Information Security Compliance Lead
Requisition ID: 298155
- Relocation Authorized: None
- Telework Type: Part-Time Telework
- Work Location: Sydney, NSW
Extraordinary teams building inspiring projects:
Since 1898, we have helped customers complete more than 25,000 projects in 160 countries on all seven continents that have created jobs, grown economies, improved the resiliency of the world's infrastructure, increased access to energy, resources, and vital services, and made the world a safer, cleaner place.
Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers' objectives to create a lasting positive impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals, and the Manufacturing and Technology markets. Our services span from initial planning and investment, through start-up and operations.
Core to Bechtel is our Vision, Values and Commitments. They are what we believe, what customers can expect, and how we deliver. Learn more about our extraordinary teams building inspiring projects in our Impact Report.
Project Overview:
Great infrastructure transforms communities. Our customers’ projects have a higher purpose – their roads, rail, communications, airports and energy projects are a gateway to a modern prosperous world. A world that caters for growing populations and keeps up with rapid technological change; a world that is resilient to economic and geophysical setbacks; a world powered by cleaner energy and systems that accelerate the path to global decarbonization; a world connected by smart and affordable transport networks to empower disenfranchised communities and unlock access to opportunities.
Job Summary:
The Infrastructure Information Security Compliance Lead is responsible for developing, implementing, and maintaining the organization's information security compliance program in support of Australian Government, Defence, critical infrastructure, and national security requirements.
The role serves as the subject matter expert for the governance, protection, and control of Defence-related, export-controlled, classified, and other sensitive information. The position leads compliance with Defence Industry Security Program (DISP), Defence Security Principles Framework (DSPF), Protective Security Policy Framework (PSPF), ASD Information Security Manual (ISM), Essential Eight, Security of Critical Infrastructure (SOCI) Act, and related regulatory obligations.
Working closely with Corporate Security, Cyber Security, Information & Digital, project teams, legal, procurement, and executive leadership, the role ensures secure information handling and regulatory compliance across Defence and national security projects.
Applicants must be Australian Citizens and eligible to obtain and maintain an Australian Government Security Clearance (NV1 or higher). Please note we are flexible to work locations being Canberra/Perth/Sydney/Brisbane?Melbourne
This position is designated as part-time telework per our global telework policy and may require at least three days of in-person attendance per week at the assigned office or project. Weekly in-person schedules will be determined by the individual and their supervisor, in consultation with functional or project leadership”
Major Responsibilities:
Security Governance & Compliance
- Develop, implement, and continuously improve the organization's Defence and national security information security compliance program.
- Establish and maintain security policies, procedures, standards, governance frameworks, and assurance processes aligned with DISP, DSPF, PSPF, ISM, Essential Eight, SOCI, and export control requirements.
- Serve as the primary advisor and point of contact for Defence information security compliance matters.
- Monitor regulatory changes and implement compliance improvements.
Defence Information Protection
- Establish and oversee controls governing the classification, access, storage, transmission, sharing, retention, and destruction of sensitive and classified information.
- Develop and maintain Information Security Plans, Technology Control Plans, Security Classification Guides, Security Risk Assessments, and foreign access management arrangements.
- Assess and manage security risks associated with foreign ownership, control, influence, and access to controlled information.
- Defence Industry Security Program (DISP) & Security Assurance
- Support and maintain DISP membership requirements across Governance, Personnel, Physical, and ICT Security domains.
- Lead Defence audits, DISP assurance activities, annual reporting obligations, and security compliance reviews.
- Develop and track remediation plans arising from audits, assessments, and regulatory reviews.
- Maintain audit-ready evidence, compliance records, and security documentation.
Cyber Security Compliance & Risk Management
- Partner with Cyber Security and Information & Digital teams to ensure compliance with DISP, PSPF, ISM, and Essential Eight requirements.
- Support security accreditation, certification, and authorisation activities for Defence systems and projects.
- Monitor information security risks and compliance across project, operational, and corporate environments.
Stakeholder Engagement & Advisory
- Act as the primary liaison with Defence, DISO, government regulators, customers, and prime contractors on information security matters.
- Provide security guidance and compliance advice to project teams, subcontractors, joint venture partners, and leadership teams.
Security Culture & Awareness - Develop and deliver security awareness programs, briefings, and training.
- Promote a positive security culture and support executive and project leadership awareness of Defence security obligations.
Domestic travel may be required to support Defence projects.
Education and Experience Requirements:
- Bachelor's degree in Information Security, Cyber Security, Governance, Risk & Compliance, Security Management, Engineering, Law, or related discipline and 10-15 years of relevant professional experience.
- Experience establishing or managing information security, compliance, protective security, or assurance programs.
- Experience within Defence, government, critical infrastructure, national security, or similarly regulated environments.
Preferred Experience:
- Defence, AUKUS, naval shipbuilding, submarine, nuclear stewardship, critical infrastructure, or national security programs.
- Experience supporting DISP audits, DSPF assessments, ASD reviews, or accredited information systems.Development of Technology Control Plans, Security Plans, Security Risk Assessments, and foreign access procedures.
- Experience as a Security Officer, Chief Security Officer, DISP Security Lead, Information Security Compliance Lead, or Governance, Risk & Compliance professional.
- Knowledge of SCEC, secure facilities, and Security Construction requirements.
- CISSP, CISM, or CRISC
- ISO 27001 Lead Implementer/Auditor
- CPP or PSP
- SABSA
- PMP or equivalent project management qualification
Required Knowledge and Skills:
-
Information security governance, risk management, compliance, and assurance.
-
Strong knowledge of DISP, DSPF, PSPF, ASD ISM, Essential Eight, SOCI, security classifications, and government security frameworks.
-
Experience managing controlled, classified, Defence, export-controlled, and sensitive information.Knowledge of Defence export controls, Defence Trade Controls Act, ITAR/EAR requirements, and foreign access controls.
-
Security policy development, audit management, compliance reporting, and risk assessment.Strong stakeholder engagement, communication, and policy-writing skills.
Total Rewards/Benefits:
For decades, Bechtel has worked to inspire the next generation of employees and beyond! Because our teams face some of the world's toughest challenges, we offer robust benefits to ensure our people thrive. Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth. Learn more at Bechtel Total Rewards
Diverse teams build the extraordinary:
As a global company, Bechtel has long been home to a vibrant multitude of nationalities, cultures, ethnicities, and life experiences. This diversity has made us a more trusted partner, more effective problem solvers and innovators, and a more attractive destination for leading talent.
We are committed to being a company where every colleague feels that they belong-where colleagues feel part of "One Team," respected and rewarded for what they bring, supported in pursuing their goals, invested in our values and purpose, and treated equitably. Click here to learn more about the people who power our legacy.
Bechtel is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, disability, citizenship status (except as authorized by law), protected veteran status, genetic information, and any other characteristic protected by federal, state or local law. Applicants with a disability, who require a reasonable accommodation for any part of the application or hiring process, may e-mail their request to acesstmt@bechtel.com