Westpac

Information Security Consultant

To become number one for customer service

  • Consulting and Professional Services

  • Full-time

  • Office | Sydney, NSW, Australia

  • Visa sponsorship · No

  • Junior · A role for someone with some basic skills, good motivation and ability to learn. Typically 1-2 years of experience is required.

  • ·

Why Westpac

Westpac is Australia’s oldest bank and company, one of four major banking organisations in Australia and one of the largest banks in New Zealand. We provide a broad range of banking and financial services in these markets, including consumer, business and institutional banking and wealth management services.

About the role

How will I help? As a Purple Team Consultant is responsible for the coordination of the interface between defensive and offensive security teams, with a focus on ensuring issues are successfully and rapidly remediated. This work is guided by the Westpac Purple (offensive/defensive) Teaming framework. Key Responsibilities

  • Ensure that Westpac continues to be protected against current and emerging threats through the implementation of Purple Team engagements.
  • Ensure that all Purple Teaming findings are captured centrally, are reviewed by blue teams, that remediation steps are identified, and that remediation is allocated to the appropriate service owner. Remediation may occur through BAU or projects, within ISG or in other parts of the Group. 
  • Coordinate and lead technical workshops to advise on the design of security controls improvement.
  • Identify patterns of findings which may indicate control weaknesses, and similarly initiate remediation or control improvement
  • Provide reporting on (a) aggregate Purple team findings, (b) remediation commitments, (c) progress against those commitments, and (d) subsequent improvement in the Group’s protection against sophisticated threats. 
  • Provide visibility of security controls effectiveness measures, based on the MITRE ATT&CK Framework and associated Purple Team engagements.
  • Ensure virtual teams adhere to Purple Teaming policies, processes, methodologies, standards, and guidelines
  • Advise on the development, implementation and maintenance of security policies, procedures, standards, governance frameworks and strategies, and assist with development of security tools and processes to ensure that Westpac operates within the established risk appetite.
  • Implement Purple Team strategies and plans to continue to mature our Purple Teaming capabilities, with a strong linkage to the Westpac Red (offensive) Team, Blue (defensive) Teams and Cyber Threat Intelligence capabilities.

  What’s in it for me? You will play an important and significant part in the future of a business that has been around for 200 years. Our vision is to become one of the world’s great service companies. So, we will back you in the development of your career, with internal career prospects and flexible working. You will also be backed by a fantastic team of people in a can-do, supportive structure.  Whatever shape your family takes, we offer generous paid and unpaid parental leave for your nominated primary and support carers. This includes leave to organise adoptions, surrogacy, and foster care arrangements.    What do I need? To be successful in this role, you need to have the following skills, education & personal attributes: 

  • Strong experience in information security, threat intelligence, risk management, or equivalent role
  • A good understanding of security controls related to red team findings, blue team operations and cyber threat intelligence. 
  • Familiar with the use of cyber threat intelligence to inform control and investment decisions.
  • Demonstrated strong experience in managing virtual teams to deliver Purple Team engagements and providing visibility of security control improvements to senior management.
  • Project Management Certifications or equivalent 
  • Tertiary education in Cyber Security

What you'll be responsible for

  • 🔀

    Technology Solution Design and Development

    Design and develop customized technology solutions, such as software applications, databases, networks, and platforms

  • 🖥

    Technology Implementation

    Manage technology implementation projects, including budget, timeline, and resources

  • 💬

    Client Communication and Relationship Building

    Communicate with clients and stakeholders to build relationships, gather feedback, and ensure satisfaction with services

Skills you'll need

  • 🤔

    Decision Making

    Considers the costs and benefits of potential actions and determines the most appropriate one

  • 💭

    Critical thinking

    Identifies and synthesizes patterns and trends amongst various sources of information to reach a meaningful conclusion, perspective or insight

  • 💡

    Problem solving

    Identifies problems and develops logical solutions that address the problems

Meet the team

Avatar
Consulting

Westpac