Cyber Security Assurance Engineer

CIVMEC · Henderson WA 6166 · Full time
Posted 9d ago

Cyber Security Assurance Engineer

CIVMEC
~$90k - $120k(Estimated)
KEY POINTS WE FOUND
  • Provide technical assurance of systems and security controls.
  • Design and implement security controls for sensitive environments.
  • Conduct technical security risk assessments and maintain governance documentation.

The Company

Civmec is an Australian-owned, integrated, multidisciplinary heavy engineering and construction services provider to the energy, resources, infrastructure, marine and defence sectors. With a pipeline of more than $1 billion in current and future projects, our diversification enables us to operate extensively across the nation, supporting a wide range of landmark projects and providing variety and career development opportunities for our workforce. 

Join the Civmec Team

At Civmec, we believe that building the right solutions in-house is key to meeting our evolving business needs and supporting sustainable growth. Joining our team means working directly on systems that have a real and immediate impact across the business.

This is a full-time position based in Henderson, WA, offering the opportunity to work within a collaborative and forward-thinking team supporting critical business operations.

As Cyber Security Assurance Engineer, you will provide technical assurance of systems and security controls, translating security requirements into implementable controls and maintaining governance and assurance artefacts to demonstrate their effectiveness.

The Role

  • Interpret ISM, Essential Eight, PSPF and DSPF into practical controls
  • Design and implement controls for PROTECTED and sensitive environments
  • Maintain mappings between components, controls, owners and evidence
  • Assess control design and effectiveness across identity and networks
  • Review architectures and system changes to identify security gaps
  • Develop and govern system security documentation and standards
  • Own and maintain SRMPs, security plans and risk registers
  • Collect and validate technical evidence for DISP and IRAP
  • Conduct technical security risk assessments and remediation processes
  • Track control deficiencies and report on risk and progress
  • Support vulnerability, patching, hardening and control monitoring
  • Assess third-party and supply chain systems within security boundaries

About You

To be successful in the role, you will possess the following:

  • Qualifications in IT, cyber security or infrastructure
  • 3-5 years in cyber security or assurance
  • Defence/Government security experience
  • Ability to translate requirements into actions
  • Enterprise infrastructure and security controls
  • Strong written communication and documentation
  • Effective stakeholder engagement skills
  • CISSP, CISM or equivalent (desirable but not essential)
  • CRISC or risk certification (desirable)
  • ISO 27001 Lead Auditor (desirable)
  • ISM, Essential Eight, DISP, IRAP knowledge (highly regarded)

Due to the Security Clearance required for this position, applicants must be an Australian Citizen and eligible to obtain and uphold a Baseline Security Clearance through the Australian Department of Defence.

 

Civmec + You

At Civmec, we offer an inclusive workplace built on family values, with a ‘Never Assume’ culture, sustained by our experienced and supportive management team. We believe our workforce is our greatest asset, and that’s why we provide an environment rich in career development opportunities to upskill and develop professionally. Our generous Reward and Recognition scheme recognises employees that go the extra mile. Our staff benefits scheme gives you access to accident and sickness insurance, and a range of travel, entertainment, vehicle and lifestyle discounts.   

How to Apply

Please click the “apply” link to start your application. We look forward to starting the pathway to your career with Civmec.

Alternatively, please call our Recruitment Team on (08) 6595 5888.
Civmec is an equal opportunity employer and encourages applications from Aboriginal and Torres Strait Islanders. Defence force experience is desirable, and veterans are encouraged to apply. We respectfully request no agency submissions.
Follow us on LinkedIn, Facebook and Instagram for news, updates and career opportunities!

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 67 matched
Cyber security frameworksDspfEssential eightIrapIsmsIso 27001 lead auditorPspfSecurity architecture designSecurity architecture reviewSecurity control auditSecurity control documentationSecurity control documentation standardsSecurity control effectiveness evaluationSecurity control effectiveness frameworksSecurity control effectiveness improvementSecurity control effectiveness improvement toolsSecurity control effectiveness lifecycle managementSecurity control effectiveness lifecycle management toolsSecurity control effectiveness metricsSecurity control effectiveness metrics toolsSecurity control effectiveness monitoringSecurity control effectiveness monitoring toolsSecurity control effectiveness reportingSecurity control effectiveness reporting toolsSecurity control effectiveness reviewSecurity control effectiveness review toolsSecurity control effectiveness testingSecurity control effectiveness testing toolsSecurity control effectiveness validationSecurity control effectiveness validation toolsSecurity control evidence collection frameworksSecurity control evidence collection toolsSecurity control evidence managementSecurity control gap analysisSecurity control gap analysis toolsSecurity control gap closureSecurity control implementationSecurity control implementation frameworksSecurity control improvementSecurity control lifecycle managementSecurity control lifecycle management toolsSecurity control mappingSecurity control monitoringSecurity control monitoring toolsSecurity control remediationSecurity control remediation planningSecurity control remediation toolsSecurity control reportingSecurity control testing and validationSecurity control validationSecurity control validation toolsSecurity controlsSecurity controls implementationSecurity documentationSecurity governanceSecurity hardeningSecurity incident responseSecurity patch managementSecurity risk assessmentSecurity standards and frameworksSecurity standards complianceStakeholder engagementTechnical evidence collectionTechnical security controlsThird-party security assessmentTradingVulnerability management

Licenses & certifications

0 of 5 matched
Baseline security clearanceCismCisspCriscIso 27001 lead auditor

Perks & benefits

0 of 3 matched
Accident and sickness insuranceCareer development opportunitiesTravel, entertainment, vehicle and lifestyle discounts

CIVMEC