Skip to main content
AfterDuty

Cyber Security Assurance Analyst

Kinetic Plc · Melbourne, Victoria

Type
Full-time
Posted
8 days ago

Overview

Your investigative discipline and attention to detail are directly applicable to vendor risk assessments and security control validation.

About this role

Cyber Security Assurance Analyst

  • Newly created GRC function
  • Join a growing cyber function with the opportunity to help shape assurance practices and security standards
  • Initial 12 month max-term contract - Melbourne location

Due to significant global growth, Kinetic are undertaking a large scale, multi stream program of work designed to transform our technology landscape, create simplified, consistent ways of working, and ensure our future growth plans are underpinned by seamless technology products and processes.

Part of this transformation program is a major cyber security uplift across the Kinetic business. As the Cyber Security Assurance Analyst, you'll ensure security is designed into our applications and vendor relationships from the outset, rather than added on afterwards. Reporting directly to the Information Security Manager, you'll define security requirements during market scans and procurement, negotiate them into vendor contracts, and confirm they carry through design and implementation. You'll also build and maintain the assurance register that evidences our security control posture across the application landscape, supporting Kinetic's ISO 27001 certification and governance audit obligations.

What You Will Do

  • You’ll work closely with the Information Security Manager to:
  • Define and maintain security requirements for technology procurement, projects and solution delivery.
  • Conduct cyber assurance assessments of vendors, suppliers and proposed technology solutions.
  • Review and negotiate security requirements within commercial and technology contracts.
  • Partner with Architecture, Project and Procurement teams to embed security throughout delivery lifecycles.
  • Validate security controls and manage remediation activities prior to production deployment.
  • Own and maintain the Cyber Security Assurance Register across Kinetic's application landscape.
  • Lead third-party security assurance and risk assessment activities.
  • Support ISO 27001 certification, governance reviews and ongoing compliance reporting.

What You Will Need

  • Experience reviewing and negotiating security clauses and schedules in commercial and vendor contracts.
  • Background in vendor and third-party risk assessment (TPRM), including gap assessment against security requirements.
  • Working knowledge of ISO 27001 Annex A controls and the evidence required to demonstrate them, along with an understanding of the Essential 8.
  • Comfortable reading solution architecture and design documentation and translating it into control requirements.
  • Certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM or CRISC are highly recommended.
  • Experience with GRC or register tooling (such as Jira, ServiceNow GRC or Archer) and strong analytical skills and attention to detail.
  • Excellent communication and interpersonal skills, with the confidence to negotiate directly with vendors, Legal and Procurement.
  • Most importantly, our values resonate with you – Passion, Integrity, Respect, Authenticity, Humility.

About us

At Kinetic, we don't just move people - we're creating the positive change our planet needs. As a leader in sustainable transport, we're committed to creating cleaner, safer, and greener environments for generations to come.

Our size and scale give our people real opportunities to learn, grow, and progress in their careers. Calm, positive and respectful team players thrive here. Our people embrace change and are encouraged to stretch their comfort zone while making a difference. We challenge each other to be our best.

We're driven by respect, diversity and genuine connection. From networking groups to community partnerships and volunteering, our camaraderie naturally brings people together. Our energy and dedication keep communities moving and our people growing.

How to apply

Kinetic is proud to be an Equal Opportunity Employer and our people represent the community which we service. We invite all suitably qualified applicants to apply, including First Nations People, and people from diverse social, cultural and gender backgrounds.

If you're interested in this rewarding role with Kinetic then click the 'Apply' button now!

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Melbourne

Why this fits a police background

  • Risk & threat assessment
  • Working to legislation & regulation

More cyber security & digital forensics jobs for ex-police

  • Control Manager Vulnerability Management

    Commonwealth Bank · Melbourne

    Full-time

    Control Manager, Vulnerability Management Do you thrive at the intersection of cyber security, technology, and stakeholder engagement? Help drive vulnerability remediation, shape governance practices, and make a real impact across the organisation.

    Posted 5 days ago

  • Information Security & Risk Analyst

    The Royal Australian College of General Practitioners (RACGP) · Melbourne

    Full-time

    Your incident command and threat assessment experience maps directly to security risk and resilience work.

    Posted 7 days ago

  • Contract

    Your experience with evidence handling and regulatory compliance maps directly to security assurance and vendor risk assessment.

    Posted 7 days ago

  • Cloud Security Engineer

    IFM Investors · Melbourne

    Full-time

    About Us JOB DESCRIPTION IFM Investors is a global asset manager, founded and owned by pension funds, with capabilities in infrastructure equity and debt, private equity, private credit, real estate and listed equities.

    Posted 12 days ago