Secure the technology that protects those who matter
Silentium Defence is developing world-leading passive radar and advanced sensing technology supporting Defence, national security and critical infrastructure. As our products and engineering capability continue to grow, we are looking for an experienced Product Security GRC Specialist to
strengthen the security, resilience and compliance of our products and development environments.
This is a hands-on security governance role sitting at the intersection of cyber security, engineering and Defence assurance. You will work closely with multidisciplinary engineering teams to embed security throughout the product lifecycle, manage Governance, Risk and Compliance activities, and help ensure our products meet Australian Government, Defence and industry security requirements.
If you enjoy translating complex security frameworks into practical engineering outcomes and want to contribute to technology with genuine national security impact, this could be your next opportunity.
Your Opportunity
As our Product Security GRC Specialist, you will take ownership of key product security assurance and compliance activities across our technology portfolio.
You will support products through Assessment and Authorisation activities, maintain audit-ready security artefacts, help engineering teams implement appropriate controls, and ensure
security remains embedded throughout the Secure Development Lifecycle.
You will also play an important role in identifying emerging security risks, managing vulnerabilities and continuously improving secure engineering practices across Silentium Defence.
What You’ll Be Doing
- Develop and maintain product security documentation including security policies, procedures, risk assessments and System Security Plans.
- Manage Assessment and Authorisation (A&A) activities and associated product security artefacts.
- Maintain security documentation and evidence to support Defence assurance and IRAP assessment readiness.
- Interpret and apply applicable controls from the Australian Government Information Security Manual (ISM) and relevant industry frameworks including the NIST Cybersecurity Framework.
- Monitor product architectures and security controls to ensure ongoing compliance with regulatory, legislative and contractual requirements.
- Integrate security controls, processes and testing throughout the Secure Software Development Lifecycle (SDLC).
- Assess existing software development practices and identify opportunities to strengthen security and compliance.
- Manage vulnerability remediation activities and support product security incident response and forensic investigations when required.
- Support Linux system security, operating system hardening and application security practices.
- Work with engineering teams to strengthen DevSecOps practices including CI pipelines, Infrastructure-as-Code and early vulnerability identification.
- Contribute to supplier and supply-chain assurance activities, including supplier security evaluations, SBOM reviews and third-party component integrity.
- Provide informed advice to stakeholders regarding emerging cyber threats, security technologies and Defence ICT security developments.
- Continuously improve security governance, engineering practices, tools and standards.
About You
You are an experienced cyber security professional who understands that successful security is not simply about applying controls — it is about working with engineering teams to deliver secure, compliant and practical products.
You can confidently interpret security frameworks and translate requirements into actions that engineers, project teams and business stakeholders can understand and implement.
You are comfortable working across technical and governance environments and can balance cyber risk, compliance obligations, engineering constraints and business priorities.
You will bring:
- Approximately 5+ years’ experience in cyber security, including at least two years focused on security engineering.
- Experience supporting Governance, Risk and Compliance activities within technical or engineering environments.
- Working knowledge of the Australian Government ISM and familiarity with Defence security requirements.
- Awareness and practical understanding of the NIST Cybersecurity Framework.
- Experience developing security documentation, risk assessments and audit evidence.
- Understanding of secure software development and SDLC principles.
- Familiarity with Linux security and hardening practices.
- Understanding of DevSecOps practices and security within CI/CD environments.
- Exposure to scripting or software development languages such as Bash, Python or C++.
- Strong stakeholder engagement skills and the ability to influence both technical and non-technical audiences.
Qualifications & Security Requirements
To be considered for this opportunity you will require:
- Australian Citizenship.
- Eligibility to obtain and maintain an Australian Government NV1 security clearance or higher.
- Bachelor’s degree or equivalent qualification in Cybersecurity, Computer Science, Engineering or a related discipline.
- Security+ or Certified in Cybersecurity (CC), or equivalent relevant certification.
Highly regarded certifications include:
- Certified in Governance, Risk and Compliance (CGRC)
- Certified Information Systems Security Professional (CISSP)
- Information Systems Security Engineering Professional (ISSEP)
- Certified Secure Software Lifecycle Professional (CSSLP)
- Certified Information Systems Auditor (CISA)
Why Silentium Defence?
At Silentium Defence, you will be working alongside talented engineers and specialists developing technology with real-world Defence and national security applications.
You will have the opportunity to influence how security is incorporated into our products from design through development, deployment and sustainment — rather than simply assessing security after the fact.
This is an opportunity to take meaningful ownership, work across diverse technical challenges and help shape secure engineering practices as our organisation continues to grow.
If you are passionate about product security, Defence cyber assurance and building security into technology from the beginning, we would love to hear from you.