Cyber Security Risk Advisor

1 week ago


Sydney, New South Wales, Australia UNSW Australia Full time
Cyber Security Risk Advisor

Job no: 525136
Work type: full time
Location: Sydney, NSW
Categories: Information Technology, Cyber

  • Employment: Full time (35 hours per week)
  • Continuing role as a Cyber Security Risk Advisor
  • Remuneration: Excellent salary package including leave loading and generous superannuation
  • Location: Based in Kensington, Sydney (hybrid working available)

About UNSW Sydney:
UNSWe ain't like other places you've worked. Yeah, we're a large organization with a diverse and talented community; a community doing extraordinary things. Together, we are driven to be thoughtful, practical, and purposeful in all we do. Taking this combined approach is what makes our work matter. It's the reason we're one of the top 50 universities globally and a member of Australia's prestigious Group of Eight. If you're looking for a career where you can thrive, be challenged, and do meaningful work, you're in the right place.

The Cyber Security Risk Advisor supports the operational delivery of a fit-for-purpose and adaptive Cyber Security Governance framework and Information Security Management System (ISMS). Responsible for the assessment of information security risk associated with ICT services and IT initiatives, and the provision of cyber security subject matter expertise, risk assessment, assurance, and advisory services to university stakeholders. The Cyber Security Risk Advisor reports to the Cyber Security Advisory Manager and has no direct reports.

Accountabilities

  • Delivery of risk advisory and risk assessment services to university stakeholders
  • Review solution/capability design and architecture artifacts, identify and assess security risks, recommend, and prepare high-quality reports detailing security issues and risk treatment actions.
  • Perform risk assessment of 3rd party/supply chain risk exposure.
  • Update the cyber risk register with risks from projects, penetration tests, exemptions, and changes.
  • Socialize the risks to the relevant teams and administer the completion of risk treatment and policy compliance initiatives prior to deployment or change.
  • Guide University stakeholders in the practical application of security and risk management concepts, principles, strategies, and relevant industry standards.
  • Provide expert advice on cyber security compliance by ensuring and communicating adherence to policies, standards, architecture, and strategies (including surrounding cloud services).
  • Ensuring any non-compliance, control under-performance or risk beyond appetite is appropriately recorded and effectively escalated for remediation.
  • Drive penetration testing scope validation, penetration test report review, risk assessment and retesting recommendations of IT systems and infrastructure as a part of project assurance.
  • Advise on new or complex exemptions requests.
  • Identify and recommend required changes to cyber security policies and standards.
  • Deliver periodic cyber security risk advisory service SLA and KPI metrics to drive compliance.
  • Support the independent audit of cyber security controls on behalf of the University, including statutory audits completed by the Audit Office of NSW.
  • Stay up to date and aware of legal, regulatory compliance, and contractual obligations relevant to the University's management of cyber security risk.
  • Promote awareness of the University's internal and external environment for emerging cyber security threats.
  • Build effective working relationships with internal and external stakeholders to develop innovative solutions that meet business needs.
  • Promote a culture of continuous improvement, championing professional standards, innovation, and methods.
  • Other duties appropriate and in line with this position as requested by the Cyber Security Risk Advisory Manager.
  • Align with and actively demonstrate the UNSW Values in Action: Our Behaviors and the UNSW Code of Conduct.
  • Ensure hazards and risks psychosocial and physical are identified and controlled for tasks, projects, and activities that pose a health and safety risk within your area of responsibility.

Skills and Experience

  • Minimum 5 years' experience in the delivery of cyber security risk assessment, consulting, and advisory services, ideally with experience working for a global consulting firm, technology giant, or large government agency or defense consultancy.
  • A relevant Degree with extensive experience in cyber security governance, compliance, risk management, or cyber security operations within major organizations or an equivalent level of knowledge gained through any other combination of education, training, and experience.
  • Strong cyber security GRC fundamentals and strong knowledge of cyber security principles and practices.
  • Excellent understanding of industry-wide security standards and compliance frameworks such as ISO 27001, NIST 800-53, CSA, Essential 8, PCI DSS, COBIT 5, Mitre ATT&CK etc.
  • Relevant industry certification(s) such as CISSP (Ideal), CEH, CISM, CRISC, GSEC, AWS Security Specialty, Microsoft Azure (highly desirable).
  • Excellent understanding of current security technologies, products, and services, including native cloud security controls in AWS and Azure.
  • Strong interpersonal, communication, and negotiation skills including the ability to develop effective relationships and influence key stakeholders at all levels in the organization.
  • Ability to present with credibility and translate technical and complex information concisely for diverse audiences using strong analytical and problem-solving skills.
  • Demonstrated high level of personal motivation, resilience, and ability to work effectively individually or in teams.
  • An understanding of and commitment to UNSW's aims, objectives, and values in action, together with relevant policies and guidelines.
  • Knowledge of health & safety (psychosocial and physical) responsibilities and commitment to attending relevant health and safety training.


