Classification: Parliamentary Executive Level 1
Branch: Cyber Security
Section: Cyber Security Operations
Immediate supervisor: Director, Cyber Security Operations
Duty Statement
Under limited/general direction undertake duties in accordance with the agreed standards for the specified classification. The duties will include, but are not limited to, the following:
1. Lead and manage the day-to-day operations of the Cyber Hunt and Threat Emulation function, including work planning, prioritisation, quality assurance, staff guidance and delivery of agreed cyber security outcomes.
2. Plan, scope and deliver cyber hunt, penetration testing, red team, threat emulation and other technical security assurance activities across networks, applications, cloud services, end-user environments and enterprise platforms.
3. Provide expert technical advice to stakeholders on cyber risk, vulnerabilities, threat actor tactics, security control weaknesses and practical remediation or mitigation options.
4. Analyse threat intelligence, vulnerability reporting, incident information and technical telemetry to identify exposure, prioritise activity and support informed cyber security decision-making.
5. Prepare clear, evidence-based technical reports, briefs and recommendations that communicate findings, risks, business impact and remediation priorities to technical and non-technical audiences.
6. Contribute to the uplift of Cyber Hunt and Threat Emulation services by developing frameworks, methodologies, procedures, tooling, reporting practices and capability improvement initiatives aligned to departmental cyber security objectives.
Selection Criteria
1. Demonstrated ability to lead and manage a technical cyber security function, including planning work, setting priorities, supporting staff, assuring quality and delivering outcomes in a complex operating environment.
2. Demonstrated experience planning, scoping and conducting penetration testing, cyber hunt, red team, threat emulation or similar technical security assurance activities across enterprise technology environments.
3. Strong technical knowledge of common vulnerability classes, exploitation methods, operating systems, networks, web applications, cloud services, security controls and the tools and methodologies used to assess them.
4. Ability to analyse threat intelligence, vulnerability information, technical findings and operational context to assess risk, prioritise activity and provide practical remediation or mitigation advice.
5. Well-developed written and verbal communication skills, including the ability to prepare clear technical reports and explain complex cyber security risks, findings and recommendations to technical and non-technical stakeholders.
6. Eligible qualifications and/or other technical requirements: minimum five years’ relevant experience in cyber security or a related discipline; relevant certifications such as GPEN, GWAPT, OSCP, OSWE, OSEP or equivalent are desirable; tertiary qualifications in information technology, computer science, cyber security or a related discipline are desirable; experience in Microsoft Azure, Microsoft 365, hybrid cloud environments, scripting, red team activities, physical security assessment or social engineering is desirable.
Employees of DPS are required to be able, and to be seen to be able, to provide professional advice and services to all Senators and Members without favour or prejudice.