IT Security Analyst - Assurance
On-siteBrisbane, Queensland, Australia
Job Summary
Conduct threat and risk assessments for new systems, applications, and AI solutions, producing structured reports with prioritised remediation recommendations. Perform security architecture reviews against firm standards and frameworks, analyse vulnerability scan results, and track remediation to closure. Coordinate penetration testing activities, respond to client questionnaires and audits, and perform supply chain security reviews to maintain the risk register. Run quarterly audits on privileged access, user access, and asset inventory, and assist with security incident response during and after business hours. Maintain the Security Trust Centre with regular updates and contribute to ISO27001 and other compliance certification programs.
Required Qualifications
- At least 2 years' experience in information security or IT risk
- hands-on exposure to technical security assessments
- Demonstrated ability to conduct structured threat and risk assessments using recognised methodologies (e.g. STRIDE, OCTAVE, NIST RMF)
- Practical exposure reviewing security architectures including cloud security (Azure/M365) and hybrid infrastructure
- Familiarity with vulnerability management tooling (e.g. Qualys, Tenable, CrowdStrike)
- Excellent knowledge of security frameworks such as ISO27001, SSAE16, APRA CPS234, ASD Essential 8, and NIST v2.0
- Expert coordination skills with ability to maintain programs on schedule
- Demonstrated experience writing high quality executive reports/briefings
- Experience running internal IT audits and supplier assessments
- Agile mindset with ability to manage tasks independently
Desired Qualifications
- Relevant certifications highly desirable (CISSP, CISM, CISA, CompTIA Security+, or cloud security certifications)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.