Cyber Security Assurance Engineer
Civmec Construction & Engineering · Corporate Office, Henderson, WA, AU · Australia · On-site
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
The Company
Civmec is an Australian-owned, integrated, multidisciplinary heavy engineering and construction services provider to the energy, resources, infrastructure, marine and defence sectors. With a pipeline of more than $1 billion in current and future projects, our diversification enables us to operate extensively across the nation, supporting a wide range of landmark projects and providing variety and career development opportunities for our workforce.
Join the Civmec Team
At Civmec, we believe that building the right solutions in-house is key to meeting our evolving business needs and supporting sustainable growth. Joining our team means working directly on systems that have a real and immediate impact across the business.
This is a full-time position based in Henderson, WA, offering the opportunity to work within a collaborative and forward-thinking team supporting critical business operations.
As Cyber Security Assurance Engineer, you will provide technical assurance of systems and security controls, translating security requirements into implementable controls and maintaining governance and assurance artefacts to demonstrate their effectiveness.
The Role
Interpret ISM, Essential Eight, PSPF and DSPF into practical controls
Design and implement controls for PROTECTED and sensitive environments
Maintain mappings between components, controls, owners and evidence
Assess control design and effectiveness across identity and networks
Review architectures and system changes to identify security gaps
Develop and govern system security documentation and standards
Own and maintain SRMPs, security plans and risk registers
Collect and validate technical evidence for DISP and IRAP
Conduct technical security risk assessments and remediation processes
Track control deficiencies and report on risk and progress
Support vulnerability, patching, hardening and control monitoring
Assess third-party and supply chain systems within security boundaries
About You
To be successful in the role, you will possess the following:
Qualifications in IT, cyber security or infrastructure
3-5 years in cyber security or assurance
Defence/Government security experience
Ability to translate requirements into actions
Enterprise infrastructure and security controls
Strong written communication and documentation
Effective stakeholder engagement skills
CISSP, CISM or equivalent (desirable but not essential)
CRISC or risk certification (desirable)
ISO 27001 Lead Auditor (desirable)
ISM, Essential Eight, DISP, IRAP knowledge (highly regarded)
Due to the Security Clearance required for this position, applicants must be an Australian Citizen and eligible to obtain and uphold a Baseline Security Clearance through the Australian Department of Defence.
Civmec + You
At Civmec, we offer an inclusive workplace built on family values, with a ‘Never Assume’ culture, sustained by our…