Summary
✨ AI‑Generated
A program management position leading security uplift initiatives for critical infrastructure environments. The role involves managing risks across cyber, personnel, supply chain, and operational domains while coordinating diverse stakeholders.
Highlights
Leadership role managing complex security and compliance programs across multiple risk domains with executive-level engagement.
Description
OCRT is a sovereign, veteran-owned Australian consultancy delivering professional services across Defence, Government, and national security.
We are putting together a team to support a critical infrastructure risk and security uplift opportunity for a major renewable energy transmission network in NSW, and are seeking an experienced Program/Engagement Manager to line up for delivery.
The role:
Embedded within the client's business in Sydney, you'll lead a phased engagement to establish and uplift a Critical Infrastructure Risk Management Program (CIRMP) under the Security of Critical Infrastructure Act 2018; spanning cyber, personnel, supply chain, and physical/natural hazard risk domains, through to board-ready compliance outcomes.
What we're looking for:
Proven experience leading complex, multi-stakeholder risk/compliance or security programs, ideally in critical infrastructure, energy, or utilities sectorsFamiliarity with the Security of Critical Infrastructure Act 2018 and CIRMP Rules (or equivalent regulatory/compliance frameworks) - direct SOCI Act experience highly regardedExperience in greenfield infrastructure or renewable energy transmission projectsExperience managing phased, deliverable-based engagements with formal client sign-off/acceptance gatesComfortable operating across OT/IT environments and engaging both technical specialists (cyber, engineering) and executive/board-level stakeholdersExperience working across multi-party delivery models - e.g.
coordinating between an asset owner, a design/construct partner, and an operations/maintenance partnerStrong governance, reporting, and documentation discipline - including fortnightly status reporting, RAID/issues logs, and evidence-based compliance reportingBackground across one or more of: cyber and information security, personnel security, supply chain risk, or physical security/natural hazard managementBased in or willing to be embedded in Sydney for the engagement duration, with on-site presence as requiredExperience producing board-ready or executive-level reporting and briefings
Nice to have:
Prior exposure to the Australian Energy Sector Cyber Security Framework (AESCSF)Familiarity with critical infrastructure asset registers, material risk assessments, or design conformance reviews
Why OCRT:
We're a tight-knit, capability-led team that backs our people into meaningful national-security-adjacent work; with the autonomy of consulting and the support of a firm that knows this sector.
📩 Interested or want to know more? Apply with your CV or reach out to info@ocrt.com.au directly.