Triton Cybersecurity GRC Lead
AUSTRALIAN CITIZENSHIP REQUIRED FOR THIS POSITION: Yes
RELOCATION ASSISTANCE: No relocation assistance available
CLEARANCE TYPE: AU-TSPV (Positive Vetting)
TRAVEL: Yes, 10% of the Time
Description
We are Northrop Grumman Australia (NGA). Our 800 strong team is leveraging unparalleled global resources to deliver sovereign Defence capability aligned to the Government’s priorities across Aeronautics, Mission Critical Systems, Space and Guided Weapons. As we build our business and our capabilities, we are also developing a reputation as a great place to work. Help us define what is possible for our nation and for your career.
The Role:
The MQ-4C (Triton Unmanned Aircraft System) team in Edinburgh (SA) is expanding.
Northrop Grumman Australia is seeking a Cyber Security GRC Lead to take ownership of the governance, risk and authorisation activities underpinning one of Australia's most advanced Defence capabilities.
Triton is a first-of-type ISR platform for the ADF, operating across complex systems and classifications. Cybersecurity isn't a tick-box exercise, it needs to be clearly defined, documented, justified and maintained throughout the system lifecycle.
This role sits at the centre of that process. You'll lead the development and maturity of the security artefacts, assessments and governance activities that support Authorisation to Operate (ATO), helping ensure Triton systems remain secure, compliant and trusted.
You'll inherit a solid foundation with established frameworks, templates and artefacts already in place. The opportunity is to take ownership, uplift their maturity, and help shape a professional suite of security documentation that supports the Triton program.
This role is Adelaide-based (RAAF Edinburgh). Australian Citizenship and an NV1 clearance are required to be considered.
Key Responsibilities
You'll lead how cyber risk is assessed, documented and managed, ensuring Triton systems maintain their ATO and continue to meet Defence security requirements.
- Own and mature the security artefacts supporting Assessment & Authorisation activities, including SSPs, SRMPs and PoAMs
- Lead system approvals, re-authorisations and security impact assessments across system changes and upgrades
- Conduct and present security risk assessments, treatment options and recommendations to stakeholders and risk owners
- Maintain system security registers, asset baselines and authorisation documentation
- Work closely with engineering, configuration management and data management teams to ensure governance activities remain aligned to system changes
- Engage with Defence stakeholders and assessment authorities to support authorisation outcomes
About You
You're someone who enjoys bringing structure to complexity. You understand technical systems, but your strength lies in translating risk into clear, defensible and professionally presented security outcomes.
- Experience in cyber GRC, risk management, and Defence Assessment and Authorisation (A&A) processes
- Strong experience developing and maintaining security artefacts and systems security documentation for Defence classified networks
- Comfortable working within frameworks such as the ISM, PSPF and Defence security requirements
- Ability to assess complex technical changes and articulate security impacts and risk treatment options
- Strong written communication skills with the ability to produce high-quality, audit-ready documentation
- Confident engaging with engineers, program stakeholders and Defence representatives
You might be:
- A senior GRC practitioner looking to take ownership of the authorisation process of a complex, multi-classification Defence system.
- An A&A or cybersecurity GRC specialist seeking greater influence and accountability
- An IRAP, Governance or Defence security professional wanting to move into a role focused on long-term capability uplift and security governance
What we Offer
We have built our benefits to help you define your possible.
- Professional Development – further education, leadership development, professional industry memberships and unlimited access to a range of online training
- Additional purchased annual leave – 2 weeks
- Salary packaging including novated car leases
- Generous paid parental leave – 18 Weeks
- Volunteer and enhanced Reservist Leave
- Health & Wellbeing program
- Employee Assistance Program
Everyone Matters Doing the right thing and sharing success are two values underpinning how we behave at Northrop Grumman. Here, everyone matters including candidates from diverse backgrounds.
We are particularly proud of our commitment to reconciliation with Aboriginal and Torres Strait Islander people as demonstrated through our Second Innovate RAP (2024-2026), and our support for Veteran employment, and welcome Aboriginal and Torres Strait Islander people and Veterans to apply to join our team.
For more information or a confidential discussion, please contact the•••••••@au.ngc.com NB Files cannot be sent to this address.
As a Defence security clearance is required for this role, you must be an Australian Citizen. International Traffic in Arms Regulations (ITAR) are applicable, as such your nationality may be a factor in determining your suitability for this role. You will also need to satisfy police checks and employment screening verification.
We are proud to be WORK180 accredited – check us out here Northrop Grumman Australia | WORK180 Endorsed Employer