Risk Management Analyst, AUS

3 weeks ago


City of Brisbane, Australia Cubic Corporation Full time

# **Business Unit:**Cubic Transportation Systems# # **Company Details:**# When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people’s lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners. We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). Explore more on Cubic.com.# **Job Details:**Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.**Job Summary:**As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating environment to ensure compliance with organization security policies and controls. Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develop mitigation plans. Partners with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts. This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.**RESPONSIBILITIES****Essential Job Duties** **and Responsibilities*** Perform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.* Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.* Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits. Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilities* Lead the design and control reviews and assessments to support continuous compliance with security policies and standards* Manage security review processes for all solutions to ensure they their design and implementation meets compliance requirements – including: PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements like the Australian Essential 8 and New Zealand NZ-ISM. Document and actively communicate any areas where the solutions and processes are not fully compliant.* Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.* Identify stakeholders in remediation of compliance gaps and actively escalate issues to them in a constructive manner that helps them understand the actions required. Work to gain acceptance of responsibility and track progress towards remediation. Actively manage escalation as needed if solutions are not resolved in a timely manner.* Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.* Capture compliance gaps and remediation plans in the OneTrust GRC system. Plans, reviews, and performs (as needed) controls monitoring around complex customer facing systems using the One Trust.* Liaise/engage with Cubic customers and Security Teams to build positive relationships and outcomes* Supports efforts to educate Security Management and Security Team Members in compliant IT processes and controls. Prepare and maintain process and control documentation* Aid in the development of solutions to problems identified during audits and translates these solutions into practical recommendations. Partner with Operations and Engineering Teams to ensure timely and acceptable remediation of issues.* Follow up on recommendations and appraises corrective actions taken to improve deficient conditions. To the greatest extent possible, ensure all Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.* Review vendor contracts and SOC reports to evaluate the impact on the company’s controls. Coordinates with third party vendors where appropriate.**General Duties and Responsibilities:*** Reliably demonstrate accountability for work assignments and proactive communications about issues and status. A strong history of proactively identifying effective solutions for challenges.* Able to reliably demonstrate ethical behavior and accurate communications even when complex factors are involved.* Able to operate in a professional manner, even in tense or continuous settings.* Comply with Cubic’s Quality Management System* Comply with Cubic's quality, health, safety, and security policies.* Support the company's strategic objectives and collaborate across departments.* Comply with Cubic Human Resources Procedures**SKILLS/EXPERIENCE/KNOWLEDGE**Essential:* Strong written and oral communication skills in English, with capability to use Microsoft Office solutions. Ability to effectively and openly collaborate with team members clients, IT management, staff, and business units in a cross functional and matrixed IT organization* Comfortable working with staff at all levels and in other geographical locations within the organization* Familiarity with PCI DSS 4, ISO 27001-2022, and or SOC I/II requirements and audits.* Expert level experience collaborating with stakeholders and solution providers in a cross functional and matrixed IT organization. Able to adapt style efforts to persuade in delivering messages that relate to the wider business. Is frequently called on to advise others on complex matters and may be accountable through team for delivery of business targets.* Exhibits advanced wide- ranging experience, using in- depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures. Provides solutions to issues in creative and effective ways. Understands the interrelationships of different disciplines. Directs the application of existing principles and guides development of new policies and ideas.* Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors. Determines methods and procedures on new assignments. Exercises judgment in selecting methods, evaluating, adapting complex techniques and evaluation criteria for obtaining results.Desirable:* Deep understanding of security risks and threats as they relate to the company’s operating environments.**QUALIFICATIONS**Essential:* Minimum 8 years’ experience in services or IT systems in a mission critical setting.* University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.* At least 5 years’ experience working in IT security and/or Payment Card processing systems. Strong understanding of technical concepts, as well as demonstrated ability to understand complex internally developed systems.* The candidate must reside within commuting distance from CTS offices in Brisbane QLD, Sydney NSW or Wellington NZ, and be able to periodically travel within the region.Desirable* Relevant security or IT compliance certification in one or more areas, such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA or equivalent.* Knowledge of or willingness to learn information security best practices as it pertains to Open Payments, Mobility as a Service, data classifications,
#J-18808-Ljbffr



  • Brisbane, Queensland , Australia Risk & Security Management Full time $80,000 - $120,000 per year

    About Us Risk & Security Management (RS) is a leading provider of end-to-end receivables and mercantile services, delivering innovative solutions and expert advice to clients across multiple industry sectors. We provide a range of trusted services to major banks, large financiers, insurers, government departments, global corporations, and legal firms. As we...


