25th September, 2026
We are partnering with a top-tier consultancy delivering a major Federal Government program in Canberra. We are seeking experienced Security Product Assessors to join a specialist Defence cyber security assurance team responsible for evaluating the security capabilities of software and hardware products used across Defence environments.
With two positions available, this is a unique opportunity for cyber security professionals who enjoy deep technical analysis, security architecture review, and identifying weaknesses before they become operational risks.
About the Role
As a Security Product Assessor, you will conduct detailed evaluations of security products, applying rigorous scrutiny to the security-enforcing mechanisms within hardware and software solutions. Your assessments will help determine whether products are suitable for use within Defence environments.
You will analyse product architecture, security features, technical documentation, implementation approaches and vendor claims to identify risks, vulnerabilities and security limitations. Your findings will be translated into clear, evidence-based reports used by senior Defence stakeholders to make informed risk decisions.
Clearance Required
AGSVA NV1 preferred, Baseline minimum.
Location
Minimum of 3 days on site in Canberra, subject to change.
How You'll Contribute
- Conduct independent security evaluations of hardware, software and security products proposed for use within Defence environments.
- Assess the effectiveness of security controls, security-enforcing mechanisms and protective capabilities within products and technologies.
- Review architecture documentation, design specifications, implementation guidance and vendor-supplied security material.
- Analyse product risks, security weaknesses and potential impacts to Defence systems and operations.
- Produce comprehensive technical and risk assessment reports for senior risk owners and decision-makers.
- Provide expert advice on product suitability, security limitations, mitigations and recommended risk treatments.
- Engage with vendors, project teams and Defence stakeholders throughout assessment activities.
- Support assessment triage, prioritisation and assurance activities aligned to Defence operational priorities.
- Contribute to holistic cyber risk reporting and assurance outcomes across the organisation.
- Assist with governance, reporting, Freedom of Information requests, executive briefings and other cyber assurance activities as required.
What You'll Bring to the TeamWe are looking for candidates with experience in one or more of the following:
- Security product evaluation and assurance.
- Security architecture review and analysis.
- Application, platform or infrastructure security.
- Security control testing and validation.
- Network, endpoint, cloud or enterprise security solutions.
- Vulnerability assessment and security research.
- Technical risk assessment and reporting.
- Information security governance, risk and compliance.
- Working within government, Defence or other highly regulated environments.
- Strong understanding of cyber security principles, security controls and assurance methodologies.
- Familiarity with the Australian Government Information Security Manual (ISM) and its application within government environments.
- Ability to identify, assess and articulate cyber security risks to technical and non-technical stakeholders.
- Strong written communication skills, with experience producing detailed technical assessments and risk reports.
What Sets You ApartYou are a cyber security professional with strong technical analytical skills and a genuine interest in understanding how security technologies work beneath the surface.
You can critically evaluate both hardware and software products, identify potential security weaknesses, and communicate complex technical findings in a clear, concise manner for both technical and executive audiences.
Qualifications & Certifications One or more of the following will be highly regarded:
- Tertiary qualifications in Cyber Security, Information Security, Computer Science or a related discipline.
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
- GSLC (GIAC Security Leadership Certificate)
- GSNA (GIAC Systems and Network Auditor)
- ISO 27001 Lead Auditor
- PCI QSA (Qualified Security Assessor)
Why You'll Love This OpportunityThis role offers the opportunity to work on significant cyber security challenges, assessing the technologies that underpin the protection of critical information and capabilities. You'll be part of a highly specialised team whose assessments directly influence security decisions across a complex and evolving technology landscape.
How to Apply
Apply via SEEK, or for a confidential discussion contact Byron at
Byron@approachconsult.com.au or call
0415 531 330.
Apply For Job