C

Risk Analyst

Cubic Transportation Systems

Wellington, Wellington Region, New Zealand · Full Time

Be the first to apply

Experience
8+ yrs
Salary
—
Openings
1
Posted
3 days ago
Work mode
In office
Education
University degree in Computer Science, Engineering, Business Administration or related field
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Cubic Transportation Systems

Cubic Transportation Systems (CTS) is a worldwide frontrunner in intelligent transport solutions, focusing on technologies that enhance the efficiency, accessibility, and user experience of public transit. One of their core offerings includes Fare and Payment card services tailored for governmental and municipal clients across the globe.

Job Summary

As a valued member of the Cubic information security team, your primary role involves supporting security compliance within production transaction processing environments. Responsibilities include assessing the effectiveness of security controls and operational environments to ensure alignment with corporate security policies. You will plan and execute IT compliance evaluation programs, identify potential security risks, and develop appropriate mitigation strategies. Collaboration with external auditors to facilitate compliance audits (including PCI-DSS, ISO 27001 etc.) is a key function. This role typically operates with limited supervision, requiring discretionary and substantial decision-making capabilities.

Key Responsibilities

  • Serve as the acknowledged Subject Matter Expert for Security Risk Assessment practices, policies, strategies, and procedures.
  • Coordinate all security audit activities such as scheduling, vendor liaison, program management, and stakeholder engagement.
  • Work independently with Internal/External Auditors and IT teams to complete regular audits, including holding control walkthrough sessions and ensuring all parties understand their responsibilities.
  • Lead design and control assessments to maintain continuous adherence to security policies and standards.
  • Oversee security reviews for all solutions ensuring designs and implementations comply with standards like PCI-DSS, ISO 27001, SOC 1 & SOC 2, as well as regional mandates including Australia's Essential 8 and New Zealand's NZ-ISM; document and report any compliance shortfalls.
  • Identify and communicate major information security risks linked to applications, development, networks, data centers, cloud and physical IT infrastructure, vendors, and third parties.
  • Manage remediation efforts by identifying responsible stakeholders, escalating unresolved issues constructively, and tracking remediation progress.
  • Collaborate with system operators and security experts to communicate compliance gaps and devise acceptable remediation plans.
  • Document compliance deficiencies and remediation measures in the OneTrust GRC platform; plan, review, and conduct control monitoring of complex customer-facing systems using OneTrust.
  • Engage with Cubic clients and internal Security teams to foster positive relationships and outcomes.
  • Support security management and team education regarding compliant IT processes and controls; maintain related documentation.
  • Assist in developing audit-related solutions and convert them into actionable recommendations; partner with Operations and Engineering for timely remediation.
  • Follow up on recommendations ensuring that corrective actions and corporate standards including SDLC, Change Management, and risk governance are thoroughly observed.
  • Review vendor contracts and SOC reports to assess impact on company controls and coordinate with third-party vendors accordingly.
  • Demonstrate accountability, proactive communication, ethical conduct, and professionalism in all work settings.
  • Adhere to Cubic’s Quality Management System, health, safety, security policies, and strategic organizational objectives.

Required Skills and Experience

  • Excellent written and verbal communication skills in English and proficient in Microsoft Office tools.
  • Ability to collaborate effectively with diverse teams, including clients, IT management, and business units within a cross-functional, matrixed IT environment.
  • Experience working across different organizational levels and geographical locations.
  • Knowledge of PCI DSS 4, ISO 27001:2022, SOC I/II compliance requirements, and audit processes.
  • Expertise in stakeholder management and influencing within matrixed organizations; regularly trusted to advise on complex issues and contribute to business objectives.
  • Extensive professional experience using advanced knowledge to resolve complex challenges and develop innovative policy solutions.
  • Proficient in analyzing complex situations where multiple variables affect outcomes, making independent decisions regarding methodologies and evaluation criteria.

Preferred Qualifications

  • In-depth understanding of security risks and threats applicable to the company’s operating environments.

Education and Experience Requirements

  • A minimum of 8 years in IT services or systems supporting mission-critical operations.
  • University degree in Computer Science, Engineering, Business Administration with relevant IT experience, or related technical fields.
  • At least 5 years' experience in IT security and/or Payment Card processing environments with strong technical knowledge of internally developed systems.
  • Resident within commuting distance to Cubic’s Wellington, NZ office and availability for regional travel.
  • Desirable certifications include CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA, or equivalents.
  • Willingness to acquire expertise in security best practices for platforms such as Open Payments, Mobility as a Service, cloud security (Azure, AWS), web and network infrastructure security, encryption methodologies, database and OS security, vulnerability assessments, and SIEM/FIM solutions.

Conditions of Employment

Successful completion of a National Police Check is required.

Minimum education

Bachelor's Degree

Tools & software

Microsoft Office Microsoft Office required

How they work

Communication Work Ethic Relationship Building Accountability

Languages

Servicenow

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer