LH-07503
12 months
Principal - EL2 equivalent
You'll be the Technical Lead for a program of work in DFAT's Cyber Security, Cloud and Networks Branch focused on assessing, enhancing and maturing the Department's cryptographic services capability: Public Key Infrastructure (PKI), Hardware Security Modules (HSMs), certificate and key management, and related trust services. The work spans capability assessment, architecture development, documentation uplift, operational process improvement, transition planning and future-state service design. You'll identify capability gaps, develop practical and sustainable solutions, and improve the maturity and long-term sustainability of cryptographic services across the Department. Alongside the architecture, you'll shape how these services are governed: PKI governance frameworks, certificate management policies, operational procedures, security controls and risk management processes. You'll work with business analysts, project resources, engineering and operational teams to establish governance, procedural and assurance practices that support the secure operation of cryptographic services in a regulated, security-sensitive environment. DFAT recognises deep PKI expertise is a specialised capability, and welcomes candidates from cryptographic services, PKI governance, security architecture, infrastructure security, cryptography or related technical leadership backgrounds who can balance technical solution design with governance, policy and procedural controls.
• Provide technical leadership for the design, delivery and ongoing operation of enterprise PKI, HSM and cryptographic services • Lead the development and maintenance of cryptographic governance artefacts, including policies, standards, procedures, operating models and security risk management processes • Define, govern and maintain target cryptographic architectures, including trust models, key management approaches, availability requirements and security standards • Assess current capabilities and conduct gap analysis to support roadmap development, business cases and future-state planning • Act as a senior technical authority for cryptographic and security architecture decisions, engaging stakeholders across business, project and operational teams • Lead solution architecture and detailed technical design activities, ensuring secure implementation, deployment and operational practices • Identify and manage cryptographic risks, platform dependencies and operational resilience requirements • Support engineering teams through design, build, testing, release and transition-to-operations activities • Produce and maintain architectural artefacts, technical designs, operational documentation and implementation guidance • Support the ongoing operation and improvement of cryptographic services, including upgrades, maintenance, testing and issue resolution • Ensure services align with organisational security policies, government standards and industry best practice • Provide technical mentoring, knowledge transfer and capability uplift across engineering and operational teams
SFIA skills and levels: • Strategy and Architecture - Strategy and Planning - Solution Architecture (ARCH) - Level 6 • Strategy and Architecture - Security and Privacy - Information Security (SCTY) - Level 6 • Strategy and Architecture - Advice and Guidance - Specialist Advice (TECH) - Level 6
Onsite. Canberra based, 5 days in the office. Remote and interstate candidates will not be considered.
1. Cryptographic Security Architecture Demonstrated experience leading the assessment, architecture and improvement of enterprise security or cryptographic services, such as Public Key Infrastructure, Hardware Security Modules, certificate lifecycle management, key management, identity or other high-assurance trust services. Demonstrate the ability to: (a) assess current-state capabilities and identify architectural, security, operational and governance gaps; (b) define target-state architectures, trust models, security controls and practical improvement roadmaps; (c) translate business, security and operational requirements into secure, supportable and proportionate solutions; and (d) apply relevant government or industry security standards and risk-management practices within complex enterprise environments. 2. Governance, Policy and Operating Model Design Demonstrated experience developing and implementing governance arrangements for security, cryptographic, identity or trust services, including producing or improving policies, standards, certificate policies, certification practice statements, key-management requirements, procedures, control frameworks, assurance arrangements, operating models and decision authorities. Demonstrate an ability to translate business, regulatory, security and operational requirements into clear, sustainable and auditable controls and processes. 3. Delivery, Transition and Operational Readiness Demonstrated experience leading or supporting secure technology services across the delivery lifecycle, including design, implementation, testing, assurance, transition to operations and continual improvement. Demonstrate experience: (a) managing technical risks, dependencies and operational resilience requirements; (b) developing architecture, design, implementation and operational documentation; (c) working with engineering and operational teams to establish maintainable support arrangements; and (d) supporting knowledge transfer, service transition and capability uplift. 4. Technical Leadership and Stakeholder Engagement Demonstrated experience operating as a senior technical authority in a complex, multidisciplinary environment. Demonstrate the ability to: (a) provide authoritative and pragmatic technical advice; (b) communicate complex security and cryptographic matters to technical and non-technical stakeholders; (c) resolve competing architectural, security, delivery and operational priorities; (d) influence business, architecture, engineering, project, procurement and operational stakeholders; and (e) mentor personnel and transfer specialist knowledge to internal teams.
1. Government and High-Assurance Cryptographic Services Experience in one or more of the following will be highly regarded: (a) delivering or governing cryptographic, PKI, identity or trust services in Australian Government, Defence or another regulated or high-assurance environment; (b) enterprise PKI, Certificate Authority, HSM, key-management or certificate-lifecycle-management technologies; (c) the Australian Government Information Security Manual, Gatekeeper PKI Framework, ICAO Doc 9303, ICAO Public Key Directory arrangements, or comparable security and trust frameworks; (d) PKI supporting ePassports, electronic travel documents, biometric identity systems or other high-assurance credentials; (e) CSCA, Document Signing Certificate and Certificate Revocation List lifecycle management; (f) cryptographic key ceremonies, multi-person control, HSM-based key protection, disaster recovery and cryptographic assurance; (g) current-state assessment, target-state architecture, operating-model development, technology roadmaps, requirements definition or procurement support for a cryptographic capability uplift; and (h) cryptographic agility or post-quantum cryptography readiness assessment.
Each candidate must upload a one page pitch addressing all criteria specified. This includes responding to the Job Details, Key Responsibilities, and Essential Criteria. The pitch cannot be more than 5000 characters. Structure the pitch using the STAR format (Situation, Task, Action, Result). Sell your capability rather than listing duties: for each essential criterion, describe a specific cryptographic or PKI engagement, what you were accountable for, the architecture and governance decisions you made and the outcome. Target the criteria directly, in particular the SFIA Level 6 capabilities named in the role (Solution Architecture, Information Security and Specialist Advice), and name the PKI, HSM, certificate and key-management technologies and the frameworks (ISM, Gatekeeper, ICAO) you have worked with. State your current security clearance level clearly.
About Us
We are a team of professionals committed to delivering excellence in government projects. We offer transparent commissions so you can maximise your rate and growth in the role.
How to Apply
Please submit your application via the form below. We will reach out to you if you are suitable for the role.