Security Lead
Your New RoleWorking on a Federal Government project, the Governance, Risk and Compliance position is focused on the delivery of secure, compliant and accredited Health Knowledge management Systems for JP2060 Phase 4. Specifically, the role will support the delivery of a complex system of systems for eHealth data hosted on cloud environments. Tasks include:Engagement with key stakeholders, including internal project management, Assessment Authority representatives, security service providers, project subcontractors and vendors, other internal IT security personnel and business owners.Lead a small team of GRC specialists ensuring that all work is completed according to the project plan.Tailor and deliver security controls, artefacts, risk assessments, and security testing.Provide advice on corporate policies and procedures required to operate the system and draft these documents.Provide basic security configuration and monitoring for the project and educate administrators on their responsibilities to maintain security compliance.Provide advice on secure software development practices.Consideration of and alignment with project schedules such that the assessment and authorisation effort support the business requirement to operate the subject system(s).Identification, validation and advocacy for security requirements (functional or non-functional) and dependencies associated with system delivery, transition into service or ongoing sustainment.Development of an Authorisation Plan detailing the elements above with the necessary activities, artefacts and stakeholder contributions required to complete the certification and accreditation process for assigned projects.Ownership of the Authorisation Plan with reporting as required by the business, project, Assessment Authority or other interested stakeholders.Handover all completed artefacts to operational groups for ongoing sustainment of the authorised system.