LH-07687
6 months
Lead - EL1 equivalent
The Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts is looking for a Cyber Security Engineer to join its Information Technology and Data Division. You'll provide hands-on security engineering, professional advice and assurance across a portfolio of Digital Strategy projects spanning cloud identity and access management with Microsoft Entra ID, SharePoint Online records management, resilience for remote and regional systems, Azure DevOps pipeline security and code assurance, and emerging Azure Foundry and AI accelerator technologies. This is a build-and-implement role rather than a policy one. You'll design secure technology patterns, configure and validate controls, remediate gaps, and produce the implementation artefacts that carry each solution through testing, deployment, transition to operations and ongoing maintenance. You'll work alongside delivery teams to embed security gates, automated scanning and secure release practices into their existing ways of working, and you'll engineer secure patterns for identity, access and data protection in regional operating environments. Throughout, you'll implement controls and capture evidence against Australian Government cyber security requirements including the ISM, PSPF, Essential Eight, privacy, data protection and supply chain security obligations.
• Implement secure technology patterns across Digital Strategy projects, including solution configuration, control implementation, testing, deployment support, transition to operations and operational readiness activities • Build, configure and validate security controls, remediate agreed gaps and produce implementation artefacts that support practical delivery, handover and ongoing maintenance • Implement secure SharePoint Online records management capabilities, including access models, retention and information protection settings, secure site patterns and integration with operational records processes • Configure Microsoft Entra ID capabilities for secure authentication, authorisation and access governance, including conditional access, application access patterns and integration with cloud services • Implement Azure DevOps pipeline security and code assurance capabilities, including automated scanning, security gates, remediation workflows and secure release practices aligned to delivery teams' ways of working • Engineer secure implementation patterns for Azure Foundry, AI accelerator and emerging technology solutions • Develop strategies for identity, access, data protection and deployment considerations for remote and regional operating environments • Implement controls and capture evidence against relevant Australian Government cyber security requirements, including the ISM, PSPF, Essential Eight, privacy, data protection and supply chain security obligations
Onsite. The worker must be in the office at least 3 days a week, and must start and finish work within standard working hours (7am to 7pm).
Candidate Capability and Technical Fit The extent to which you meet the specified technical requirements. Relevant Experience on EDRMS, RAN and Regional Infrastructure Uplift projects Demonstrated experience in: • Enterprise security engineering and/or architecture • Design and implementation of Entra ID Suite security and access management capabilities • Applying the ISM, PSPF and Essential Eight to enterprise information systems • Embedding security into low-code/RAD platforms • Cloud security across Azure/AWS/M365 as well as AI and Foundry resources
Each candidate must upload a one page pitch addressing all criteria specified. This includes responding to the Job Details, Key Responsibilities, and Essential Criteria. The pitch cannot be more than 5000 characters. Structure the pitch using the STAR format (Situation, Task, Action, Result) so each example shows what you did and what changed as a result. Sell your capability rather than listing duties: lead with the outcomes you delivered. Target the two Essential Criteria directly, with concrete instances of Entra ID security and access management design, applying the ISM, PSPF and Essential Eight to enterprise systems, embedding security into low-code or RAD platforms, and cloud security across Azure, M365 and AI or Foundry resources. Where you have worked on EDRMS, records management or regional infrastructure uplift projects, name them.
About Us
We are a team of professionals committed to delivering excellence in government projects. We offer transparent commissions so you can maximise your rate and growth in the role.
How to Apply
Please submit your application via the form below. We will reach out to you if you are suitable for the role.