Information Security Specialist
Summary
The Information Security Specialist provides security advice, risk assessments, and assurance across the organization's technology and business initiatives. The role involves evaluating security controls, managing supplier security, and supporting governance activities while leveraging AI for efficiency.
Essential Requirement: Applicants must hold Australian citizenship
Opportunity to be involved
We are looking for an experienced Information Security Specialist to provide information security advice, assessment and assurance across ARPC's business and technology environment. Reporting to the Director of Information Security, you will help decision-makers understand security risks, evaluate control design and evidence, and make informed decisions.
You will work across business, technology, data, risk and supplier stakeholders, providing practical security advice and constructive challenge while maintaining clear records and agreed priorities.
Role responsibilities
Conduct information security assessments for technology, cloud, data, supplier and business change initiatives.
Provide practical security advice to project teams and business owners from planning through implementation and transition.
Assess security risks, control design and supporting evidence, then document clear recommendations and required actions.
Review proposed architectures, solution designs and changes to identify security requirements and control gaps early.
Support Operations and governance activities including policies, standards, risk assessments, control assessments and security exceptions.
Review remediation evidence and advise whether identified security issues are ready for governance closure.
Support third-party security assessments and define security requirements for procurement and supplier reviews.
Analyse vulnerabilities, incidents, control issues and assurance results to support management and committee reporting.
Maintain clear assessment records, action tracking and evidence so security decisions can be reviewed and supported.
Support incident governance, post-incident reviews and security exercises without owning containment, recovery or technical remediation.
Candidate attributes
Qualifications
• Tertiary qualification in information technology, cyber security or related discipline - Desirable
• Relevant industry certification or training in information security, risk, audit or assurance - Desirable
• Commitment to maintain relevant professional development and security knowledge - Mandatory
Experience
• 5-8 years of relevant information security experience, including consulting, advisory, governance, risk or assurance work - Mandatory
• Experience leading security assessments and translating technical evidence into clear risks, recommendations and business decisions - Mandatory
• Experience assessing cloud, identity, endpoint, network, data protection, vulnerability, monitoring, software and service controls - Mandatory
• Experience applying the Australian Government Information Security Manual (ISM), Essential Eight or comparable security frameworks - Highly Desirable
• Experience conducting security risk assessments, control reviews and evidence-based assurance activities - Mandatory
• Experience reviewing supplier security, procurement requirements or third-party assurance evidence - Desirable
Technical capability
Strong knowledge of information security governance, risk management, security controls and assurance practices.
Ability to assess technical security evidence and translate findings into clear risks, recommendations and practical business actions.
Ability to develop and maintain security policies, standards and supporting governance documentation.
Strong understanding of AI, cloud, identity, endpoint, network, data protection, vulnerability management, monitoring, software and service security controls.
Strong written and verbal communication skills, including preparation of concise assessment reports, governance papers and management reporting.
Strong stakeholder management skills across business, technology, data, risk and external service providers.
Ability to analyse security data and present trends through reporting or visualisation tools - Desirable.
Scripting, automation or data analysis capability to support repeatable security assessment and reporting activities - Desirable.
Adopt and leverage AI capabilities as part of ongoing work efficiency and automations.
Note
The role is based in Sydney.
You must be an Australian citizen and be able to obtain an Australian Government Baseline Security Clearance.
Please apply with your resume and covering letter.
Your application will be reviewed by a member of the HR team and suitable candidates will be invited to an interview for the role.
The closing date for applications for this role is 18 September 2026.