First listed on: 28 March 2023
EL 1 - Assistant Director ITIS - Insider Threat Development


$108,195 - $122,044 (plus Super)
Reid - ACT


The Role
The Assistant Director for Insider Threat Development (ITD) will lead a technical team in the data engineering, design and implementation of detection use cases to identify the presence of potential insider threats to Defence. 

They are responsible for:

  • Applying data engineering concepts to enable teams of security analysts to perform insider threat assessments through the curation and effective presentation of event logging data to support analysis.
  • The administration of content within the ITIS Security Information and Event Management (SIEM) system to generate alerts based on derived cyber threat vectors and detection use cases to identify potentially malicious or risky behaviours on ICT systems.
  • Collaborating closely with stakeholders and customers to elicit business requirements and needs to support the development and sustainment of an effective insider threat monitoring capability.
  • Building team capability through coaching, feedback, and mentoring activities to build resiliency and technical competency within a high performing team in an operational environment.
  • Exercise associated people and financial responsibilities to achieve work unit outcomes.

Note: The additional payment is a Building Defence Capability Payment (BDCP) which enables Defence to provide a premium, in addition to the rate of salary otherwise payable under the Enterprise Agreement (EA) to some or all of the jobs within a critical occupation(s) or discipline within a workplace. Applicants engaged into a BDCP position must consider the following. BDCPs provide remuneration in addition to the Defence Enterprise Agreement (EA). This arrangement is subject to meeting eligibility criteria and is subject to annual review. Should your performance fall beyond requirements or the eligibility criteria not be met, your eligibility for the BDCP may be reviewed and ceased. It may also be ceased should you change positions or the requirement for the BDCP is no longer necessary, as determined by Defence. Should the BDCP be ceased you will be advised and your BDCP additional payment will cease.

About our Team
The Directorate of Insider Threat and Investigative Support (ITIS) is a highly skilled team of cyber security professionals with a specialised focus on the timely detection and response to insider threats and behavioural driven cyber security concerns within the Defence Enterprise portfolio. 

Within ITIS, the Insider Threat Development section combines data analytics, cyber security, and software development skills to build detection use cases to identify behaviours of concern and insider threat events that pose a risk to Defence. ITIS is a cross-cutting, multidisciplinary team, operating within Defence’s complex and high tempo environment and works closely with the Defence Investigative Authorities to provide evidentiary standard digital artefacts to enable their investigations for counter intelligence and in response to potential misconduct and criminal activity. 

As part of ICT Security Branch, ITIS reports to the Defence Chief Information Security Officer (CISO) and operates as part of the broader Defence Cyber Security ecosystem including the Defence Security Operations Centre (DSOC), other Australian Government security teams and international agencies. ITIS contributes to the overall Defence ICT security posture through the development of ICT security policy settings, engagement with risk and assessment management teams, ICT service providers and project teams.

Our Ideal Candidate

Our ideal candidate will:

  • Have a strong technical background, with a focus on cyber security, data analytics and data engineering.
  • Demonstrate their motivation for developing their skills while adapting with the rapid pace of technology advancement.
  • Have demonstrated experience applying engineering best practice through their leadership of a development team.
  • Be experienced in administering SIEM products.
  • Have strong knowledge of networking protocols, and both system and application event logging.
  • Have experience delivering technical capabilities in direct support of cyber security functions.
  • Be a confident and persuasive communicator with the ability to explain complex concepts and risk in plain language.
  • Be a pragmatic self-starter with a proven ability to manage competing priorities to a high standard of accuracy within allocated timeframes.
  • Be dynamic, able to switch priorities whilst maintaining focus of overarching strategic goals.

Application Closing Date: Thursday 20 April 2023

For further information please review the job information pack, reference CIOG/02036/23 on https://defencecareers.nga.net.au/?jati=8E2EF135-9D76-8A56-DBBC-D1777B09947B

 
 
 



Recent Jobs