Back to jobs

pae
Actively hiring
Cyber Security Specialist
- Workplace
- On-site
- Commitment
- Full-time
- Posted
Location
Brisbane, Australia
The role is a Cyber Security Specialist position supporting Uncrewed Aircraft Systems within a UAS Program Office. The successful candidate works as a Systems Engineer providing engineering services to support delivery, acceptance, test and evaluation, and sustainment of small UAS. Key duties include assessing design disclosure documentation for compliance, developing and maintaining accreditation documentation and risk assessments, evaluating security controls against frameworks such as ISM and Essential Eight, and conducting security gap analysis and assurance activities. The role involves communicating technical findings in plain language to contractors, Defence engineering, project managers and military leadership.
Responsibilities
- Perform a range of system engineering activities supporting the introduction into service of SUAS including the assessment of supplied design disclosure documentation to determine compliance with requirements.
- Develop, verify, review, update and maintain accreditation documentation and compliance artefacts, including risk assessments and reports.
- Effectively gather information from contractors and communicate technical finding in plain language to non-technical stakeholders, Defence engineering, project managers, and military leadership.
- Evaluate the effectiveness of security controls against the approved security frameworks such as ISM, Essential Eight Maturity Model etc. Potentially mapping against other frameworks where necessary such as NIST SP 800-53 and other frameworks and standards.
- Conduct security, gap analysis, compliance assessments, and assurance activities, providing detailed reporting and supporting documentation.
Requirements
- Tertiary qualification in either Engineering, Cyber Security, Information Technology, or equivalent extensive industry experience.
- Excellent interpersonal, written, and verbal communication skills, with the ability to engage effectively with technical and non-technical stakeholders.
- Ability to simplify complex technical information and communicate findings clearly to a range of audiences.
Nice to have
- Network security (firewalls, IDS/IPS, segmentation)
- System hardening (Windows, Linux, embedded platforms)
- Secure software development lifecycle (SSDLC)
- Cryptography and key management
- Incident detection and response
- Familiarity with cyber security frameworks such as ISM, NIST 800-53, STIGs etc