Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Risk Management Analyst role.
Rezi rewrites your resume against Cubic Corporation's job description. Free.

Tailor your resume to this Risk Management Analyst role.
Rezi rewrites your resume against Cubic Corporation's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Risk Management Analyst posting at Cubic Corporation — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Risk Management Analyst posting at Cubic Corporation — free, in seconds.
About the Role
As a member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. You will evaluate the security controls and operating environment to ensure compliance with organizational security policies and controls, plan and prepare the scope of IT compliance evaluation programs, isolate potential risks, and develop mitigation plans. You will also partner with external auditors to coordinate and facilitate PCI-DSS and ISO 27001 compliance efforts.
Responsibilities
- Serve as the Subject Matter Expert on Security Risk Assessment methodology, policy, strategy, and processes.
- Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.
- Coordinate with Internal/External Auditors and Information Technology teams to complete periodic audits.
- Schedule and conduct control walk-through meetings and address follow-up procedures.
- Lead design and control reviews and assessments to support continuous compliance with security policies and standards.
- Manage security review processes for all solutions to ensure design and implementation meet compliance requirements (PCI-DSS, ISO 27001, SOC 1 & SOC 2, Australian Essential 8, NZ-ISM).
- Document and communicate areas of non-compliance.
- Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud, physical IT infrastructure, vendors, and third parties.
- Identify stakeholders for remediation of compliance gaps and escalate issues constructively.
- Track progress towards remediation and manage escalations.
- Communicate system compliance gaps and develop remediation plans with system operators and security subject matter experts.
- Capture compliance gaps and remediation plans in the OneTrust GRC system.
- Perform controls monitoring for complex customer-facing systems using OneTrust.
- Liaise with Cubic customers and Security Teams to build positive relationships.
- Educate Security Management and Security Team Members on compliant IT processes and controls.
- Prepare and maintain process and control documentation.
- Aid in the development of solutions to audit-identified problems and translate them into practical recommendations.
- Partner with Operations and Engineering Teams to ensure timely remediation of issues.
- Follow up on recommendations and appraise corrective actions.
- Ensure Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.
- Review vendor contracts and SOC reports to evaluate impact on company controls.
- Coordinate with third-party vendors.
- Demonstrate accountability for work assignments and proactive communication.
- Proactively identify effective solutions for challenges.
- Demonstrate ethical behavior and accurate communications.
- Operate in a professional manner in tense or continuous settings.
- Comply with Cubic’s Quality Management System.
- Comply with Cubic’s quality, health, safety, and security policies.
- Support the company's strategic objectives and collaborate across departments.
- Comply with Cubic Human Resources Procedures.
Requirements
- Minimum 8 years’ experience in services or IT systems in a mission-critical setting.
- At least 5 years’ experience working in IT security and/or Payment Card processing systems.
- Strong understanding of technical concepts.
- Demonstrated ability to understand complex internally developed systems.
- Must reside within commuting distance from CTS offices in Brisbane QLD, Sydney NSW or Wellington NZ.
- Able to periodically travel within the region.
Skills
- Strong written and oral communication skills in English.
- Capability to use Microsoft Office solutions.
- Ability to effectively and openly collaborate with team members, clients, IT management, staff, and business units in a cross-functional and matrixed IT organization.
- Comfortable working with staff at all levels and in other geographical locations.
- Familiarity with PCI DSS 4, ISO 27001-2022, and/or SOC I/II requirements and audits.
- Expert level experience collaborating with stakeholders and solution providers in a cross-functional and matrixed IT organization.
- Ability to adapt style and efforts to persuade in delivering messages that relate to the wider business.
- Frequently called on to advise others on complex matters.
- Accountable through team for delivery of business targets.
- Advanced wide-ranging experience, using in-depth professional knowledge, acumen, concepts, and company objectives to develop and resolve complex models and procedures.
- Provides solutions to issues in creative and effective ways.
- Understands the interrelationships of different disciplines.
- Directs the application of existing principles and guides development of new policies and ideas.
- Understands and works on complex issues where analysis of situations or data requires in-depth evaluation of variable factors.
- Determines methods and procedures on new assignments.
- Exercises judgment in selecting methods, evaluating, and adapting complex techniques and evaluation criteria for obtaining results.
- Deep understanding of security risks and threats as they relate to the company’s operating environments (Desirable).
- Relevant security or IT compliance certification (e.g., CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA) (Desirable).
- Knowledge of or willingness to learn information security best practices for Open Payments, Mobility as a Service, data classifications, Microsoft Azure, AWS (or similar) cloud security and infrastructure, Web infrastructure security (Applications and APIs), Network security tools (IDS/IPS, firewalls, etc.), Encryption technology and implementation, Database security, Operating system security and hardening, vulnerability assessment tools and writing risk mitigation plans, and SIEM and FIM solutions (Desirable).
Location
- Brisbane QLD
- Sydney NSW
- Wellington NZ
Work Type
- Employee
- Full-time
Experience Level
- Minimum 8 years’ experience in services or IT systems in a mission critical setting
- At least 5 years’ experience working in IT security and/or Payment Card processing systems
Education Level
- University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.
About the Company
- Cubic Corporation creates and delivers technology solutions in transportation to make people’s lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation.
- Cubic is committed to solving global issues through innovation and service to our customers and partners.
- Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly.
- CTS provides Fare and Payment card services to government and municipal customers across the globe.
Equal Opportunity
- We are committed to creating an inclusive workplace and welcome applications from people of all backgrounds.
- We do not discriminate based on any protected characteristic under applicable law.