Own AtO delivery in a complex, enterprise federal environmentLong Term Fed Gov Contract | Canberra Based | NV1 Required No Payroll Fees | 2 Pay Runs Per Week | Easy Online TimesheetsLead the Authorisation to Operate lifecycle for mission‑critical FedGov systems in a long‑term ACT based role
Your new company
We are seeking a Lead Cyber Security Analyst to play a critical role in safeguarding highly sensitive government information systems. This is a senior, hands‑on role responsible for leading the end‑to‑end Authorisation to Operate (AtO) lifecycle, working across complex ICT environments that support essential national outcomes. You will join their cyber and assurance function on an up to 12‑month initial contract, with the potential for up to two further 12‑month extensions.
This role is ideal for a cyber professional who enjoys operating at the intersection of risk, governance and delivery, and who can confidently translate technical security requirements into practical, business‑aligned outcomes. This position will be based in Canberra and requires candidates to be Australian citizens who can obtain Negative Vetting Level 1 (NV1) clearance. You'll be working in a mature, highly regulated ICT environment where strong cyber governance and risk management are essential to business continuity and trust.
Your new role
As a Lead Cyber Security Analyst (EL1 equivalent), you will take ownership of the end‑to‑end Authorisation to Operate (AtO) lifecycle, ensuring information systems remain compliant with government security frameworks and fit for purpose throughout their operational life. You will work closely with Authorising Officers, system owners, delivery leads and technical teams, acting as the trusted security advisor across complex ICT environments involving multiple service providers.
Key responsibilities include:
Leading system security authorisation activities in line with the Information Security Manual (ISM) and Protective Security Policy Framework (PSPF)Developing and maintaining critical security documentation, including security plans, SOPs and control artefactsConducting comprehensive cyber risk assessments across project and operational environmentsSupporting and maintaining systems post‑authorisation through audits, change impact assessments and ongoing assurance activitiesEstablishing and supporting processes for security incident reporting and management that protect AtO statusSupporting compliance against frameworks such as: ACSC ISMEssential EightISO/IEC 27001NIST Cyber Security FrameworkWhat you'll need to succeedMinimum 3+ years' professional experience in information security, cyber risk or governance rolesProven experience supporting or leading AtO or security accreditation activitiesStrong working knowledge of Australian Government security standards, particularly ISM and PSPFExperience conducting risk assessments and clearly articulating risks, controls and residual riskExposure to cloud security environments (desirable)The ability to explain technical security concepts in plain language to support informed decision‑makingBachelor's degree in Cyber Security, ICT or a related fieldCertifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or AuditorWhat you'll get in return
A long-term initial up to 12‑month contract with the potential for multiple extensionsExposure to enterprise‑scale cyber programs and senior stakeholdersThe opportunity to operate at a strategic EL1‑equivalent level, influencing security and risk decisionsA collaborative, outcomes‑driven environment where cyber assurance is valued and well‑supportedWhat you need to do now
If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.
If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion on your career.
Desired Skills and Experience
GRC, CYBER, \"ATO\", SSA, \"GRC ANALYST\", \"SECURITY ANALYST\", \"AUTHORITY TO OPERATE\", \"SYSTEM ACCREDITATION\", AUDIT, CISA, CISSP, \"GOVERNANCE RISK AND COMPLIANCE\"