ORGANISATION
Join Lifeline Australia and you will be helping to support the delivery of critical services ensuring that “no person in Australia has to face their darkest moments alone.”
Lifeline Australia is a national suicide prevention charity providing all Australians experiencing emotional distress with access to 24-hour crisis support and suicide prevention services. They are committed to empowering Australians to be suicide-safe through connection, compassion and hope. This is achieved through a partnership of over 10,000 committed volunteers and their member centres in communities across the nation.
Lifeline Australia Ltd (LLA) is located in Sydney, with small teams of dedicated staff employed to lead funding and corporate relations activities, and to provide the design, technical infrastructure and governance of services across Lifeline’s member network. LLA recently embarked on an exciting transformation journey, guided by an ambitious strategic plan.
The 2024-2027 Strategic Plan will see enhancements across services, technology and workforce to bring about better outcomes and a more accessible and flexible support system for help-seekers.
THE ROLE
We are seeking a practical, hands-on Cyber Security Analyst who has real-world experience securing enterprise environments and delivering cybersecurity outcomes. This is not a governance-only or policy-writing role. We are looking for someone who has personally assessed systems, identified risks, implemented controls, worked with vendors, and driven remediation activities. The successful candidate will support the Cybersecurity Uplift Program, improve alignment with ISO 27001:2022, increase Essential Eight maturity, and bring business-managed and Shadow IT platforms into formal security governance.
This role suits someone who enjoys rolling up their sleeves and getting things done. We are not looking for a compliance-only resource. We want someone who can assess, advise, implement, and deliver tangible security outcomes for the organisation.
This is a 12-month contract, working full-time hours.
RESPONSIBILITIES
- Conduct security assessments of business applications, cloud platforms, SaaS solutions, and third-party suppliers.
- Identify security risks, control gaps, and remediation actions across technology platforms.
- Establish, maintain, and test cyber incident response procedures through tabletop exercises, simulations, and post-incident reviews to improve organisational preparedness and response capability.
- Lead the onboarding of Shadow IT and business-managed systems into formal security governance and support processes.
- Review new technology solutions and integrations to ensure compliance with organisational security requirements.
- Support the maintenance and continual improvement of the Information Security Management System (ISMS).
- Gather and maintain evidence required for ISO 27001:2022 audits and compliance activities.
- Support Essential Eight uplift initiatives and remediation activities.
- Contribute to security awareness and education programs.
- Prepare risk assessments, security reports, and recommendations for management.
ABOUT YOU
Essential Skills and Experience
- Minimum 5 years' experience in a Cyber Security Analyst, Security Consultant, or similar hands-on security role.
- Demonstrated experience conducting security assessments and risk reviews.
- Proven experience implementing security improvements, not just producing reports and recommendations.
- Strong knowledge of ISO/IEC 27001:2022 and practical experience implementing and maintaining security controls.
- Experience working with the Australian Cyber Security Centre (ACSC) Essential Eight framework.
- Experience assessing and onboarding Shadow IT, SaaS platforms, and business-managed applications into formal governance processes.
- Experience conducting supplier security assessments and third-party risk reviews.
- Experience supporting audit and compliance activities.
- Strong stakeholder engagement and communication skills.
- Ability to work independently and drive outcomes with minimal supervision.
Desirable Experience
- Experience within a not-for-profit, healthcare, or regulated environment.
- Experience with Microsoft Defender, Microsoft Sentinel, vulnerability management platforms, and security monitoring tools.
- Experience reviewing Salesforce, cloud-hosted platforms, integrations, and externally managed applications.
- Knowledge of privacy legislation, data protection requirements, and supplier assurance frameworks.
- Experience supporting ISO 27001 audits or certification activities.
Personal Attributes
- Hands-on and action-oriented.
- Comfortable challenging vendors and stakeholders when security risks are identified.
- Strong problem-solving and analytical skills.
- Pragmatic approach to balancing risk and business requirements.
- Curious, proactive, and continuously looking for improvement opportunities.
- Able to build strong working relationships across the organisation.
WHAT SUCCESS LOOKS LIKE
Within the 12 month contract, the successful candidate will:
- Complete security assessments across key business and technology platforms.
- Establish and test cyber incident response procedures through exercises and simulations.
- Successfully onboard Shadow IT platforms into formal governance and support processes.
- Support and improve compliance with ISO 27001:2022 requirements.
- Improve Essential Eight maturity across the organisation.
- Strengthen supplier security assurance processes.
- Reduce identified cybersecurity risks through practical remediation and control improvements.
- Contribute to a stronger, more resilient security posture across the organisation.
CULTURE
The team are passionate, supportive and hardworking. They are very driven to reach their goals, so that they can continue to grow and deliver critical support to all Australians at a time when the importance of mental health has never been so prevalent.
EMPLOYEE BENEFITS PACKAGE
- Salary Packaging – being a not-for-profit organisation allows us to offer our employees access to some amazing tax savings through salary packaging
- Paid Primary Carer Parental Leave – (14 weeks at full pay or 28 weeks at half pay)
- Flexible working – we provide flexibility and support to all employees and encourage work-life balance
- Employee Assistance Program – access to free counselling sessions for you and your family
- Beautiful office facilities in central location – including shower facilities (Head Office roles only, delete if not required)
HOW TO APPLY
To apply, please select “Apply Now” and follow the prompts to submit your expression of interest.