Position summary
The IRAP Consultant provides expert advice and assurance to ensure that clients’ systems and environments hosting Australian Government classified data meet the strict requirements of the PSPF and ISM. They play an important role in helping organisations mitigate cyber security threats, enhance their security posture, and develop robust security strategies. Additionally, as a senior mentor, they actively develop and support associate consultants on their pathway to becoming endorsed IRAP assessors. This role can be performed anywhere in Australia.
Responsibilities:
- Conduct independent security assessments in accordance with the ASD’s PSPF, ISM, and ACSC IRAP process
- Oversee the delivery of IRAP projects by establishing clear goals and engaging key stakeholders to successfully fulfill contract deliverables
- Work with clients to understand the IRAP process and ensure a common understanding of the pathway for systems to achieve Approval to Operate (ATO) status
- Mentor, support, and provide guidance to consultants, fostering a collaborative and inclusive work environment that ensures their professional growth in cyber security and builds a pathway to become IRAP assessors
- Provide expert advice and guidance to clients on emerging cyber security threats, regulatory compliance, and industry best practices
- Contribute technical and strategic expertise to the development of client proposals, presentations, and market-facing materials
- Stay informed of the latest developments in information security, risk management, compliance requirements, and emerging threat landscapes
Knowledge, skills and experience:
- An approved Information Security Registered Assessors Program (IRAP) Assessor
- Minimum of 5 - 10 years of experience in cyber security, with a strong background in consulting, audit, assurance, and strategic advisory roles
- Strong knowledge of Australian Government Security Frameworks, international cyber security frameworks, industry standards, and best practices (e.g. PSPF, ISM, Essential Eight, SoCI, NIST, ISO 27001 and CMMC)
- Proven track record in delivering successful cyber security assurance projects and driving client satisfaction
- Experience supporting and leading a team of cyber security professionals
- Excellent communication, negotiation, and presentation skills, with the ability to effectively articulate complex cyber security concepts to both technical and non-technical stakeholders
- Current NV1 clearance or higher
- Relevant tertiary qualifications and/or certifications such as CISSP, CISM, CRISC, ISO 27001, or equivalent (highly desirable)
Please visit https://willyama.com.au/ for more information