Cyber Security Consultant

Harvey Norman · Homebush West NSW 2140 · Full time
Posted today

Cyber Security Consultant

Harvey Norman
Graduates
~$100k - $130k(Estimated)
Harvey Norman Logo
KEY POINTS WE FOUND
  • Work closely with security leaders and project teams to embed security-by-design principles.
  • Conduct security assessments and manage identified risks through to remediation.
  • Develop and communicate security requirements and assurance guidance.

  • Opportunities to make discounted purchases on a great range of products.
  • Access to Udemy an online training platform with over 5,500 courses.
  • Experience working within a diverse, unique, and successful global organisation. 

As one of Australia’s largest retailers of lifestyle products, with more than 300 complexes worldwide, Harvey Norman® has been a part of almost every Australian’s shopping experience. Whether getting the latest electronic gadgets, or furnishing your first home, Harvey Norman® is the place where you can shop with confidence.  

About the role 

Reporting to the Cyber Security Assurance Manager and based onsite at the Silverwater Corporate Office, you will work closely with security leaders, project teams, solution architects, business stakeholders and vendors to embed security-by-design principles across business and technology initiatives. Acting as a trusted security advisor, you will assess proposed solutions, identify security risks and recommend practical controls that support secure business outcomes.

This role will involve conducting security and third-party risk assessments, reviewing solution designs, coordinating security testing and managing identified risks through to remediation or formal acceptance. You will also contribute to improving the organisation’s information security assurance frameworks, processes and standards.

You will

  • Conduct Information Security Assurance reviews across business and technology initiatives, ensuring security-by-design principles are embedded throughout the project lifecycle from initiation through to implementation and closure.
  • Develop, maintain and communicate security requirements, assessment criteria, standards and assurance guidance to support the consistent application of security controls across projects and third-party engagements.
  • Partner with solution architects, project teams, business stakeholders and vendors to identify security risks, assess potential business impact and recommend pragmatic security controls and risk treatment options.
  • Perform Third Party Risk Assessments (TPRA) of vendors, products and services, including the review of security questionnaires, certifications, audit reports and supporting evidence to support informed risk-based decision-making.
  • Review solution architectures, designs, integrations, data flows and technology implementations to ensure alignment with organisational security requirements, standards and industry best practices.
  • Coordinate and perform security assessment activities including vulnerability assessments, security configuration reviews, web application security testing, external penetration testing engagements etc.
  • Review security assessment findings and work with project teams, vendors and stakeholders to ensure identified vulnerabilities, weaknesses and security risks are appropriately remediated or formally accepted.
  • Perform Information Security Risk Assessments (ISRA) for projects, technology implementations and business initiatives in accordance with Harvey Norman's risk management framework.
  • Document, track, monitor and escalate identified security risks through established governance processes, ensuring remediation activities, mitigation plans and risk acceptance decisions are managed through to closure.
  • Contribute to the continuous improvement and maturity of the Information Security Assurance function through the adoption of industry best practices and enhancement of assurance methodologies, templates and processes.

About you

You are a proactive cyber security professional who can balance security requirements with business needs and provide practical, risk-based advice to stakeholders. With strong analytical skills, sound judgement and attention to detail, you take a risk-based approach and remain current with emerging cyber threats, technologies and industry practices.

You will have

  • At least 5 years’ experience in cyber security, information security assurance, risk management or a related area.
  • Experience reviewing solution architectures, technology implementations, integrations and data flows.
  • Experience conducting information security and third-party risk assessments.
  • Exposure to vulnerability assessments, security reviews and penetration testing activities.
  • Sound knowledge of security frameworks and practices such as ISO 27001, NIST Cybersecurity Framework, OWASP, Identity and Access management, Zero Trust etc..
  • An understanding of security principles across cloud, infrastructure, networks, applications and integrations.
  • Strong stakeholder engagement, communication and influencing skills.
  • The ability to manage multiple projects and competing priorities in a fast-paced environment.

Qualification:

  • Degree qualification in Information Technology, Computer Science, Cyber Security or a related discipline, or equivalent industry experience.
  • Industry-recognised Information Security certifications such as CISSP, CISM, CRISC, CCSP or equivalent certifications (preferred).
  • Relevant security architecture, cloud security, risk management or security assurance certifications will be highly regarded.

This opportunity will provide: 

  • Salary packaging and novated leasing options for eligible employees.
  • Company paid parental leave for eligible employees.
  • Access to Udemy an online training platform with over 5,500 courses.
  • Professional development and career progression.
  • Experience working with an Iconic Australian Brand with global success in NZ, Asia, and Europe.
  • A supportive team environment that celebrates diversity and promotes a healthy work and family life balance. 
  • Opportunities to make discounted purchases on a great range of products and services.

Have we got your interest?  

Apply now to be considered to join our dedicated team.  

Please note that only people with the right to work in Australia should apply for this position.  

Recruitment Agencies – thank you for thinking of us, however we do endeavour to fill our opportunities through direct channels wherever possible. If we find that we do need agency assistance, we’ll be in touch.  

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 18 matched
Analytical skillsAttention to detailCyber securityInformation securityProblem solvingSecurity architecture reviewSecurity assessmentSecurity controls implementationSecurity policy developmentSecurity standards and frameworksSecurity testingStakeholder managementTeamworkThird party risk assessmentTime managementTradingVendor security assessmentVulnerability assessment

Licenses & certifications

0 of 5 matched
Certified ethical hacker (ceh)Certified information security manager (cism)Certified information systems security professional (cissp)Comptia security+Iso/iec 27001 lead implementer

Perks & benefits

0 of 2 matched
Access to udemy online training platformDiscounted purchases on a great range of products

Harvey Norman

Harvey Norman Logo

Harvey Norman supports the following values and diversity groups:

Cyber Security Consultant | Harvey Norman | The Shout