Assessment and Authorisation
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
About Accenture
Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialised skills across more than 40 industries, we offer Strategy and Consulting, Technology and Operations services and Accenture Song — all powered by the world’s largest network of Advanced Technology and Intelligent Operations centers. Our 799,000 people deliver on the promise of technology and human ingenuity every day, serving clients in more than 120 countries. We embrace the power of change to create value and shared success for our clients, people, shareholders, partners and communities. Visit us at www.accenture.com.
Job Description
We are seeking an experienced and results-driven Security Assessment and Authorisation (A&A) consultant, to perform security risk management and assurance activities across systems, applications, and third-party services. The role ensures that systems meet required security standards; risks are properly assessed and documented, and appropriate authority to operate (ATO) are obtained and maintained.
This position works closely with system owners, architects, project teams, cybersecurity specialists, and compliance stakeholders to guide them through the A&A lifecycle and ensure alignment with organisational, regulatory, and Australian government frameworks.
Key Responsibilities
- Security Risk Management
- Conduct risk assessments to identify, evaluate, and mitigate security risks across projects and operational environments.
- Facilitate risk workshops with stakeholders to capture and validate security risks.
- Monitor and report on risk status, treatment progress, and residual risk to governance forums.
- Ensure security controls are implemented and tested to mitigate identified risks effectively.
- Help project manage day to day tasks with the manager and program leads.
- Security Assessment and Authorisation
- Execute system security authorisation processes in accordance with ISM (Information Security Manual) and the client's security requirements, including Risk Management Framework (RMF) steps.
- Prepare and maintain risk assessments, and accreditation documentation.
- Ensure compliance with security controls for governance, identification, protection, detection, and response functions.
- Maintaning Compliance
- Develop and maintain security documentation as per the client's security guidelines (e.g., security policies, procedures, incident response plans).
- Support compliance obligations by adhering to ISMAustralian Government’s security compliance requirements for classified and controlled information handling.
- Maintain accurate records of security authorisations, exceptions, and audit evidence for accreditation reviews.
- Stakeholder Engagement
- Liaise with Authorising Officers, system owners, and project teams to ensure security documentation meets the client's required standards.
- Provide guidance on ISM, Essential Eight, and the Department’s specific security controls during project delivery.
- Monitoring & Reporting
- Support in establishment and ongoing management of GRC (Governance, Risk and Compliance) tooling.
- Track and report on security authorisation status, documentation, deliverables, and compliance gaps.
- Assist in continuous monitoring activities and maintain documentation for audits and inspections.
Qualifications and Skills
- Education & Certifications
- Bachelor’s degree in Cybersecurity, Information Technology, or related field.
- Certifications such as CISM, CRISC, CISSP, IRAP Assessor, or equivalent security accreditation experience preferred.
- Technical Knowledge
- Strong understanding of Australian PSPF and ISM cybersecurity principles and NIST guidelines (Govern, Identify, Protect, Detect, Respond).
- Deep understanding of the Essential 8 requirements for classified information and processes.
- Experience with security documentation (Accreditation packages).
- Skills
- Excellent documentation and organisational skills with attention to detail.
- Ability to interpret and apply ISM and security controls in practical scenarios.
- Experience in collaboration tools (e.g., SharePoint, Confluence)
- Familiarity with security GRC (Governance, Risk and Compliance) platforms.
- Strong communication skills for engaging operational and business stakeholders.
Security Clearance
- Current Baseline Security Clearance and willingness to upgrade to NV1
- Australian Citizens with ability to obtain a clearance considered
Must be willing to work onsite 5 days a week
This is required.
Why Join Us?
This is an excit