The Organisation The Australian Security Intelligence Organisation (ASIO) protects Australia and Australians from threats to their security. In a complex, challenging and changing security environment, our success is built on the imagination and intelligence of our team. ASIO's people are ordinary Australians but they do extraordinary things - they are our most important asset. To be successful in our mission, we need talented people who are highly capable, dedicated, adaptable and resilient. We seek to reflect the diversity of the community we protect. ASIO is committed to fostering a diverse and inclusive environment, where all staff are valued and respected. We welcome applications from all eligible candidates, irrespective of gender, sexual orientation, ethnicity, religious affiliation, age or disability. Aboriginal and Torres Strait Islander Peoples are encouraged to apply. We are secretive about what we do, not what we value. The opportunity ASIO employs a diverse range of cyber security specialists across offensive and defensive functions. As a cyber security specialist, you could be involved in the protection of ASIO from insider and cyber threats, or directly contribute to operational activities. At ASIO, you have the opportunity to develop, expand and apply your skills across the full breadth of its cyber security functions. We are seeking Cyber Security Leaders to fill vacancies in our Cyber Security Assurance team. These roles are instrumental in safeguarding ASIO's sensitive information and systems by providing the technical foundations that enable the effective and secure operation of our functions, thereby ensuring the integrity, confidentiality, and availability of our critical assets. These positions may attract an additional technical skills allowance. A merit pool may be created to fill future vacancies which have the same or similar requirements to this position. This merit pool will be valid for up to 18 months. The key duties of the position include Role responsibilities As a Cyber Security Technologist, Cyber Security Assurance (SITEC), you will: • Drive the integration of cutting-edge security principles into the design and architecture of emerging systems, aligning with industry best practices and community standards. • Foster a culture of security by design, collaborating with project teams to develop secure systems and providing expert security guidance through comprehensive documentation and risk assessments. • Champion compliance and governance, leading assessments of ASIO's systems against Australian Government policies, standards, and best practices, including the Protective Security Policy Framework (PSPF) and Information Security Manual (ISM). • Develop and execute strategic threat modelling and risk management initiatives, facilitating workshops with stakeholders to identify, assess, and prioritise security threats and risks, and providing strategic guidance on mitigation strategies. • Shape the future of ASIO's IT security posture by developing and maintaining policies that address emerging threats and opportunities. • Enhance the security awareness and capability of ASIO staff through targeted assessments, interactive awareness campaigns, and curated training programs. • Stay at the forefront of the rapidly evolving cyber security landscape, maintaining expertise in the latest threats, technologies, and developments to inform ASIO's cyber security strategy. As Assistant Director, Cyber Security Assurance (AEE1), you will: • Lead and oversee a team of Cyber Security Assessors to ensure ASIO systems adhere to Australian Government policies, standards, and best practices, driving a culture of compliance and continuous improvement. • Orchestrate the planning, scheduling, and coordination of assessment and remediation activities, ensuring efficient and effective execution. • Develop and implement strategic security uplift initiatives across the organisation, aligning with business objectives and risk management frameworks. • Create, maintain, and review relevant documentation, procedures, and policies, ensuring they remain current and effective in addressing emerging cyber threats. • Stay abreast of the latest cyber security threats, technologies, and developments, applying this knowledge to inform and enhance the organisation's cyber security posture.