- Location
- Canberra
- Workplace
- Hybrid
- Type
- Full-time, Contract
- Department
- Legal
- Clearance
- Required
- Closing date
- Today
- Source
- CareersPage
Description
We are Fujitsu
We use technology to make happier lives. We are a global leader in technology and business solutions that transform organisations and the world around us. We have a long heritage of bringing innovation and expertise, continuously working to contribute to the growth of society and our customers.
About the role
- RFQ Opportunity
- 12 months Contract
- ACT Based
- Hybrid
- Employment Type: Full-Time Contract (40 hours per week)
- Security Clearance: Negative Vetting Level 2 (NV2) Mandatory
Overview
We are seeking a highly motivated Project Officer - Security & Compliance (PROF Level 4) to support cyber security, governance, risk, and compliance initiatives within a complex ICT environment.
This role is responsible for helping maintain the confidentiality, integrity, and availability of information systems and data while ensuring compliance with security policies, regulatory obligations, and industry best practices. Working closely with security and technical teams, you will contribute to security governance activities, compliance assurance, vulnerability management, incident response, and Authority to Operate (ATO) processes.
The successful candidate will have a strong understanding of cyber security frameworks, risk management, security operations, and stakeholder engagement.
Key Responsibilities
Security Governance & Compliance
- Assist in the development and maintenance of security documentation and compliance artefacts.
- Support Authority to Operate (ATO) activities and security accreditation requirements.
- Contribute to security governance, risk management, and compliance initiatives.
- Assist with audits, security assessments, and assurance activities.
- Interpret and apply security policies, standards, and regulatory requirements.
Security Operations & Technology
- Build, operate, and optimise security technologies including:
- Tenable.sc / Nessus
- Data Loss Prevention (DLP) solutions
- Endpoint Security platforms
- Web Proxy solutions
- Malware Analysis Sandboxes
- Onboard new hosts and systems into security monitoring platforms.
- Configure and maintain vulnerability assessments and scanning activities.
- Develop and maintain security policies, procedures, and technical documentation.
Vulnerability & Threat Management
- Conduct vulnerability assessments and support remediation activities.
- Analyse vulnerabilities, threats, and emerging security risks.
- Generate security reports and work with stakeholders to address identified risks.
- Update threat intelligence feeds, software versions, and security platform configurations.
Incident Response & Security Monitoring
- Support security incident investigation and response activities.
- Assist with file analysis and investigation of unusual user activities.
- Contribute to the development of SIEM monitoring rules and threat detection use cases.
- Support ongoing improvement of security monitoring capabilities.
Network & Data Protection
- Configure web proxy whitelisting and blacklisting rules.
- Implement and maintain DLP policies in alignment with organisational requirements.
- Assist in protecting sensitive information and reducing data loss risks.
Stakeholder Engagement
- Participate in security working groups and stakeholder forums.
- Prepare reports, risk assessments, briefings, and recommendations.
- Communicate security concepts to both technical and non-technical audiences.
- Promote security awareness and compliance across the organisation.
Essential Skills & Experience
Cyber Security Knowledge
- Strong understanding of cyber security principles, controls, and best practices.
- Knowledge of security frameworks and standards including:
- Australian Government Information Security Manual (ISM)
- Protective Security Policy Framework (PSPF)
- Essential Eight
- ISO 27001
- NIST Cybersecurity Framework
Governance, Risk & Compliance
- Experience supporting security governance, risk management, and compliance activities.
- Experience applying security policies, standards, and regulatory requirements.
- Experience supporting audits, assessments, accreditation, or assurance activities.
Technical Security Skills
- Knowledge of:
- Cloud Security
- Identity and Access Management (IAM)
- Network Security
- Vulnerability Management
- Security Monitoring and Incident Response
Analytical & Problem-Solving Skills
- Ability to identify and assess cyber security risks.
- Strong analytical and investigative capabilities.
- Ability to develop practical remediation and mitigation strategies.
- Strong attention to detail and risk-based decision making.
Communication & Stakeholder Management
- Excellent written and verbal communication skills.
- Ability to prepare technical and executive-level documentation.
- Ability to explain complex security concepts clearly.
- Strong stakeholder engagement and collaboration skills.
Highly Desirable Experience
Candidates with experience in any of the following will be highly regarded:
- Tanium
- Tenable Security Solutions
- Cisco ISE
- Cisco Security Products
- Microsoft Security Technologies
- Trellix
- Carbon Black
- Security Information and Event Management (SIEM) platforms
Authority to Operate (ATO) Experience
- Development of System Security Plans (SSPs)
- Development of System Security Plan Annexes (SSP-A)
- Security accreditation and assessment support
- Security documentation and compliance artefacts
Additional Security Knowledge
- Essential Eight implementation and compliance
- Information Security Manual (ISM) compliance activities
- Centre for Internet Security (CIS) Controls
- Security Technical Implementation Guides (STIGs)
Why Fujitsu?
We are an organization with a strong set of values and a history of respecting fairness and equality, whilst promoting diversity, equity and inclusion. We constantly push ourselves to do better and strive to bring together a diverse mix of perspectives and talents in an inclusive environment, where we encourage our people to bring their full selves to work. We call this Be Completely You.
- We put people first. We believe in the power of diversity to drive innovation and our Work180 accreditation, AWEI (Australian Workplace Equality Index) Gold Employer status and Rainbow Tick certification for LGBTI+ inclusion show that we value an inclusive culture.
- We offer tailored career paths across our global organization to support your professional and personal growth.
- Our customers trust us. We have an excellent reputation across the region and globally.
- Best in class reward and recognition programs flexible work, volunteering leave and more.
- We live our values of aspiration, trust and empathy, all day, every day.
As an inclusive employer, Fujitsu aims to recruit a diverse range of talents to help us achieve our purpose. In line with our diversity, equity and inclusion strategy, we welcome applications from women and gender diverse people; Aboriginal and Torres Strait Islander people; Māori and Pacific people; LGBTI+ people; people with a disability; culturally and linguistically diverse people; and veterans and emergency responders. Applicants who identify as transgender or gender diverse can contact [email protected] for a copy of our Frequently Asked Questions to assist with the recruitment journey. For all other general inquiries, please contact [email protected]
If you dont tick every box in this job description, please dont rule yourself out. Research suggests that women and other people in underrepresented groups tend to only apply if they meet every requirement. We focus on hiring people who value inclusion, collaboration, adaptability, courage, and integrity, rather than ticking boxes so if this resonates with you, then please apply. For more information, please email [email protected].
Search Firm Representatives Please Read Carefully
Fujitsu does not accept unsolicited assistance from search firms for employment opportunities. All CVs or resumes submitted by search firms to any employee at our company without a valid written agreement in place for this position will be considered the sole property of our company. No fee will be paid if a candidate is hired by Fujitsu due to an agency referral where no existing agreement is in place with the Fujitsu Talent Acquisition Team. Where agency agreements are in place, introductions must be through engagement by the Fujitsu Talent Acquisition Team.
For Security Cleared Roles - PLEASE NOTE:
Due to the inherent requirements of the role, candidates must be Australian Citizens and hold a minimum Baseline Australian Federal Government Security Clearance. As a consequence of these restrictions and requirements, applicants may be adversely impacted if they are not Australian citizens, are dual nationals, hold citizenship from proscribed countries or are not of Australian national origin. Please refer to Discrimination (Fujitsu Australia Limited) Exemption 2017 (No 1) Notifiable instrument NI2020-672 (ACT).