  • Sydney, New South Wales, Australia University of New South Wales Full time

    Employment: Full time (35 hours per week) Continuing role as a Cyber Security Risk Advisor Remuneration: Excellent salary package including leave loading and generous superannuation Location: Based in Kensington, Sydney (hybrid working available) About UNSW Sydney:UNSW isn't like other places you've worked. Yes, we're a large organisation with a diverse and...


  • Sydney, New South Wales, Australia University of New South Wales Full time

    Job no: 525136Work type: full timeLocation: Sydney, NSWCategories: Information Technology, Cyber Employment: Full time (35 hours per week) Continuing role as a Cyber Security Risk Advisor Remuneration: Excellent salary package including leave loading and generous superannuation Location: Based in Kensington, Sydney (hybrid working available)About UNSW...


  • Sydney, New South Wales, Australia Bluefin Resources Full time

    Prestigious State Government Client w Excellent Team Culture 6 Month Contract w Guaranteed Extensions Sydney Location w Excellent Hybrid Working FlexibilityA large government organisation is on the lookout for a mid level Cyber Secuirty Advisor for a 6 month contract based from their head office in the Sydney CBD. As a Cyber Security Consultant and Advisor,...


  • Sydney, New South Wales, Australia Bluefin Resources Full time

    Prestigious State Government Client w Excellent Team Culture 6 Month Contract w Guaranteed Extensions Sydney Location w Excellent Hybrid Working FlexibilityA large government organisation is on the lookout for a mid level Cyber Security Advisor for a 6 month contract based from their head office in the Sydney CBD. The purpose for the role is to be...


  • Sydney, New South Wales, Australia Cyber Crime Full time

    Singtel The Singtel Group, Asia's leading communications group provides a diverse range of services including fixed, mobile, data, internet, TV, infocomms technology (ICT) and digital solutions. View company page We don't sit back and wait for the future to happen, we are out there crafting our own path through new technology, innovation, and investment....


  • Sydney, New South Wales, Australia NSW Government -Department of Customer Service Full time

    Cyber Security Advisor (Policy Development) Location: Sydney Region / Sydney City Role type: 6 12 month Temporary Opportunity Salary: Grade 7/8, base salary starting at $101,947 + superannuation and leave loadingCyber Security NSW is looking for a Cyber Security Advisor to join their team. This role is a great opportunity for those seeking to develop their...


  • Sydney, New South Wales, Australia Cyber Crime Full time

    Exciting opportunity to join a best-in-class cyber teamDevelop broad experience in cyber security operationsWork alongside an inspiring, supportive, and collaborative Cyber teamBuild Your Expertise: Become a Cyber Security ProfessionalLooking to launch your career in cyber security? Insignia Financial is building a world-class cyber security team, and we're...


  • Sydney, New South Wales, Australia NSW Government -Department of Customer Service Full time

    Cyber Security Advisor (Training & Resilience Stream)- **Role type**: Ongoing, full-time opportunity- Salary: DCS Clerk Grade 7/8, annual base salary starting at $101,947 plus employer's contribution to superannuation and annual leave loading- Location:SydneyAbout Us:The Department of Customer Service (DCS) is transforming the way NSW Government agencies...


  • Sydney, New South Wales, Australia Cyber Crime Full time

    KPMG Australia KPMG is a global network of professional firms providing Audit, Tax and Advisory services. View company page Immerse yourself in our inclusive, diverse and supportive cultureChoose the way you want to work by embracing our flexible work arrangementCollaborate with sector and technical experts to grow your knowledge and networkKPMG Australia...


