Senior Systems, Cloud & Security Engineer (Williamstown)

Senior Systems, Cloud & Security Engineer (Williamstown)

06 Aug
|
ZOAK
|
Williamstown

06 Aug

ZOAK

Williamstown

Senior Systems, Cloud & Security Engineer

Melbourne, Victoria — Hybrid arrangement, Full-time, permanent / Contractor, Managing Director

Australian citizenship and eligibility to obtain and maintain an AGVSA security clearance

On-call roster and planned maintenance windows

Position purpose

- The Senior Systems, Cloud & Security Engineer is ZOAK's senior hands‑on technical operator for our mission critical operational environments. The role owns the reliable and secure operation of production services across AWS, Microsoft 365, Google Cloud Platform, which includes Linux / Windows, Serverless, networking, containerised workloads and security / high assurance monitoring.

- The successful candidate must be able to move safely between production operations, complex fault diagnosis, cloud and endpoint administration, code and automation, customer communication, and ISO 27001/ASD ISM-aligned control activities.

ZOAK operating context

- ZOAK designs, builds, operates and secures internet and cloud systems for Australian Government, critical-service, regulated and technology customers. The setting includes:

- A mission‑critical Australian numbering platform operated for a Commonwealth regulator, including a Java application, Oracle Database 19c on AWS RDS, Linux/EC2, Docker Compose, ECR, S3, Secrets Manager, load balancing, DNS/TLS, payment and BDI/SOAP integrations, synthetic monitoring and formal service‑level obligations.

- Multi‑account AWS environments and Microsoft 365 tenants using Entra ID, Intune, Exchange Online, SharePoint Online, Teams, Defender, Purview, Power Platform and privileged‑access controls.

- Linux, Windows and macOS endpoints and servers; Docker‑based services; GitHub‑hosted source, CI/CD and automation; monitoring and vulnerability‑management services.

- ZOAK and customer information security management systems aligned to ISO/IEC 27001:2022, the ASD Information Security Manual, Essential Eight and customer‑specific contractual controls.

- A small consultancy environment in which engineers deal directly with customers, auditors, vendors and senior stakeholders and must take work from diagnosis through to verified closure.

Primary accountabilities

1. Production systems and service ownership

- Operate and maintain customer and ZOAK production services across Linux, Windows, AWS and Microsoft 365.

- Own service health, availability, capacity, patching, backup verification, certificate renewal, lifecycle management and operational readiness.

- Administer the Numbering System application stack, including its EC2 hosts, Docker Compose services, Oracle/RDS dependencies, secrets, container images, integrations and monitoring.

- Diagnose application, operating‑system, network, database and integration faults using logs, metrics, traces, packet captures, system tools and database queries.

- Manage routine operational data tasks, scheduled jobs, queues, file exchanges, email relays and external service integrations.

2. Incident, problem and service‑level management

- Receive and triage alerts and customer‑reported incidents; establish impact, severity, scope and immediate safety constraints.

- Act as technical incident lead when assigned: maintain a timeline, coordinate responders, preserve evidence, restore service safely and communicate status at an appropriate cadence.

- Escalate promptly while retaining ownership through resolution and customer confirmation.

- Produce incident reports, root‑cause analysis, corrective actions and problem records; track actions through verified completion.

- Maintain and test incident, disaster‑recovery and business‑continuity procedures, including AWS/RDS restore testing.

- Contribute accurate availability, incident and SLA data to customer reports.

- Participate in a roster for critical alerts, after‑hours incidents and controlled maintenance.

3. Cloud, platform and network engineering

- Provision, configure and support AWS resources including EC2, RDS, ECR, S3, IAM, Secrets Manager, Systems Manager, CloudWatch, load balancing, Global Accelerator, Route 53 and related network/security controls.

- Maintain VPC/VNet networking, routing,



security groups, DNS, TLS, VPN/overlay connectivity and reverse proxies.

- Implement repeatable infrastructure and configuration using Terraform, CloudFormation, PowerShell, Bash, Go or equivalent tools.

- Improve resilience, observability, cost control and operational simplicity without weakening security or recovery objectives.

- Apply least privilege, separation of duties, protected secret handling and auditable change practices.

4. Microsoft 365 and endpoint administration

- Administer Entra ID, Exchange Online, Intune, SharePoint Online, Teams, Defender, Purview and Power Platform services.

- Manage identity lifecycle, groups, licensing, conditional access, MFA, privileged roles/PIM, device compliance and endpoint configuration.

- Investigate complex endpoint, identity, email, collaboration and security incidents.

- Maintain secure endpoint baselines for Windows and other supported platforms, including update, application‑deployment and Defender controls.

- Automate recurring administration and reporting through Microsoft Graph, PowerShell, APIs and approved workflow tools.

5. Secure software delivery and automation

- Maintain and extend ZOAK and customer software, scripts, integrations and operational tooling.

- Work confidently with Git, pull requests, code review, CI/CD, containers, package registries and release artefacts.

- Support controlled deployments through development, test/OTE and production, including pre‑change checks, database migration review, backups/snapshots, health verification and rollback.

- Write maintainable automation in at least one general‑purpose language and one operational scripting language.

- Maintain or extend automated tests using the tools appropriate to the system, including API, browser/synthetic and integration tests.