  • City of Melbourne, Australia Village Roadshow Ltd Full time

    Based in modern offices in South Yarra, Village Roadshow Ltd is a leading Australian entertainment company, operating core businesses in Cinema, Movie Production, Film, TV, Digital Distribution and Theme Parks. The people at Village are what makes it a vibrant, fun place to work, and we strive to create rewarding and memorable experiences for our...


  • Council of the City of Sydney, Australia Advanced Personnel Management Full time

    A diversified insurance company is looking for a Risk & Compliance Analyst to enhance their operational risk management framework. Located at their Head Office in Sydney, this hybrid position offers flexibility, competitive salary, and extensive benefits. Ideal candidates will possess a degree and 3 years of risk and compliance experience, working closely...


  • Brisbane, Queensland, Australia Risk & Security Management Pty Ltd Full time $80,000 - $120,000 per year

    About UsRisk & Security Management (RS) is a leading provider of end-to-end receivables and mercantile services, delivering innovative solutions and expert advice to clients across multiple industry sectors. We provide a range of trusted services to major banks, large financiers, insurers, government departments, global corporations, and legal firms. As we...

  • Risk Analyst

    2 weeks ago


    Council of the City of Sydney, Australia Thales Group Full time

    At Thales, we know technology has the ability to make our world more secure, sustainable, and inclusive – and that it’s all driven by human intelligence.Because it takes human intelligence to build and power the systems and solutions that people depend on every day. So we stay curious and make space for diverse points of view. We share what we know and...

  • Risk Analyst

    4 days ago


    Brisbane, Queensland, Australia 7b69f57e-9d29-4716-bb08-f87f47f153ad Full time $90,000 - $120,000 per year

    Risk Analyst - Legal Metrology (EL1 Equivalent) - Long-Term ContractLocation: Australia-wide (flexible/hybrid options may be available)Contract Type: Long-term hourly-rate contractClearance: Must be eligible for baseline security clearance (police check required)Citizenship: Australian citizens onlyAbout the OpportunityOur client - a federal government...


  • Brisbane, Australia Perigon Group Full time

    Competitive remuneration package - High performing energy markets organisation - Work under an extremely capable leader, take your career to the next level Our client is a well respected energy markets & power generation organisation. They are leaders in their field and offer safe and sustainable power, that is reflective of the current global needs. This...


  • Gold Coast City, Australia The Star Ent Group Full time

    Apply now Job no: 534277 Work type: Permanent Full Time Location: Sydney, Gold Coast, Queensland, Brisbane Categories: Corporate/Property Support Risk Assurance and Audit Data Analyst – Group Risk Internal Audit and Assurance The Star Entertainment Group (TSEG) is a publicly listed company on the ASX. Our purpose is to create fun at trusted destinations...

  • Investment Risk

    3 weeks ago


    City of Melbourne, Australia FE Fundinfo Group Full time

    Play a key role in ensuring sound investment governance, risk oversight, and portfolio integrity across a diverse range of managed account portfolios in one of Australia’s leading investment research and consulting firms. As an Investment Risk & Governance Analyst, you will have the opportunity to apply your quantitative analysis skills and risk...

  • Lead Analyst

    5 days ago


    Council of the City of Sydney, Australia Reserve Bank of Australia Full time

    Lead Analyst - Project Risk page is loaded## Lead Analyst - Project Risklocations: Sydneytime type: Full timeposted on: Posted Todayjob requisition id: JR3770* **Hybrid work environment - 50% Office/Home*** **Fulltime/Permanent Role*** **Join a high-performing team at the heart of the Bank’s transformation agenda and help shape how we manage risk...