About this role
Did you know?
The mission of the Australian Federal Police is to provide dynamic and effective law enforcement to the people of Australia. It provides policing throughout Australia in relation to the prevention and detection of crimes against the Commonwealth, its laws and integrity, and community police services to the Community of the ACT.
Working for the AFP provides you with a diverse and rewarding career. Whether you immerse yourself in a position on the frontline, or provide critical operational or professional support, the work you do makes a big impact on the people of Australia.
We’re committed to looking after you, with some of the best benefits and conditions in the industry – including (but not limited to):
- Six weeks (30 days) of paid annual leave per year + additional paid Christmas stand down
- 4 extra days of mandatory rest leave per year
- 18 days of paid personal leave per year
- Generous superannuation of 15.4%
- 18 weeks paid Parental Leave for Primary Caregiver (and 14 weeks for Secondary Caregiver) + additional unpaid leave entitlements for up until 24 months from the child’s date of birth or placement
- Generous salaries and incremental salary progression governed by the AFP Enterprise Agreement
- Flexible and hybrid working arrangements that support work-life balance
- Health & wellbeing services – with a focus on early intervention, education and prevention
- Access to ongoing training and professional development opportunities
What is the role?
The Cyber Security & Risk branch, part of The Technology Operations Command (TOC) is a key enabling Command that provides technological solutions to combat crime and support operational members through innovative solutions that impact upon the criminal environment. The products and services delivered are user focused, secure, and fit for purpose, while supported by a highly skilled, agile, and resilient workforce.
TOC Purpose
Co-design and empower the frontline through agile, secure and reliable digital capabilities to continually maximise the AFP’s impact on the criminal environment.
TOC Vision
A trusted partner, the TOC will drive adaptive technology solutions and capabilities to ensure the delivery of innovative, secure and sustainable systems.
Applications are sought from suitably qualified applicants wishing to be considered for Senior Team Member and Team Member roles within the Cyber Security Assurance Section. These positions can be worked from any capital city in Australia, though Canberra is preferred.
Vacancies include
- Band 6 Team Member
- Band 7 Senior Team Member (2IC)
- Band 7 Technical Senior Team Member
The Cyber Security Assurance section within the Cyber Security & Risk Branch delivers specialist cyber security design, architecture, advisory, assurance and risk assessment services, including Essential Eight uplift and compliance activities, to support AFP business areas.
The advertised roles provide an opportunity to specialise in the Risk & Certification stream, supporting secure capability delivery through effective assurance, certification and risk management practices.
What will you do?
- Conduct cyber security risk assessments for new and existing systems, identifying vulnerabilities and potential threats.
- Prepare assessments and decision papers to support risk-based outcomes.
- Support security certification and accreditation activities against frameworks including ISM, ISO 27001, SOC 2 and NIST.
- Identify, investigate and resolve issues affecting systems and services.
- Build productive working relationships with colleagues, stakeholders and external organisations.
- Contribute to an inclusive, collaborative and high-performing team environment.
- Maintain current knowledge of cyber security, technology processes and industry practices through ongoing professional development.
- Develop team capability through mentoring, guidance and trusted advice.
- Assist the Team Leader in managing team priorities, workflows, strategies and business outcomes.
- Provide people management and operational support to staff, contractors and supervisors.
- Lead projects supporting cyber security assurance priorities, ensuring delivery aligns with team objectives.
- Build and maintain productive relationships with internal and external stakeholders.
- Lead complex cyber security risk assessments and prepare decision papers for systems and technologies.
- Support security certification and accreditation activities against frameworks including ISM, ISO 27001, SOC 2 and NIST.
- Maintain the enterprise cyber risk register, monitor remediation activities and communicate risks and impacts to executive stakeholders.
- Support effective communication with business and technology stakeholders to inform decision-making.
- Ensure system and service issues are identified, investigated, communicated and resolved appropriately.
- Contribute to team outcomes aligned with AFP strategic and operational priorities.
- Maintain contemporary technical and cyber security knowledge through ongoing professional development.
- Build and maintain productive relationships with AFP stakeholders and external partners.
- Lead complex cyber security risk assessments and prepare recommendations and decision papers.
- Support security certification and accreditation activities against recognised frameworks including ISM, ISO 27001, SOC 2 and NIST.
- Maintain cyber risk registers and monitor remediation activities.
- Translate technical security risks into business impacts for stakeholders.
- Support stakeholder engagement and timely communication to enable informed decisions.
- Ensure issues impacting systems and services are appropriately managed and resolved.
- Contribute to delivery of team objectives and AFP strategic priorities.
- Maintain contemporary technical and cyber security expertise through professional development.
Further information on the roles can be found in the Candidate Pack.
Essential Requirements
Both Bands
- You must be an Australian Citizen at the time of application.
- A Negative Vetting 1 (Secret) security clearance or the ability to obtain one.
- Minimum 18 months demonstrated experience in Cyber Security Risk & Certification.
- Excellent written and verbal communication skills, with an ability to translate between business and technical people.
- Excellent organisational, negotiation and conflict management skills.
- Minimum 18 months demonstrated experience in Cyber Security Risk & Certification.
- Excellent written and verbal communication skills, with an ability to translate between business and technical people.
- Excellent organisational, negotiation and conflict management skills.
- People management and or Team leader experience at a minimum of 2 years
- Minimum five years demonstrated experience in Cyber Security Risk and Certification, or an equivalent related field.
- Relevant qualification or extensive experience and knowledge in area of expertise.
- Excellent written and verbal communication skills, with an ability to translate between business and technical people.
- Excellent organisational, negotiation and conflict management skills.
Desirable Requirements
The following skills and/or experience would be highly regarded:
- Tertiary qualifications in an information technology discipline (such as cyber security, computer science, networks, information systems or engineering), or equivalent industry experience.
- A strong understanding of digital technologies and appreciation of technical methodologies.
- Industry-recognised cyber security certifications such as the CISSP, CISA, CISM or OSCP and cloud-technology certifications.
Additional Information
- When applying you will be asked to nominate which band level/s and role/s you wish to be considered for. Note you will only be assessed against the band level/s and role/s you select.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in Canberra →Why this fits a police background
- Police experience explicitly valued
- Investigative casework
- Multi-agency & police liaison
- Risk & threat assessment
- Working to legislation & regulation