About the Role
As the Cyber Assessment Lead, you will ensure systems align with Defence security frameworks, contribute to accreditation activities, security compliance reviews, technical risk assessments, and security-by-design initiatives. This role strengthens organisational cyber resilience and supports operational capability. Travel to conduct on-site assessments may be required, with familiarity with Defence equipment preferred. This role is located onsite in Sydney, CBD.
Responsibilities
- Conduct cyber security assessment and authorisation (A&A) activities for Defence ICT, OT, and military platform systems in alignment with Defence security frameworks including ISM, PSPF, DISP, NIST, and applicable Defence policies and procedures.
- Lead technical assessments and validation activities for cyber security control implementations across IT and OT environments to assess effectiveness, compliance, operational suitability, and residual risk.
- Work within a small specialist team to deliver cyber security risk assessments of military platforms and associated systems for acceptance and sign-off by the Defence CISO, NI&IW, and other Defence stakeholders as required.
- Lead and coordinate on-site cyber security assessments, including stakeholder engagement, technical inspections, evidence collection, vulnerability analysis, security validation activities, and reporting of findings and recommendations.
- Liaise with Capability Managers (CMRs), security specialists, engineers, project teams, and operational support personnel involved in the operation, sustainment, and maintenance of Defence IT and OT systems within military platforms.
- Develop system risk assessment reports and security assessment documentation based on the cyber threat landscape, threat modelling, vulnerability analysis, and intelligence available through Defence, Government, and industry channels.
- Develop and maintain authorisation artefacts including cyber security risk assessments, security assessment reports, and remediation recommendations to reduce cyber security risk.
- Identify security vulnerabilities, analyse cyber risks, and provide remediation and risk mitigation recommendations to support the secure operation and sustainment of Defence capabilities.
- Provide technical cyber security advice and guidance to Defence stakeholders, engineering teams, and project managers regarding emerging threats, secure architecture, control implementation, and security-by-design principles throughout the system lifecycle.
- Develop and improve techniques, processes, and procedures for the management of cyber security information and associated cyber security activities across Defence environments.
- Provide knowledge transfer, mentoring, and guidance to Navy, FCU, DNE, and other Defence personnel regarding cyber security management, assessment methodologies, and cyber security risk management practices.
- Provision updates and recommendations relating to platform equipment, utilities, cyber threat models, and security control improvements to support evolving operational and threat environments.
Requirements
- Australian citizen required for Defence projects.
- Minimum AGSVA NV1 clearance required.
- Able to work across ITAR.
- Ability to obtain a Negative Vetting 2 (NV2) security clearance is preferred.
- Experience working across enterprise Defence project environments.
- Communicates clearly and confidently, both written and verbal.
- Highly organised with strong attention to detail.
- Builds positive relationships and manages stakeholders effectively.
- Works well independently and takes initiative.
- Can manage competing priorities and meet deadlines.
- Adapts easily to change and works well in a team environment.
Skills
- ISM
- PSPF
- DISP
- NIST
- Essential Eight
- Cyber security assessment
- Accreditation
- Security compliance reviews
- Technical risk assessments
- Security-by-design
- Cyber resilience
- Analytical skills
- Collaborative mindset
- Defence security frameworks
- IT
- OT
- Cyber threat landscape
- Threat modelling
- Vulnerability analysis
- Secure architecture
- Secure operation
- Sustainment
- Cyber security management
- Assessment methodologies
- Cyber security risk management practices
- Platform equipment
- Utilities
- Cyber threat models
- Security control improvements
Location
- Sydney, CBD
Work Type
- Onsite
Experience Level
- Minimum AGSVA NV1 clearance
- Ability to obtain NV2 clearance preferred
Education Level
- BACH or other tertiary qualification relative to your role
- Relevant industry qualification in either IRAP, CISSP, CISM, CISA, or ISO27001 Lead Auditor
Benefits
- Long Service Leave @ 7 years (Pro-rata)
- Annual Health & Wellbeing allowance ($250)
- First year leave (5 days)
- Birthday leave
- $2500 annual Higher Education Subsidy
- Veteran Career Development Program
- Service Awards (1, 5, and 10-year)
- Employee Recognition
- Donate for a Cause (matched up to $200)
About the Company
- C4i Solutions is a leading Technology, ICT, and Digital Solutions company, delivering real outcomes for Defence, Government, and Industry partners.
- Veteran-Focused: As a Veteran-owned and operated company, we value your service.
- People First: We are a company that puts people at the centre, fostering a culture of wellbeing, engagement, and respect for your unique skills.
- A Culture That Values You: Be part of a passionate, supportive, and growing team that recognises your contribution and rewards success.
- We work hard, support each other, and make space for a laugh along the way.
