Description of the job
We're seeking an experienced Cyber Security Business Analyst to join a strategically critical cyber uplift program already in motion with one of our clients in the Legal domain. This high-impact role sits within a large-scale transformation delivering key security capabilities including Data Loss Prevention (DLP) and Web Security Gateway (WSG), with broader workstreams spanning PAM, CMDB and MSIEM.
We're looking for someone who can step in and add value immediately. This is not a role for junior BAs or those unfamiliar with security programs - you'll need to be confident navigating both technical and business complexities from day one.
Key Responsibilities:
- Collaborate with cybersecurity engineers, analysts, and stakeholders to translate business security needs into functional and technical requirements.
- Facilitate investigations into business problems, contributing to business cases, solution options, and risk assessments.
- Define and document business processes, workflows, and requirements for Secure Web Gateway deployments, DLP implementation and policy tuning, User Access Review automation tools, Security policy uplift projects.
- Ability to interpret technical IAM and cloud configurations and translate them into actionable business insights.
- Assists with preparation of business cases / proposals which define potential benefits, options for achieving these benefits through development of new or changed technical system changes, and associated business risks.
- Develop and document security policies, procedures, and standards.
- Strong experience as a Technical Business Analyst in cyber security or information security domains.
- Demonstrated experience implementing and upgrading security systems (e.g. DLP, WSG, PAM).
- Working knowledge of MFA, SSO, and IAM frameworks, Role-Based Access Control (RBAC) frameworks. MFA and SSO enablement, audits, and reporting.
- Experience in Cloud Security assessments and documentation (e.g., Azure, AWS).
- Ability to quickly grasp technical detail, work autonomously, and adapt to changing priorities.
- Excellent stakeholder engagement across diverse business and technical audiences.
Additional Info:
- Hybrid: 2-3 days per week onsite in Melbourne CBD.
- Immediate start.
- Role can be offered on a day rate or max term contract basis.