Position Description Technical Lead, Computer Network Defence Business unit: Responsible to: Position purpose: Directorate overview: Information Assurance and Cyber Security Directorate Manager, Cyber Security Operations The Technical Lead Computer Network Defence provides senior oversight of the analysis and discovery of sophisticated computer network threats and exploitation. The Technical Lead assists the Manager in determining and achieving the strategic goals of the unit, as well as assisting with team leadership and personnel management duties. The IAC Directorate contributes to the national security of New Zealand by providing technical advice and assistance to Government and organisations with significant national information infrastructures to enable them to protect their information from advanced technology-borne threats. To achieve this, the Directorate provides high assurance services; information assurance policy and advice; and high-end cyber security services to detect and respond to such threats. GCSB mission and values Our mission Protecting and Enhancing New Zealand s Security and Wellbeing. Our values Respect, Commitment, Integrity, Courage. UNCLASSIFIED PAGE 1
Information Assurance & Cyber security Directorate mission, values and goal Our vision Protect New Zealand s vital information infrastructures Our mission To be a team of confident professionals, admired for our innovation and regarded both domestically and internationally as leaders in the Information Assurance and Cyber sectors. To have a comprehensive understanding of the advanced, technology-borne attempts to target our vital information infrastructures and steal our secrets and intellectual property. To be confident about our ability to monitor these threats and either reduce harm directly through timely provision of assurance and technical services or help others to mitigate risks through authoritative policy and expert advice built on our unique capabilities. Our goal There are no advanced, foreign-sourced, technology-borne compromises of the most significant national infrastructures by June 2016. UNCLASSIFIED PAGE 2
Objectives The position encompasses the following major functions or objectives: Developing and Managing People Manage team outputs Technical leadership Maintaining Training and Technical expertise Jobholder is accountable for: Team Leadership Effectively lead Computer Network Defence Team, to enable successful results across the Unit. Promote a positive, cohesive team environment where individuals demonstrate the core values of the GCSB. Ensure any impediments are identified and rectified. Enable individuals to complete their tasks through analytic, technical and personal development and training. Ensure a technical training curriculum is designed and implemented for all Unit staff. Effectively manage workloads to ensure they are appropriate to meet Unit objectives and staff abilities. Ensure performance objectives, reviews and discussions are completed in line with Bureau policies and procedures for all direct reports In conjunction with Human Resources and the Cyber Security Operations Unit Manager, address poor performance of employees and ensure that good conduct and discipline is maintained at all times and any issues are dealt with promptly. Demonstrate the stated values of the organisation in all aspects of their representation of the team/bureau. Jobholder is successful when: Staff are motivated and engaged with a clear understanding of the technical requirements that meet unit and organisational objectives. Staff are appropriately trained to meet Unit objectives. Unit and staff performance is continuously monitored. Unit is performing to its expected potential and organisational values are represented appropriately and respectfully. Any variance is addressed fairly and within an appropriate timeframe. UNCLASSIFIED PAGE 3
Managing Section Output Provide technical oversight of the detection, understanding and analysis of sophisticated sophisticated computer network threats and exploitation. Provide technical oversight of the discovery and analysis of new or emerging cyber security threats. Provide expert oversight of the engineering, integration and maintenance of software solutions that enable efficient analysis and reporting of threats. Ensure technical solutions are optimised Enable the timely provision of event reporting. Understand and adhere to GCSB and community guidelines to ensure outputs comply with appropriate guidelines. Assist NCSC entities with the provision of appropriate mitigation responses to GCSB customers and partners. Customer and Partner Interaction Enhance GCSB s relationships and reputation with customers through professionalism, representation and engagement. Develop and manage a range of relationships Participate in the development of new or enhanced tradecraft. Provide technical leadership and advice to customers Seek out and develop new customer and operational relationships, to further enhance the Cyber Security Operation Unit s capabilities and reputation. Threats to New Zealand critical national infrastructure are identified and understood. Analysis is performed in accordance with procedures. Detection capabilities are enhanced. Detection systems remain operational Detection capabilities are routinely investigated to ensure they are fit for purpose. Relevant and timely threat reporting is provided to customers GCSB reporting complies with all community guidelines and policies. The content of provided mitigation advice is unambiguous in its meaning and implications of why it is being provided are clear. Productive and enduring relationships are formed with domestic and international partners. The technical capability of the Cyber Security Operations Unit is valued at the national and community level. The Cyber Security Operations Unit has a detailed awareness of customers needs and expectations. Customer and partner enquiries are attended to in a timely manner. UNCLASSIFIED PAGE 4
Maintaining Training and Technical Expertise Maintain a comprehensive understanding of capabilities and infrastructure in order to effectively mentor analysts and engineers. Maintain and improve technical understanding and expertise through continuing education, and act as the GCSB point of contact for computer network threats Support and nurture the Units understanding of attack tool capabilities and infrastructure. Maintain a personal technical research and development portfolio, and also monitor and support unit-wide research into new and innovative techniques for discovery and detection of computer network threats Monitor external drivers, and technology trends that are likely to impact the Unit s business and stakeholders. Develop and articulate technical strategic direction for the Unit. Identify and influence growth and business opportunities. Contribute to the success of the wider IAC Directorate Promoting cross-team collaboration and support for operational exchanges between different IACD business units. Participating in both functional (specific skill-sets) and cross-functional (mixed skill-sets) IACD teams at the request of the IACD Executive Team and Leadership Group. Pro-actively demonstrating a willingness to transfer skill sets to other teams when necessary. Personal technical competency is retained. NCSC technical capability and information can be operated with confidence. NCSC remains a leader in the area of Cyber expertise and knowledge within New Zealand. The unit retains a high standard of research and analysis of Cyber threats, which is relevant and aligned to Unit objectives. Directorate-wide objectives are delivered. Customer feedback suggests IACD s performance, through the creation of a more obviously joined-up operating model, has a positive effect Policy and process gaps are highlighted and rectified. Staff retain an active interest in developments within IACD beyond their own unit. Precise performance measures for this position will be developed in discussion between the jobholder and manager as part of the performance development and review process. It UNCLASSIFIED PAGE 5
is also expected that you will undertake other duties that can be reasonably be regarded as relevant to the position, your experience and capability Person specification Qualifications Essential: Tertiary degree at a post-graduate level, or equivalent experience, in Computer Science, Software Engineering or equivalent Respected Professional IT Security industry qualification; CCNA, SANS Desirable Professional computing/networking qualification, e.g. in computer networking, or systems administration Knowledge/experience Essential: Knowledge of computer and network security, and computer network defence, gained through a mixture of commercial and/or GCSB Computer Network Defence experience totalling a minimum of 5 years Experience with network defence and attack tools Intimate knowledge of network protocols Experience in mentoring technical staff. Desirable: UNCLASSIFIED PAGE 6
Personal attributes Teamwork and leadership Excellent analytical, written and oral skills to enable technical and non-technical executive audiences to make informed decisions. Tenacity in seeking the desired outcome Pragmatic Persuasive Collaborative Able to build and maintain effective working relationships with both internal and external stakeholders at all levels of an organisation. Technical troubleshooting Enthusiasm, self-motivation and innovation Proven leadership qualities in a technical environment, and the ability to deal effectively and sensitively with others The ability to represent the GCSB with credit within national and international communities. UNCLASSIFIED PAGE 7