Risk Management Analyst
Wellington, Wellington Region, New Zealand · Full Time
Be the first to apply
- Experience
- 8+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 6 days ago
- Work mode
- In office
- Education
- University degree in Computer Science, Engineering, or related technical or Business Administration with IT experience
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Cubic Corporation
Join Cubic Corporation and become part of a team dedicated to creating innovative technology solutions that simplify public transportation and strengthen defense capabilities globally. Cubic operates through leading divisions including Cubic Transportation Systems (CTS) and Cubic Defense (CD), delivering products that improve daily journeys and promote safety for service members.
Position Summary
As a key member of Cubic's information security team, you will ensure compliance of production transaction environments with organizational security policies through thorough evaluations of controls and operational settings. You will develop and oversee IT compliance programs, identify risks and mitigation strategies, and collaborate with external auditors on standards such as PCI-DSS and ISO 27001. This role involves independent decision making and requires a proactive approach to information security management.
Main Responsibilities
- Serve as the Subject Matter Expert for security risk assessment strategies, methodologies, and policies.
- Lead all facets of security audit operations including scheduling, managing vendor collaboration, program coordination, and stakeholder engagement.
- Conduct control walkthrough meetings independently and liaise with internal and external auditors as well as IT teams to ensure successful audit completion.
- Design and perform control reviews and assessments to maintain continuous adherence to security standards and policies.
- Oversee security review processes for solutions, ensuring compliance with PCI-DSS, ISO 27001, SOC 1 & SOC 2, and regional standards like Australian Essential 8 and New Zealand NZ-ISM, reporting any non-compliance.
- Identify and communicate significant security risks related to applications, networks, cloud services, infrastructure, vendors, and third parties.
- Engage with relevant stakeholders to address and remediate compliance gaps, tracking progress and escalating unresolved issues responsibly.
- Work alongside system operators and security experts to relay compliance deficiencies and outline remediation plans.
- Maintain compliance records within the OneTrust Governance, Risk, and Compliance (GRC) system and support controls monitoring for customer-facing systems.
- Build and sustain positive relationships with customers and security teams to facilitate cooperation and successful outcomes.
- Provide training and education for security management and team members on compliant IT processes and controls while keeping documentation up-to-date.
- Develop practical solutions for problems identified during audits, collaborating with operations and engineering teams for timely resolution.
- Ensure follow-up on audit recommendations and corrective measures adhere to Corporate Standards, SDLC, Change Management, and risk governance protocols.
- Review vendor contracts and SOC reports to assess impact on company controls and coordinate with third-party vendors as necessary.
General Duties
- Demonstrate reliability in completing assignments and communicate proactively regarding status and challenges.
- Exhibit ethical conduct and maintain accurate communication even in complex situations.
- Maintain professionalism in high-pressure and continuous working environments.
- Adhere to Cubic's Quality Management System and health, safety, and security policies.
- Support company strategic goals through cross-department collaboration and comply with human resources procedures.
Required Skills and Experience
- Strong verbal and written English communication skills, with proficiency in Microsoft Office.
- Ability to effectively collaborate with teams, clients, management, and various business units across multiple locations.
- Familiarity with PCI DSS 4.0, ISO 27001:2022, SOC I/II standards and audits.
- Extensive experience working with stakeholders and solution providers within complex matrixed IT organizations, demonstrating persuasive communication and advisory capabilities.
- Advanced knowledge and problem-solving skills related to IT security risk assessment and policy implementation.
- Analytical abilities to address complex issues requiring detailed evaluation of various factors and application of sound judgment.
Preferred Qualifications
- In-depth understanding of security risks and threats relevant to Cubic's operational environments.
- Relevant certifications such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA, or equivalents.
- Familiarity or willingness to learn best practices in areas including Open Payments, Mobility as a Service, data classification, Microsoft Azure, AWS cloud security, web application security, network security tools (IDS/IPS, firewalls), encryption, database security, operating system security, vulnerability assessment, SIEM and FIM technologies.
Educational Requirements
A university degree in Computer Science, Engineering or related technical discipline, or in Business Administration accompanied by relevant IT experience is required.
Professional Experience
Candidates should possess at least 8 years of experience in IT or service environments with mission-critical systems and a minimum of 5 years specializing in IT security and payment card processing systems.
Other Important Criteria
- The candidate must reside within commuting distance of Cubic Transportation Systems offices in Wellington, New Zealand, and be available for periodic regional travel.
- Employment subject to successful National Police Check results.
Inclusion and Diversity
Cubic is committed to fostering an inclusive workplace and invites applications from diverse backgrounds, ensuring no discrimination based on protected characteristics under applicable law.
Minimum education
Bachelor's Degree