
Principal - Security Governance
1 week ago
Purpose of Role
The Principal, Security Governance role is integral to maintaining the organization's cyber health and resilience against cyber threats. This role is responsible for developing and maintaining robust information security processes, ensuring disaster recovery (DR) readiness, contributing to the cyber security strategy, and managing cyber risk in alignment with business objectives. Additionally, it encompasses enforcing compliance with standards like the ACSC Essential 8 and ISO27001, evolving cyber reporting for management, and supporting security operations. The role also entails assessing third-party vendor risks, updating security training to reflect the current threat landscape, and coordinating audit and penetration testing activities to address vulnerabilities promptly.
Responsibilities & Accountabilities
**Strategy, Policies and Procedures**
- Develop and maintain Information Security processes and operational procedures.
- Ensure technical DR processes are maintained across all services, including those delivered by QTC's key vendors.
- Provide input into the development and maintenance of QTC's Cyber Security Strategy.
- Develop and manage Cyber Security Risk Management processes with an understanding of business requirements and alignment with cyber strategy with business objectives.
**Standards, Reporting and Compliance**
- Ensure compliance with agreed targets and cyber security standards (eg. ACSC Essential 8, ISO27001).
- Develop, maintain, and evolve QTC's cyber reporting for all levels of management.
- Support the broader security operations team in the implementation and management of security controls across QTC's technology environment.
**Third Party Vendor Risk**
- Work with procurement, legal and business stakeholders across the organization to assess and manage third-party vendor risk.
- Review and assess vendor security certifications to ensure validity and applicability to the service being delivered.
**Cyber Awareness and training**
- Support the delivery of security awareness campaigns.
- Update security training content to ensure it remains relevant to the evolving threat landscape.
**Audit, Vulnerabilities and Penetration findings.**
- Co-ordinate and support the successful completion of cyber audit and penetrations testing activities across QTC.
- Support the remediation of all findings to ensure they are addressed in the agreed timeline.
Competencies
Technical Competencies
- Understanding of Operating Systems: Proficiency in various operating systems like Windows, UNIX, and Linux is crucial for managing security across different platforms.
- Networking Knowledge: A solid grasp of networking concepts, protocols, and security measures is essential for protecting an organization's network infrastructure.
- Risk Assessment: Understanding of risk assessment activities to identify vulnerabilities and potential threats to the organization's cyber environment.
- Compliance: Experience in ensuring adherence to relevant cyber security laws, regulations, and standards.
- Threat Modelling: Knowledge of threat modelling tools and techniques to anticipate and mitigate potential attacks.
- Intrusion Detection: Expertise in using intrusion detection systems (IDS) and understanding attack signatures and anomalies that may indicate a security breach.
- Virtualization and Cloud Security: Understanding of virtualization technologies and cloud security principles to secure virtual environments and cloud-based services.
- Cyber Security Frameworks: Familiarity with cyber security frameworks like the NIST Cybersecurity Framework or the ISO/IEC 27001 standard to guide the organization's security strategy.
- Incident Response Planning: Ability to develop and implement cyber incident response plans to quickly and effectively address security breaches.
- Disaster Recovery: Aligning disaster recovery processes with broader business continuity processes and requirements.
- Input into design processes to ensure alignment with existing security standards and policies.
Behavioural Competencies
- Integrity, including upholding strong professional and ethical standards.
- Has developed a deep understanding of what drives each stakeholder (their needs, desires and motivations) Speaks up early and often and takes initiative regarding opportunities for improvement.
- Actively tries to improve knowledge management systems and processes within their team.
- Establishes a positive environment by always acting with positive intent, and assuming positive intent from others.
Leadership Competencies
- Builds trust and confidence with the team by communicating clearly, following through on commitment, values diverse perspectives.
- Holds themselves to a standard of excellence and takes pride in their work.
- Strong communication skills to effectively convey complex technical information to non-technical stakeholders and to collaborate with other departments.
- Ability to lead and
-
Principal Advisor Information Security
2 weeks ago
Brisbane, Queensland, Australia Transport And Main Roads Full timeEmbark on a challenging and transformative journey with the Department of Transport and Main Roads (TMR). As the Principal Adviser Information Security (Governance, Risk & Compliance), you will serve as the guiding light, providing critical advice and steering the strategic direction for our information security policies and governance frameworks.In this...
-
Principal Security Specialist
2 weeks ago
Brisbane, Queensland, Australia Transport And Main Roads Full timeKey responsibilitiesInformation Security Services within CITEC covers the below a broad range of cyber security domains: - Security governance, risk and compliance- Security architecture, roadmap and risk assessment- Security consultancy and professional services to agencies- Security initiatives to enhance our services or develop new security services for...
-
Principal Security Grc Analyst
2 weeks ago
Brisbane, Queensland, Australia Hudson Australia Full timeHudson is proud to be working with a local government agency in the search for a principal cyber security GRC specialist to guide them in the uplift of information security standards across the organisation. A key pillar in this uplift will be achieving ISO 27001 accreditation.The workplace has a flexible hybrid working model (2 days from home). This is a 12...
-
Principal Cyber Security Officer
2 weeks ago
Brisbane, Queensland, Australia Queensland Government Full time $90,000 - $120,000 per year*About the Department of Education: Working for the Queensland Department of Education means joining an organisation that values its people and promotes leadership and innovation. Be part of an environment that respects professionalism and diversity, offers training and development opportunities and embraces flexible careers and work-life balance. Find out...
-
Principal Cyber Security Officer
2 weeks ago
Brisbane, Queensland, Australia Office Of Industrial Relations Full timeReporting to the Manager Cyber Security, Information Communication and Technology Services, the Principal Cyber Security Analyst will:- Proactively contribute to safeguarding the department from security intrusions, threats, weaknesses and exploits to support the effective delivery of information and cyber security services for the department.- Work to...
-
Security Governance Professional
1 week ago
Brisbane, Queensland, Australia beBeeCybersecurity Full time $80,000 - $120,000Security Governance SpecialistThe role of the Security Governance Specialist is critical in ensuring effective security management and compliance within an organization.This position involves developing and implementing security policies, conducting regular risk assessments, and enforcing adherence to regulatory requirements.Develop and enforce security...
-
Security Governance Lead
2 weeks ago
Brisbane, Queensland, Australia Northrop Grumman Full time**Requisition ID: R10186730**:- ** Category**: Security- **Location**: Australia Fortitude Valley, Queensland, Australia | Symonston, Australian Capital Territory, Australia- **Clearance Type**: Secret (NV1)- **Telecommute**: No- Teleworking not available for this position- **Travel Required**: Yes, 10% of the Time- **Positions Available**: 1We are Northrop...
-
Security Governance Lead
2 weeks ago
Brisbane, Queensland, Australia Northrop Grumman Full timeAUSTRALIAN CITIZENSHIP REQUIRED FOR THIS POSITION: YesRELOCATION ASSISTANCE: No relocation assistance availableCLEARANCE TYPE: AU- Secret (NV1)TRAVEL: Yes, 10% of the Time**Description**:We are Northrop Grumman Australia. Our 800 strong team is leveraging unparalleled global resources to deliver sovereign Defence capability aligned to the Government's...
-
Security Officers
7 days ago
Brisbane, Queensland, Australia Mss Security Full timeAbout the CompanyAs one of Australia's leading security companies, with a national footprint across Australia, MSS Security has unrivalled experience in delivering the highest quality of service & protecting some of the nation's highest profile sites. To find out more visit our website atCultureOur employees enjoy working with MSS because we:- Have a high...
-
Security Specialist
2 weeks ago
Brisbane, Queensland, Australia Transport And Main Roads Full timeReporting dReporting directly to the Principal Security Specialist, you have the opportunity to combine your technical skills with consultancy and/or project management depending on client requirements and your own personal direction.The below is a list of high-level responsibilities for this role under the guidance of the Principal Security Specialist: -...