Aris Zinc
Canberra,
This job was published 2 days ago
Category:
Seniority:
<ul> <li>Location - ACT</li> <li>Security Clearance - Australian Citizens with NV1 Clearance</li> <li>Length of Contract - 12 months</li> <li>Closing Date - 10th October 2025</li> </ul> <strong>Key Responsibilities:</strong><br> <ul> <li>Conduct comprehensive vulnerability assessments and penetration tests of ICT systems.</li> <li>Prepare and deliver plans, testing reports, and remediation recommendations.</li> <li>Identify, document, and assess system vulnerabilities, including software, operating systems, and physical components (locks, keys, keypads, etc.).</li> <li>Ensure all testing complies with the Australian Government Information Security Manual (ISM) and relevant standards.</li> <li>Maintain clear communication with stakeholders and provide early notification of critical vulnerabilities.</li> <li>Develop and implement risk mitigation and remediation plans.</li> <li>Support validation testing after remediation and produce final assurance documentation.</li> <li>Work collaboratively within the stakeholders.</li> </ul> <strong>Essential Qualification & Experience:</strong><br> <ul> <li>Personnel must be qualified and experienced vulnerability assessors and penetration testers.</li> <li>Must have knowledge of the specific technologies and systems in scope, particularly: - CyberAudit software - Red Hat Enterprise Linux operating systems - Physical CyberLock components (locks, keys, keypads, etc.)</li> <li>OSCP (Offensive Security Certified Professional)</li> <li>CREST Registered Penetration Tester</li> <li>CEH (Certified Ethical Hacker)</li> <li>CISSP or CISM (for senior cybersecurity professionals)</li> </ul> <strong>Additional Criteria:</strong><br> <ul> <li>DSS - 2.6 Systems and Software Engineering - System Security - L4</li> <li>SFIA Skill Code - Information security (SCTY)- L5</li> </ul>