Job description
Agency Department of Corporate and Digital Work unit ICT Services - Cyber NT, Cyber Risk and
Development Assurance
Job title Director, Cyber Risk and Assurance Designation Executive Contract Officer 1
Job type Full time Duration Fixed for up to 4 years
Remuneration package $233,112 Location All NT Regions
Position number 68260255 RTF 353921 Closing 25/08/2026
Contact officer Romi Peerzada on 08 8994 3844 or [email protected]
About the agency https://dcdd.nt.gov.au/
Apply online https://jobs.nt.gov.au/Home/JobDetails?rtfId=353921
APPLICATIONS MUST INCLUDE A ONE-PAGE SUMMARY ABOUT YOU, A DETAILED RESUME AND COPIES OF YOUR TERTIARY
QUALIFICATIONS.
Information for applicants – inclusion and diversity
The NTPS values diversity. The NTPS encourages people from all diversity groups to apply for vacancies and accommodates people with
disability by making reasonable workplace adjustments. If you require an adjustment for the recruitment process or job, please discuss this
with the contact officer. For more information about applying for this position and the merit process, go to the OCPE website.
Primary objective
Provide expert capability in cyber security governance, risk and assurance management, leading a team managing cyber security risk and
assurance across the NT Government’s technology environment.
Context statement
The Department of Corporate and Digital Development manages digital systems on behalf of NT Government agencies. The position
operates within the Cyber NT unit providing expert cyber security governance, risk and assurance services and leadership of the cyber
risk management program. The position has involvement in sensitive issues and out of hours work may be required.
Key duties and responsibilities
1. Lead and manage a cyber security risk and assurance function, systems and regulatory reporting, including working with internal and
external stakeholders and managing reporting to the Government CISO, governance committees and executives.
2. Oversee the cyber risk management program, developing and maintaining cyber security governance and risk management
frameworks, associated practices, tools and systems, including leading ISMS implementation.
3. Maintain the enterprise cyber risk and controls register and drive engagement with risk owners to review technology and cyber risk,
verify controls, collect evidence, advise risk treatments; and administer exemption and compliance reporting.
4. Deliver cyber security controls assurance services including internal assessments and management of external reviews and audits
against relevant laws, regulations, industry standards and cyber security policy and risk frameworks.
5. Provision of expert advice to inform ICT policies and standards, security risk management plans, contractual and procurement
documentation, supply chain cyber security risk assessments and regulatory compliance.
6. Prepare and present reporting on cyber risk and assurance for the Government CISO, cyber security committees, ICT governance, risk
and audit committees and client agencies to inform decision making on cyber risk management.
7. Maintain awareness of the internal and external cyber threat environment and legal, regulatory compliance and contractual obligations.
8. Operate as a senior leader within the Cyber NT unit and broader ICT Services division, supporting and guiding others and working
collaboratively across the Digital Services portfolio to ensure alignment with Digital activities and Agency initiatives and priorities.
Selection criteria
Essential
1. Demonstrated experience within a large organisation in cyber risk management and assurance, regulatory compliance and audit
processes, including undertaking technical controls and cyber risk assessments against industry-wide security standards and
frameworks such as ISO/IEC 27001, NIST CSF, PCI-DSS, ASD’s ISM, Australian Government’s PSPF, etc.
2. Knowledge of the Security of Critical Infrastructure Act and associated regulations, Cyber Security Act and Privacy Act and Notifiable
Data Breach Scheme; and demonstrated analytical capability to interpret and apply legislation and policy requirements.
3. Experience in applying policy and processes to incorporate cyber risk management in enterprise risk management, procurement,
contractual processes and ongoing vendor management and attestation.
4. Experience in developing strategic plans, frameworks, policies and procedures, reports and technical documentation such as security
risk management plans and system security plans in alignment with industry and regulatory standards.
5. Highly developed written communication skills with the ability to convey complex concepts and translate technical information
concisely for diverse audiences and develop a range of materials including executive briefings, reports, policies, guidelines and
procedures.
6. Highly developed leadership and interpersonal skills with demonstrated ability to present to executive audiences, manage and develop
teams, and build relationships, influence, negotiate and collaborate with internal and external stakeholders to direct and achieve
outcomes.
7. Tertiary qualification(s) in a relevant discipline combined with relevant senior executive experience, or an equivalent combination of
substantial relevant senior executive experience and education and training
8. Hold or have eligibility to obtain Negative Vetting 1 National Security Clearance.
Desirable
1. Relevant industry certifications such as CISM, CISSP, ISO/IEC 27001 Lead Implementer/Auditor.
Further information
The recommended applicant will be required to undergo a criminal history check prior to commencement. A criminal history will not
exclude an applicant from this position unless it is a relevant criminal history. When choosing to apply for this position, the applicant
should consider the full requirements of the position in aligning to their work experience and capabilities to this role. Please refer to the
Capability Framework.