPF) and Essential Eight
Experience supporting Authority to Operate (ATO) or equivalent security authorisation activities
Experience assessing ICT systems across on-premises, hybrid cloud and cloud environments, including Azure and/or AWS
Ability to assess security documentation, architecture, risk artefacts and technical controls
Strong report writing skills with the ability to communicate complex risks to both technical and non-technical audiences
Excellent stakeholder engagement, organisation and time management skills
Ability to work independently while managing multiple priorities
Highly Desirable
CISSP, CISM, CRISC, CISA or equivalent industry certifications
Microsoft Azure Security or AWS Security certifications
IRAP Assessor experience or experience supporting IRAP assessments
Experience working within Australian Government cyber security or ICT assurance environments
Exposure to security assurance for AI-enabled systems
Why Apply?
Long-term contract through to June 2027, with extension potential
Multiple opportunities available within an established cyber security program
Work across modern technologies including cloud, SaaS and AI-enabled environments
Join a collaborative and highly experienced cyber assurance team
Opportunity to contribute to meaningful government cyber security initiatives
Security Requirement
NV1 security clearance is preferred.
Candidates with an active Baseline clearance are also encouraged to apply.
Apply Now
If you're an experienced Cyber Security GRC professional looking for a long-term opportunity supporting complex government cyber security initiatives, we'd love to hear from you.
Apply now with your latest CV or contact [email protected] for a confidential discussion.