Cyber Security Risk Analyst

16 hours ago


Melbourne Eastern Suburbs, Australia Victorian Government Full time

**Overview**:
**Work Type**:Fixed-term - Full-time

**Salary**: Salary not specified

**Grade**:Grade in advertisement

**Occupation**:IT and telecommunications

**Location**:Melbourne - Eastern suburbs

**Reference**:VG/1872925

Location CFA HQ Burwood
Full Time Fixed Term to 30/06/2026
PTA 5 $107,864 - $121,276 pa (plus 12% superannuation)
- Do you want to work for a values-based, emergency service organisation that puts the community at the centre of everything we do?
- We are proud of the work we do in protecting lives and property, 24 hours a day, 7 days a week.
- With over 51,000 volunteers CFA strives to be an organisation of choice for volunteers and employees. We, embrace individuals with diverse skills, experiences, and backgrounds, recognising the unique value they bring to CFA.
- To learn more about the Country Fire Authority (CFA), we invite you to visit our About Us page.

**About the Role**
- Join CFA's Cyber Security team and help safeguard one of Victoria's most trusted emergency services organisations. We're seeking a Cyber Security Risk Analyst to lead a key project focused on strengthening CFA's cyber security governance, risk and compliance (GRC) capability.
- In this project focussed role, you will drive the uplift of CFA's cyber security policies, risk frameworks and compliance practices to ensure a secure, resilient digital environment. You'll lead the implementation of GRC frameworks, particularly through Microsoft Purview, ensuring alignment with the Victorian Protective Data Security Standards (VPDSS) and ACSC's Information Security Manual (ISM).
- Responsibilities include developing and maintaining policies for identity access management (IAM), data classification and access control; producing risk and compliance reports; assessing third-party risks via UpGuard; and supporting business impact assessments (BIA), business continuity planning (BCP) and disaster recovery planning (DRP).
- You will deliver training and awareness initiatives to build a strong security culture across CFA. To succeed, you will bring proven experience with GRC frameworks, strong knowledge of cyber security standards, practical IAM expertise and the ability to engage effectively with both technical and non-technical stakeholders.
- Be part of something bigger, work with purpose to protect the digital backbone of a critical emergency service.

**About You**
- Tertiary qualifications in Information Technology, Cybersecurity, Law, Business Administration, or a related field, and familiarity with frameworks such as MITRE ATT&CK, OWASP Top Ten, and NIST Cybersecurity Framework is preferred.
- Proven track record of supporting Business Impact Analyses, developing Business Continuity Plans, and Disaster Recovery Plans.
- Previous experience in a GRC-focused role within an IT or cybersecurity context, with demonstrated success in developing and implementing GRC frameworks and compliance strategies.
- Strong skills in writing clear, actionable, and comprehensive security policies, particularly those focusing on identity management.
- Highly developed skills in written communication, inter-personal interactions, and an ability to develop effective relationships and influence key stakeholders.

**Why choose CFA**
- Meaningful Purpose: Your contribution truly makes a difference
- Work-Life Balance: Paid parental leave, generous leave provisions
- Growth Opportunities: Learning and development
- Flexibility: Hybrid work options with flexible work arrangements
- Discounts: Emergency Memberlink discounts on various services
- Wellbeing Focus: Healthy for Life programs, flu vaccinations
- Member Assistance Program: Access support across 8 service pathways

**Your Application**

**Pre-employment Checks**
- Successfully complete Reference Checks, a National Police History Check, Working Rights Check and hold a valid Working with Children Check.

