Security Architect
- Canberra, ACT – primarily onsite with hybrid arrangements available
- Contract until 30 June 2027 + 2 x 12-month extension options
- NV1 clearance required
Position Overview
An opportunity is available for an experienced Security Architect to support a significant Federal Government technology program delivering secure, resilient and enterprise-scale ICT capabilities.
The Security Architect will play a key role in defining, designing and overseeing security architecture across the program, with a strong focus on Microsoft Azure, enterprise security, security accreditation and Australian Government security requirements. Working closely with solution and system architects, delivery teams, security specialists and senior stakeholders, you will help ensure security is embedded throughout the design, development and transition of critical technology capabilities.
Key Duties
-
- Design and oversee the implementation of enterprise-wide ICT security solutions.
- Develop and maintain security architecture, technical designs, security patterns, standards and roadmaps.
- Design and support security capabilities across Microsoft Azure, including hybrid and PROTECTED environments.
- Ensure solutions align with ISM, PSPF, IRAP and relevant security accreditation requirements.
- Design security capabilities covering identity and access management, gateways, firewalls, SIEM, intrusion detection and prevention, threat analysis and encryption.
- Integrate security architecture with enterprise SOC, SIEM, SOAR, monitoring, incident response and vulnerability management capabilities.
- Apply Zero Trust and defence-in-depth principles across cloud environments.
- Embed security controls within Agile, DevSecOps, Infrastructure-as-Code and CI/CD delivery practices.
- Coordinate security accreditation activities and develop supporting security documentation and architecture artefacts.
- Identify and manage architectural and program security risks.
- Provide security architecture advice to support technology selection, solution design and implementation decisions.
- Work collaboratively with senior stakeholders, enterprise architects, delivery teams, vendors and security assessors.
- Support the transition of security capabilities into operational service.
Skills and Experience Required
- Minimum 8 years’ experience delivering enterprise security architecture and cyber security outcomes within large and complex government or regulated environments.
- Demonstrated experience leading the design, assurance and implementation of enterprise-wide ICT security solutions.
- Experience developing security roadmaps, architecture standards and strategic security programs.
- Minimum 5 years’ experience in cloud security architecture, including at least 3 years designing and governing security architecture within Microsoft Azure.
- Demonstrated experience designing enterprise-scale Azure environments, including hybrid cloud, multi-environment and PROTECTED-classification deployments.
- Strong knowledge and practical experience with ISM, PSPF, IRAP assessment and security accreditation processes.
- Experience translating security and compliance requirements into practical architecture patterns, controls and implementation guidance.
- Strong Azure security capability, including experience with Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access, Azure Firewall, Private Endpoints, Key Vault and Microsoft Defender for Cloud.
- Experience developing and governing security architecture artefacts, including target and transitional architectures, technical security designs, threat models, risk assessments, architecture decisions and security exceptions.
- Experience integrating security architecture with SOC, SIEM, SOAR, threat detection, monitoring, incident response and vulnerability management.
- Experience embedding security within Agile and DevSecOps environments, including secure CI/CD, automated security assurance, policy-as-code and cloud security guardrails.
- Strong stakeholder engagement and communication skills, with the ability to communicate complex security risks and concepts to technical and non-technical audiences.
- Relevant Microsoft or security certifications such as SC-100, AZ-500, AZ-305, CISSP, CCSP or CISM will be highly regarded.
- Experience with architecture frameworks such as TOGAF, SABSA, AGAF or NEAF will be highly regarded.
- Knowledge of Zero Trust, Essential Eight, NIST Cybersecurity Framework and CIS Controls will be highly regarded.
Application Process
If you would like to apply, please contact Emma on 0480 804 408 or email emma.gibbons@talentinternational.com
- For over 30 years Talent has been redefining the contracting experience with industry leading support, exclusive contractor benefits & a world-class digital platform ENGAGE to access it all. Apply today to see how we can elevate your career