- Review AI‑assisted changes as untrusted contributions: understand the change, test it, check security impact and retain human accountability for deployment.

6. Security operations and vulnerability management

- Monitor and triage findings from vulnerability scanners, cloud/security services, endpoint protection and external exposure monitoring.

- Validate findings, assess exploitability and business impact, assign remediation priorities, and verify closure rather than merely reporting scanner output.

- Support network and web‑application security testing using tools such as Nmap, OpenVAS/Greenbone, Snyk, ZAP/Burp or equivalents.

- Investigate suspected security events across identity, endpoint, cloud, email and application sources while preserving evidence and chain of custody where required.

- Maintain hardened configurations and support security patching, secret rotation, certificate lifecycle and access reviews.

- Identify systemic improvements and convert recurring operational failures into durable controls or automation.

7. GRC and assurance support

- Contribute technical evidence and subject‑matter expertise to ZOAK and customer ISMS activities.

- Perform or assist with risk assessments, threat modelling, control design and control‑effectiveness reviews.

- Assist with ISO 27001 internal audits, supplier/security reviews, requirements‑to‑evidence matrices, corrective actions and external audit preparation.

- Interpret ASD ISM, Essential Eight, CIS benchmarks, contractual security requirements and relevant ISO standards in the context of real systems.

- Maintain security plans, operating procedures, continuity/DR artefacts and technical standards so that documentation matches the deployed environment.

- Produce concise monthly or exception‑based security and operational reporting for management and customers.

8. Projects, customers and team capability

- Plan and deliver infrastructure, migration,



security and application tasks to agreed acceptance criteria and timelines.

- Communicate directly with customer technical teams, management, auditors, government stakeholders and suppliers.

- Translate technical risk and incident status into clear business language without overstating certainty.

- Scope work, identify dependencies and risks, estimate effort, and document decisions and handovers.

- Mentor less‑experienced staff and review their technical work.

- Improve ZOAK's reusable tooling, reference architectures and product/service offerings.

Decision authority and escalation

- The role may make reversible operational changes within approved runbooks and delegated change authority.

- Emergency or higher‑risk changes must follow the incident/change process and certain circumstances must be escalated (where they could affect customer commitments, data integrity, recovery capability or regulatory obligations.

- This position takes over delegated technical execution and operational ownership; providing the candidate with self‑directed and unrestricted growth and development opportunities.

Required experience and capability

- Five or more years in systems, cloud, platform, DevOps/SRE or security engineering, including senior responsibility for production services.

- Demonstrated Linux administration and troubleshooting experience, plus competent Windows and Microsoft 365 administration.

- Hands‑on AWS operations experience covering compute, networking, IAM, monitoring, backup/recovery and managed databases.

- Demonstrated incident response: triage, safe restoration, stakeholder communication, evidence capture, root‑cause analysis and corrective action.

- Experience deploying and operating containerised applications and CI/CD pipelines.

- Ability to read and safely modify application code, infrastructure definitions and operational scripts.

- Strong TCP/IP, DNS, HTTP/TLS, email and identity fundamentals.

- Practical understanding of backup, restore, disaster recovery, high availability and recovery testing.

- Security fundamentals covering least privilege, secrets, logging, vulnerability management, secure configuration and common web/application risks.

- Clear written communication and disciplined documentation suitable for customers, auditors and other engineers.

- Self‑directed technical learning, such as maintained repositories, labs, technical writing, certifications / substantial personal projects.

- Australian citizenship and ability to satisfy customer background, confidentiality and AGVSA clearance requirements.

Highly desirable

- Oracle Database/RDS administration or strong experience diagnosing application/database contention and migration issues.

- Java/Spring, Go, PowerShell and Bash experience.

- Terraform and/or CloudFormation; GitHub Actions; Docker/Compose; ECR/GHCR.

- Microsoft Graph, Intune, Defender, Entra Conditional Access/PIM and Exchange Online administration.

- Security testing with Burp Suite, ZAP, Nmap, OpenVAS/Greenbone or Snyk.

- Experience supporting a regulated, government or critical‑service customer under formal SLA and incident‑notification requirements.

- Working knowledge of ISO/IEC 27001:2022, ISO 22301, ASD ISM, Essential Eight, CIS benchmarks or SOC 2.

- Internal‑auditor, AWS, Microsoft, security or networking certifications. Certifications support—but do not substitute for—demonstrated hands‑on capability.

Measures of success - first 12 months

- Critical services have named primary and secondary owners, current runbooks and tested escalation paths.

- Production deployments and common recovery actions are repeatable, peer‑reviewable and have verified rollback paths.

- Alert noise is reduced and high‑value alerts lead to clear, timely action.

- Backup and DR tests produce retained evidence and tracked corrective actions.

- Vulnerability findings have defensible priority, owners, due dates and closure evidence.

- Customer incident and monthly reports are accurate, timely and understandable.

- Material Microsoft 365, AWS and endpoint configurations are documented and increasingly managed as code.

#J-18808-Ljbffr

📌 Senior Systems, Cloud & Security Engineer (Williamstown)
🏢 ZOAK
📍 Williamstown

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior systems, cloud & security engineer (williamstown) / williamstown