**CFA is committed to creating and maintaining a diverse, inclusive, and safe volunteer and work environment. Our aim is to have a volunteer and paid workforce that reflects the community it serves. First Nations people, women, people of all ages, with disabilities and culturally and linguistically diverse people are encouraged to apply.**

**Applications close: 11:59pm 22nd July 2025**

- Applications close Tuesday 22 July 2025 at 11.59pm

Posted
- 8 July 2025



  • Melbourne, Victoria, Australia StraightUp Full time $80,000 - $120,000 per year

    StraightUp is looking for a Senior Cyber Security Risk Analyst to join our Critical Infrastructure client on an initial 6 month contract. This is part of a large Security uplift program expected to run for several years and you will work across multiple projects. Please note that due to the nature of this work, Australian Citizenship is required and the...


  • Sydney Western Suburbs, Australia NSW Corporate & Enabling Services Full time

    **_Do you want your work to make a difference for NSW?_** - Working to protect the state’s environment and heritage._ - **Are you passionate about protecting critical systems, data and services? Join our team and play a key role in safeguarding the security and resilience of our organisation**: - **Temporary full-time (35 hours per week) opportunity for...

  • Cyber Risk Analyst

    6 days ago


    Melbourne, Australia Swinburne University of Technology Full time

    Join the dynamic and innovate Swinburne Cyber Security team Fulltime, 12-month position at our Hawthorn campus HEW 7 salary + 17% super About the Role The Cyber Risk Analyst will play a crucial role within the Cyber Security team, which is led by the Chief Information Security Officer (CISO) in the IT Department. As a key contributor to the team, the Cyber...

  • Cyber Risk Analyst

    6 days ago


    Melbourne, Australia Swinburne University of Technology Full time

    Join the dynamic and innovate Swinburne Cyber Security team - Fulltime, 12-month position at our Hawthorn campus - HEW 7 salary + 17% super **About the Role** The Cyber Risk Analyst will play a crucial role within the Cyber Security team, which is led by the Chief Information Security Officer (CISO) in the IT Department. As a key contributor to the team,...


  • East Melbourne, Australia CoINVEST Limited Full time

    Join CoINVEST as we modernise our unique organisation's tech capability - Participate in significant innovations and initiatives in Cyber Security - Competitive $$ | Great team culture | 11.5% super and hybrid workplace **Established in 1976, CoINVEST has earned a solid reputation for the responsible manner in which it has managed the Victorian Construction...


  • Melbourne, Australia Latitude IT Full time

    ASX50 company, superb rem + bonus + shares, hybrid working - Tailored learning & development plan - state-of-the-art tools and technologies, cloud platforms & SIEM solutions **Cyber Security Analyst - Strengthen Our Defense, Secure Our Future** **Join Our Dynamic Cyber Security Team and Make an Impact!** Are you passionate about safeguarding critical...


  • Sydney Western Suburbs, Australia HAYS Full time

    Cyber Analyst, Western Sydney, 3-month contract, $600-650 p/d + super **Your new company** This role sits within a government organisation with a head office in Western Sydney. You will work with a government agency with an excellent reputation in a highly productive team. **Your new role** The Cyber security Analyst is responsible for administration of...


  • Melbourne, Victoria, Australia Department of Health Full time $70,000 - $120,000 per year

    About the role:The Principal Cyber Security Analyst Governance, Risk & Audit is responsible for leading and executing end-to-end activities related to internal and external audits, governance forums, cyber security performance reporting, and cyber risk management. This role plays a key part in strengthening the department's cyber resilience by identifying...


  • Melbourne Eastern Suburbs, Australia HAYS Full time

    Exciting role for someone who has experience in GRC **Your new company** This role sits with one of the city councils based in Melbourne and they are looking for a Cyber Security Officer. **Your new role** The role is predominately focused on security risks, governance and compliance management. The purpose of the role is to manage cyber threats, issues,...

  • Cyber Security Lead

    3 days ago


    Melbourne Eastern Suburbs, Australia HAYS Full time

    Are you keen to be a part of Transformation program within Cyber space? If yes, look no further! **Your new company** HAYS TECHNOLOGY & City of Boroondara are proud to announce a joint campaign to find their next senior hire to come and be a part of the Boroondara team as the Cyber Security Lead. You will be leading the information security function within...