  • Sydney, New South Wales, Australia Association of Independent Schools of NSW Full time

    Location:AISNSWEmployment Type:FT - Full-Time TemporaryDepartment:TechnologyClosing Date:22/02/2023A wonderful career opportunity for a highly skilled, motivated security professional to become a trusted advisor in cyber security functions to over 500 independent schools across NSW by joining the Association of Independent Schools of NSW (AISNSW) as the...


  • Sydney, New South Wales, Australia NSW Government -Department of Customer Service Full time

    Principal Advisor, Cyber Security (Awareness Stream)- **Role type**: On-going, full-time opportunity- Salary:DCS Clerk Grade 11/12, annual base salary starting at $134,411 plus employer's contribution to superannuation and annual leave loading- Location: SydneyAbout Us:The Department of Customer Service (DCS) is transforming the way NSW Government agencies...

  • Cyber Security

    1 week ago


    Sydney, New South Wales, Australia Firesoft People Full time

    Cyber Security - Associate Director (GRC)Global Professional Services$180k - $200k + SuperBrisbane BasedOur client a renowned organization consistently recognized as one of the best companies to work for. As an Associate Director in Cyber Security Governance, Risk, and Compliance, you will have the opportunity to work on some of the largest Cyber Security...


  • Sydney, New South Wales, Australia Cognizant Technology Solutions Full time

    About CognizantCognizant (Nasdaq-100: CTSH) is one of the world's leading professional services companies, transforming clients' business, operating and technology models for the digital era. Our unique industry-based, consultative approach helps clients envision, build and run more innovative and efficient businesses.Our CultureYour passion, integrity and...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time

    About the job Cyber security specialist Job Description for Cyber Security Specialist in Melbourne/SydneyA minimum of 10 years of experience in cyber security roles within major organizations, focusing on management of governance, risk, and compliance.Relevant industry certification(s) such as CISSP, CISM, CRISC, CISA, ISO/IEC 27001 Lead Implementer/Auditor...


  • Sydney, New South Wales, Australia King & Wood Mallesons Full time

    New role to the firm - Enhance what we have and take the next step in your career- With a few years experience behind you, you will be looking to introduce what you've learnt in developing and implementing cyber governance frameworks and processes, ensuring that we meet our information security and compliance goals.- As a leading law firm, we actively seek...


  • Sydney, New South Wales, Australia Charterhouse Full time

    Join a NSW State Government Department and have an active role in keeping Australian's Cyber Safe:Up to $700/day + Superannuation (PAYG or PTY options available) with weekly pay:- 6-month contract with potential for extension:Hybrid working from home, office located in Sydney Olympic ParkRole Description Assisting the manager and team with implementation of...


  • Sydney, New South Wales, Australia Mitalent Recruitment Group Full time

    Security (Information & Communication Technology) The CompanyThis ASX Listed nationally recognised brand with an international presence is seeking a Cyber Security Audit Manager to join their Corporate Team in a WFH environment.This is a role for a Manager who is career driven and looking to succeed. Interact with various key decision makers within the...

  • Cyber Risk

    1 week ago


    Sydney, New South Wales, Australia NTT Full time

    Cyber Risk & Compliance ManagerNTT is a leading global IT solutions and services organisation that brings together people, data and things to create a better and more sustainable future.In today's 'iNTTerconnected' world, connections matter more now than ever. By bringing together talented people, world-class technology partners and emerging innovators, we...


  • Sydney, New South Wales, Australia Easy Authoring Full time

    6 months contract role with possible extension:- Daily pay rate up to $700 + Super.**:Working 38 hours per week, 7.6 hours per day:- Work Location: Sydney Olympic Park.PURPOSE OF THE ROLE:You will assist the manager and the team with the implementation of the Cyber Security Policy and Essential 8, including annual reporting and attestation.KEY...


  • Sydney, New South Wales, Australia Troocoo Full time

    Our client, a leading organization, is actively seeking a qualified Cyber Security Analyst to join their team. This exciting opportunity allows for a hybrid work arrangement, primarily based at one of their HQ locations in Australia, with the option for remote work in line with local office policies. As a Cyber Security Analyst, you will report to the Cyber...