
Cybersecurity Risk Manager
2 weeks ago
We’re inventing the future, right here, right now, at Thales. We design the critical security solutions of tomorrow by combining the curiosity to explore, the intelligence to question and the vision to create. Together we solve complicated problems by combining our experience in the market with our leading research and development capabilities.
A great opportunity has become available for an experienced **Cybersecurity Risk Manager **to join the renown safety and mission critical OneSKY program.**
The Cybersecurity Risk Manager role supports the delivery of the CMATS air-traffic management system in Australia, which is part of the OneSKY program. CMATS is a complex system and you work in a complex and challenging environment that employs well-defined system engineering processes to ensure fit for use and fit for purpose. In this role you actively manage the cyber risk of the CMATS solution through identification and evaluation of relevant risks in the context of threat sources, vulnerabilities, existing controls, business impact, and target security accreditations.
**KEY ACTIVITIES AND RESPONSIBILITIES**
As a Cybersecurity Risk Manager, you managing cyber risk through the following activities:
- Perform cyber risk assessments, capture and analyse all security requirements, and determine applicable security controls, and develop a threat model based on an agreed list of threat sources and events.
- Identify system, segment, component, and product vulnerabilities, and their impact on the CMATS solution and customer, and develop remediation strategies as appropriate.
- Monitor the effectiveness of remediation strategies and periodically update the security risk register.
- Create and maintain key cyber engineering and accreditation documents such as the Security Accreditation Plan, System Security Plan (SSP), Security Risk Management Plan (SRMP), the Threat and Risk Assessment (TRA), the security risk register, and other relevant contractual documents.
- Produce engineering design artefacts in relation to mitigation strategies including design considerations, design constraints, or design decisions that impact the overall solution design of CMATS.
- Support project IV&V activities, including the Certification and Accreditation phases in which the residual security risks are monitored and appropriately tested and assured, using agreed remediation strategies including penetration tests.
- Present the identified security risks, the analysis conducted to demonstrate effectiveness of proposed risk remediation strategies, and the proposed solutions to customer representatives during the Security Working Groups (SWG).
- Provide advice to internal and external customers on security risks of the CMATS system.
- Liaise with the appropriate federal government security organisations, customer representatives, certification authorities, and relevant service providers.
- Work with other project team members to develop cost and schedule estimates.
- Attend and actively participate in internal and external technical reviews.
**SKILLS & EXPERIENCE**
- Excellent knowledge of the Australian Government Information Security Manual (ISM) and PSPF, and accreditation requirements.
- Working with formal risk management methodologies and documents.
- Contemporary security solutions in heterogeneous environments (Linux and Windows) using a range of technologies and products
- Participating in end-to-end engineering processes with documented traceability
- Authoring and reviewing technical documentation
- Strong presentation and verbal communications and liaison skills
**QUALIFICATIONS**
- Bachelor-level qualification or higher in Information Security (or equivalent demonstrated experience)
- CISSP, CISM, SANS GIAC, SABSA, or similar professional security certifications
**SOME OF OUR GREAT BENEFITS**
- Competitive base salary + Super + Bonus
- Paid health insurance for you and your family
- Employee discounts with a number of affiliates (Travel, Car hire, Tech)
- Access to Fitness Passport
- Modernised Paid Parental leave
- Veterans Leave
Wellbeing matters at Thales, and where possible we encourage flexible working.
-
Cybersecurity Manager, Anz
2 weeks ago
Melbourne, Australia l'Oréal Full timeThe Cybersecurity Manager has the primary responsibility for all aspects of information security and technology risk management for Australia and New Zealand. ABOUT THE JOB - Lead the implementation and enforcement of information security governance, including policies, standards, and procedures, in collaboration with various counter-partners such as IT,...
-
Cybersecurity Consultant
2 weeks ago
Melbourne, Australia Datacom Full time**Position**: Cybersecurity Consultant **Datacom Location**: Australia (any city, advertising in Canberra, Sydney and Melbourne) Our Why Datacom works with organisations and communities across Australia and New Zealand to make a difference in people’s lives and help them to use the power of tech to innovate and grow. About the Role (Your Why) The...
-
Cybersecurity Business Analyst
2 weeks ago
Melbourne, Victoria, Australia Rosewood Partners Full time $80,000 - $120,000 per yearThe CompanyBehind the scenes of some of the world's most critical medical innovations lies a team of engineers, scientists, and problem-solvers dedicated to advancing healthcare. This organisation is globally recognised for building sophisticated solutions that shape the future. Their Melbourne R&D hub is at the forefront—delivering technology used by...
-
Cybersecurity Advisor
5 days ago
Melbourne, Australia AGL Energy Full timeAs the needs of our customers change, so do we. At AGL, we believe progress is powered by our people. If you’re set on making real change for tomorrow, we have the scale, resources and ambition to get it started today. Now’s an extraordinary time to work with us. We’re taking the lead on renewables and expanding our products to make them more...
-
Melbourne, Australia Talent International Full time**Job Details**: **Location** Brisbane **Salary** plus bonuses **Job Type** Full Time **Ref** BBBH98236_1675639588 **Contact** Kylie McManus **Posted** about 3 hours ago **Opportunity** Our ASX listed Client has experienced a doubling in EBIDTA in the past financial year and has a solid platform for growth and expansion into new territories. A...
-
Melbourne, Australia Talent International Full time**Job Details**: **Location** Melbourne **Salary** plus bonus **Job Type** Full Time **Ref** BBBH96215_1675637551 **Contact** Kylie McManus **Posted** about 3 hours ago **Opportunity** Our ASX listed Client has experienced a doubling in EBIDTA in the past financial year and has a solid platform for growth and expansion into new territories. A...
-
Melbourne, Australia Talent International Full time**Job Details**: **Location** Perth **Salary** plus bonus **Job Type** Full Time **Ref** BBBH98235_1675639190 **Contact** Kylie McManus **Posted** about 3 hours ago **Opportunity** Our ASX listed Client has experienced a doubling in EBIDTA in the past financial year and has a solid platform for growth and expansion into new territories. A leader...
-
Cybersecurity Engagement Manager
3 days ago
Melbourne, Australia Capgemini Full time**About Capgemini** Capgemini is a diverse collective of more than 350,000 strategic and technological experts based across more than 50 countries, partnering with world-renowned clients to transform and manage their businesses. We are dedicated to leveraging cloud, data, AI, connectivity, software, digital engineering, and platforms to address the entire...
-
Journeyman Cybersecurity Engineer
2 weeks ago
Melbourne, Victoria, Australia V2X Full time $80,000 - $120,000 per yearOverview This position description is subject to change at any time as needed to meet the requirements of the program or company. Working across the globe, V2X builds smart solutions designed to integrate physical and digital infrastructure from base to battlefield. We bring 120 years of successful mission support to improve security, streamline...
-
Cybersecurity GRC Consultant
4 weeks ago
Melbourne, Australia Triskele Labs Full timeOverview Triskele Labs are one of the leading providers of cybersecurity services in Australia. We assist clients to reduce their risk of a cyber compromise through the delivery of risk-considered controls. Triskele Labs are one of the last remaining boutiques in Australia. We are currently the largest CREST Registered Penetration Testing company in...