Job Description
Remote is seeking a Senior Security Engineer Vulnerability Assessor to join the team at ASD. The Senior Security Engineer Vulnerability Assessor will identify, assess, and prioritise threat vulnerabilities through penetration testing to improve security architecture. Key responsibilities include assessing threat profiles, leading analytical processes to improve ASD ICT infrastructure integrity, evaluating security controls, and performing risk/impact analysis. The role also involves investigating attacks, optimising security processes, and providing technical security advice while contributing to systems design policies and standards. ( LH-07163)
Role Description
Key duties and responsibilities
- Assess and explain threat profiles of a variety of electronic devices, as relevant across the Australian Signals Directorate.
- Lead analytical processes to identify and recommend actions to maintain and improve the integrity of the Australian Signals Directorate ICT infrastructure.
- Evaluate and assist with the application and compliance of security controls and review information systems for actual or potential security vulnerabilities.
- Perform security risk and business impact analysis for complex information systems.
- Investigates suspected attacks and supports security incident management.
- Maintains and optimises operational security processes.
- Provide advice on implementing and managing physical, procedural and technical security encompassing both physical and digital assets.
- Adopt and adapt appropriate systems design methods, tools and techniques selecting appropriately from predictive (plan-driven) approaches or adaptive (iterative/agile) approaches, and ensure they are applied effectively.
- Review and make recommendations and assess and manage associated risks of others' systems designs to ensure selection of appropriate technology, efficient use of resources, and integration of multiple systems and technology.
- Contribute to development of systems design policies and standards and selection of architecture components
Essential criteria
- Compliance Monitoring and Controls Testing: Level 4 (CIISEC)
Is an experienced member of a team conducting compliance monitoring and/ or controls testing.
- Internal and Statutory Audit: Level 4 (CIISEC)
Conducts security audits under supervision as part of a team.
- Intrusion Detection and Analysis: Level 2 (CIISEC)
Can explain the basic principles involved in monitoring network and system activity for anomalous behaviour and how the results can be used. This might include experience of applying these principles in a training or academic environment, for example through participation in syndicate exercises, undertaking practical exercises, and/or passing a test or examination.
- Threat Intelligence, Assessment and Threat Modelling: Level 4 (CIISEC)
Undertakes routine threat intelligence/modelling tasks or threat assessments without close supervision. Undertakes complex threat intelligence tasks or threat assessments under supervision. Appropriate and relevant certifications include CREST Registered Threat Intelligence Analyst.