Cyber Security Assurance Engineer
The Company
Civmec is an Australian-owned, integrated, multidisciplinary heavy engineering and construction services provider to the energy, resources, infrastructure, marine and defence sectors. With a pipeline of more than $1 billion in current and future projects, our diversification enables us to operate extensively across the nation, supporting a wide range of landmark projects and providing variety and career development opportunities for our workforce.
Join the Civmec Team
This is a full-time position based in Henderson, WA, offering the opportunity to work within a collaborative and forward-thinking team supporting critical business operations.
As Cyber Security Assurance Engineer, you will provide technical assurance of systems and security controls, translating security requirements into implementable controls and maintaining governance and assurance artefacts to demonstrate their effectiveness.
The Role
- Interpret ISM, Essential Eight, PSPF and DSPF into practical controls
- Design and implement controls for PROTECTED and sensitive environments
- Maintain mappings between components, controls, owners and evidence
- Assess control design and effectiveness across identity and networks
- Review architectures and system changes to identify security gaps
- Develop and govern system security documentation and standards
- Own and maintain SRMPs, security plans and risk registers
- Collect and validate technical evidence for DISP and IRAP
- Conduct technical security risk assessments and remediation processes
- Track control deficiencies and report on risk and progress
- Support vulnerability, patching, hardening and control monitoring
- Assess third-party and supply chain systems within security boundaries
About You
To be successful in the role, you will possess the following:
- Qualifications in IT, cyber security or infrastructure
- 3-5 years in cyber security or assurance
- Defence/Government security experience
- Ability to translate requirements into actions
- Enterprise infrastructure and security controls
- Strong written communication and documentation
- Effective stakeholder engagement skills
- CISSP, CISM or equivalent (desirable but not essential)
- CRISC or risk certification (desirable)
- ISO 27001 Lead Auditor (desirable)
- ISM, Essential Eight, DISP, IRAP knowledge (highly regarded)
Due to the Security Clearance required for this position, applicants must be an Australian Citizen and eligible to obtain and uphold a Baseline Security Clearance through the Australian Department of Defence.
Civmec + You
At Civmec, we offer an inclusive workplace built on family values, with a ‘Never Assume’ culture, sustained by our experienced and supportive management team. We believe our workforce is our greatest asset, and that’s why we provide an environment rich in career development opportunities to upskill and develop professionally. Our generous Reward and Recognition scheme recognises employees that go the extra mile. Our staff benefits scheme gives you access to accident and sickness insurance, and a range of travel, entertainment, vehicle and lifestyle discounts.
How to Apply
Please click the “apply” link to start your application. We look forward to starting the pathway to your career with Civmec.
Alternatively, please call our Recruitment Team on (08) 6595 5888.
Civmec is an equal opportunity employer and encourages applications from Aboriginal and Torres Strait Islanders. Defence force experience is desirable, and veterans are encouraged to apply. We respectfully request no agency submissions.
Follow us on LinkedIn, Facebook and Instagram for news, updates and career opportunities!