Cubic Corporation

Risk Management Analyst

Cubic Corporation

Wellington, Wellington Region, New Zealand · Full Time

Be the first to apply

Experience
8+ yrs
Salary
Openings
1
Posted
6 days ago
Work mode
In office
Education
University degree in Computer Science, Engineering, or related technical or Business Administration with IT experience
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Cubic Corporation

Join Cubic Corporation and become part of a team dedicated to creating innovative technology solutions that simplify public transportation and strengthen defense capabilities globally. Cubic operates through leading divisions including Cubic Transportation Systems (CTS) and Cubic Defense (CD), delivering products that improve daily journeys and promote safety for service members.

Position Summary

As a key member of Cubic's information security team, you will ensure compliance of production transaction environments with organizational security policies through thorough evaluations of controls and operational settings. You will develop and oversee IT compliance programs, identify risks and mitigation strategies, and collaborate with external auditors on standards such as PCI-DSS and ISO 27001. This role involves independent decision making and requires a proactive approach to information security management.

Main Responsibilities

  • Serve as the Subject Matter Expert for security risk assessment strategies, methodologies, and policies.
  • Lead all facets of security audit operations including scheduling, managing vendor collaboration, program coordination, and stakeholder engagement.
  • Conduct control walkthrough meetings independently and liaise with internal and external auditors as well as IT teams to ensure successful audit completion.
  • Design and perform control reviews and assessments to maintain continuous adherence to security standards and policies.
  • Oversee security review processes for solutions, ensuring compliance with PCI-DSS, ISO 27001, SOC 1 & SOC 2, and regional standards like Australian Essential 8 and New Zealand NZ-ISM, reporting any non-compliance.
  • Identify and communicate significant security risks related to applications, networks, cloud services, infrastructure, vendors, and third parties.
  • Engage with relevant stakeholders to address and remediate compliance gaps, tracking progress and escalating unresolved issues responsibly.
  • Work alongside system operators and security experts to relay compliance deficiencies and outline remediation plans.
  • Maintain compliance records within the OneTrust Governance, Risk, and Compliance (GRC) system and support controls monitoring for customer-facing systems.
  • Build and sustain positive relationships with customers and security teams to facilitate cooperation and successful outcomes.
  • Provide training and education for security management and team members on compliant IT processes and controls while keeping documentation up-to-date.
  • Develop practical solutions for problems identified during audits, collaborating with operations and engineering teams for timely resolution.
  • Ensure follow-up on audit recommendations and corrective measures adhere to Corporate Standards, SDLC, Change Management, and risk governance protocols.
  • Review vendor contracts and SOC reports to assess impact on company controls and coordinate with third-party vendors as necessary.

General Duties

  • Demonstrate reliability in completing assignments and communicate proactively regarding status and challenges.
  • Exhibit ethical conduct and maintain accurate communication even in complex situations.
  • Maintain professionalism in high-pressure and continuous working environments.
  • Adhere to Cubic's Quality Management System and health, safety, and security policies.
  • Support company strategic goals through cross-department collaboration and comply with human resources procedures.

Required Skills and Experience

  • Strong verbal and written English communication skills, with proficiency in Microsoft Office.
  • Ability to effectively collaborate with teams, clients, management, and various business units across multiple locations.
  • Familiarity with PCI DSS 4.0, ISO 27001:2022, SOC I/II standards and audits.
  • Extensive experience working with stakeholders and solution providers within complex matrixed IT organizations, demonstrating persuasive communication and advisory capabilities.
  • Advanced knowledge and problem-solving skills related to IT security risk assessment and policy implementation.
  • Analytical abilities to address complex issues requiring detailed evaluation of various factors and application of sound judgment.

Preferred Qualifications

  • In-depth understanding of security risks and threats relevant to Cubic's operational environments.
  • Relevant certifications such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA, or equivalents.
  • Familiarity or willingness to learn best practices in areas including Open Payments, Mobility as a Service, data classification, Microsoft Azure, AWS cloud security, web application security, network security tools (IDS/IPS, firewalls), encryption, database security, operating system security, vulnerability assessment, SIEM and FIM technologies.

Educational Requirements

A university degree in Computer Science, Engineering or related technical discipline, or in Business Administration accompanied by relevant IT experience is required.

Professional Experience

Candidates should possess at least 8 years of experience in IT or service environments with mission-critical systems and a minimum of 5 years specializing in IT security and payment card processing systems.

Other Important Criteria

  • The candidate must reside within commuting distance of Cubic Transportation Systems offices in Wellington, New Zealand, and be available for periodic regional travel.
  • Employment subject to successful National Police Check results.

Inclusion and Diversity

Cubic is committed to fostering an inclusive workplace and invites applications from diverse backgrounds, ensuring no discrimination based on protected characteristics under applicable law.

Minimum education

Bachelor's Degree

How they work

Communication Work Ethic Relationship Building Accountability Integrity

Languages

Servicenow
🤖
Online · instant AI help
Broxer