Job Description
Cybersecurity Certification Consultant
Australian citizenship required. Must have an active Negative Vetting Level 1 (or higher) security clearance.
Location: Australia-wide (Hybrid).
What to Submit
- A tailored resume in docx format (maximum four pages).
RFQ Details
- RFQ ID: 2026-175-Joint-LC4S-RFQ
- Agency: Department of Defence
- Closing Date: 18th Sep 2026
- Estimated Start Date: ASAP
- Initial Contract Duration: Until 31 March 2027
- Extension Term: Opportunity for extension
- Number of Extensions: Not specified
- Experience Level: L3
- Security Clearance: NV1
- Location of Work: No location restrictions within Australia; occasional travel may be required
- Working Arrangements: Minimum three days per week onsite; if Melbourne or Canberra based, part-time office attendance is expected
- Maximum Hours: Not specified
Job Details
Land Communications & Specialist Systems SPO is seeking a suitably qualified and experienced Cybersecurity Certification Consultant to work as an embedded member of the Land C4 Systems Branch. The role sits within CASG and supports the CA31 fleets, which sustain and enhance Land C4 systems at the operational and tactical level, including the Tactical Communications Network, Battlefield Telecommunications Network, Battlefield Management System and Deployable Information Environment Protected and Secret.
The successful candidate will work effectively in a complex environment, think critically, apply excellent problem-solving skills and manage competing priorities with a focus on mitigating risk. Services are to be delivered in accordance with relevant Australian and international standards, regulations, Defence requirements and industry best practice.
Key Duties and Responsibilities
- Provide System Assessment and Authorisation activities as directed by the CA31 Engineering Manager.
- Conduct system Assessment and Authorisation activities in accordance with the ASD Information Security Manual, Protective Security Policy Framework, Defence Security Policy Framework, and Cyber Security Assessment and Authorisation Charter, methodology, templates and guidance.
- Perform security assessments using Operational Effectiveness Reviews as the default approach, with Design Effectiveness Reviews where justified.
- Audit the effectiveness of system security controls implemented across CA31 capability systems.
- Develop Security Assessment Reports, ATO briefs, risk statements and recommended remediation actions.
- Identify, analyse, evaluate and escalate cyber security and business risks.
- Identify and assess vulnerabilities arising from security exceptions, software defects, and architecture or design weaknesses.
- Assess system security architecture and services using structured threat-modelling methodologies.
- Protect the confidentiality, integrity and availability of Defence information and systems.
- Review security documentation, policies and procedures for alignment with Defence and Australian Government requirements.
- Ensure system compliance with mandatory cyber security requirements.
- Support configuration governance, including Change Control Boards, and provide risks, mitigations and options for Executive Authority acceptance.
- Provide cyber security advice within the defined CA31 assessor scope.
- Help CA31 understand and mitigate cyber security risks affecting capability delivery and operations within the LC4 domain.
- Build and maintain effective relationships with applicable sustainment products, OEM, operational and security stakeholders.
Technical Skills
- Relevant qualifications, industry certification and/or professional experience suitable for eligibility to obtain DCIAB-CSAA endorsement as a Cyber Security Assessor, including CISSP, CISM, ISO 27001 Lead Auditor and IRAP accreditation.
- Strong understanding of ICT architectures, networks, platforms, cyber/security compliance and governance within the Defence environment.
- Demonstrated ability to lead security cyber audits, document outcomes and deliver reports.
- Understanding of modern networking, computers and operating systems.
- Comprehensive understanding of Defence systems, including C4 capabilities, is highly desired.
- Previous Defence, Army or CASG experience is highly desired.
- Experience in assessing and evaluating risk is highly desired.
- Understanding of the One Defence Capability System is required.
Selection Criteria
Essential
- Have an Australian Government security clearance of at least NV1.
- Ability to work on site for a minimum of 3 days a week
- Qualifications / experience as per above
Why choose Pinaka
We know the government ICT market and we keep things straightforward. We take time to understand your background, your goals and the type of role that suits you. We believe transparency is about more than rates and our margins are fair and always disclosed.
What you can expect from us...
- Fair, disclosed margins
- Clear communication at every stage
- Honest advice on fit and competitiveness
- Visibility on submissions and process status
- A professional and respectful experience
How you are paid...
You choose what's best for you.
- PAYG through Pinaka
- Third-party payroll
- Self-employed (own ABN)
- With a single, transparent and fixed margin, we ensure compliance to all state and payroll laws. So that is one less thing for you to worry about.
BYO CONTRACT
Already in a role but not happy with the setup?
Port in your contract to Pinaka for a simpler and more transparent experience. We also have some exciting limited time offers on top of the incredible margins we offer.
BETTER TOGETHER ™
Our referral program for people who introduce strong candidates to us.
Refer a friend - Earn $1/hr per successful referral as long as you both with us. Refer as many friends as you want; no caps.