28 Aug
|
Talent
|
Canberra
Canberra, ACT - primarily onsite with hybrid arrangements available
Contract until 30 June **** + 2 x 12-month extension options
NV1 clearance required
Position Overview
An opportunity is available for an experiencedSecurity Architectto support a significant Federal Government technology program delivering secure, resilient and enterprise-scale ICT capabilities.
The Security Architect will play a key role in defining, designing and overseeing security architecture across the program, with a strong focus onMicrosoft Azure, enterprise security, security accreditation and Australian Government security requirements.
Working closely with solution and system architects, delivery teams, security specialists and senior stakeholders, you will help ensure security is embedded throughout the design, development and transition of critical technology capabilities.
Key Duties
Design and oversee the implementation of enterprise-wide ICT security solutions.
Develop and maintain security architecture, technical designs, security patterns, standards and roadmaps.
Design and support security capabilities acrossMicrosoft Azure, including hybrid and PROTECTED environments.
Ensure solutions align withISM, PSPF, IRAP and relevant security accreditation requirements.
Design security capabilities coveringidentity and access management, gateways, firewalls, SIEM, intrusion detection and prevention, threat analysis and encryption.
Integrate security architecture with enterpriseSOC, SIEM, SOAR, monitoring, incident response and vulnerability managementcapabilities.
ApplyZero Trustand defence-in-depth principles across cloud environments.
Embed security controls withinAgile, DevSecOps, Infrastructure-as-Code and CI/CDdelivery practices.
Coordinate security accreditation activities and develop supporting security documentation and architecture artefacts.
Identify and manage architectural and program security risks.
Provide security architecture advice to support technology selection, solution design and implementation decisions.
Work collaboratively with senior stakeholders, enterprise architects, delivery teams, vendors and security assessors.
Support the transition of security capabilities into operational service.
Skills and Experience Required
Minimum 8 years' experiencedelivering enterprise security architecture and cyber security outcomes within large and complex government or regulated environments.
Demonstrated experience leading the design, assurance and implementation of enterprise-wide ICT security solutions.
Experience developing security roadmaps, architecture standards and strategic security programs.
Minimum 5 years' experience in cloud security architecture, including at least3 years designing and governing security architecture within Microsoft Azure.
Demonstrated experience designing enterprise-scale Azure environments, includinghybrid cloud,
multi-workplace and PROTECTED-classification deployments.
Strong knowledge and practical experience withISM, PSPF, IRAP assessment and security accreditation processes.
Experience translating security and compliance requirements into practical architecture patterns, controls and implementation guidance.
Strong Azure security capability, including experience withMicrosoft Entra ID, Privileged Identity Management (PIM), Conditional Access, Azure Firewall, Private Endpoints, Key Vault and Microsoft Defender for Cloud.
Experience developing and governing security architecture artefacts, including target and transitional architectures, technical security designs, threat models, risk assessments, architecture decisions and security exceptions.
Experience integrating security architecture withSOC, SIEM, SOAR, threat detection, monitoring, incident response and vulnerability management.
Experience embedding security withinAgile and DevSecOps environments, including secure CI/CD, automated security assurance, policy-as-code and cloud security guardrails.
Strong stakeholder engagement and communication skills, with the ability to communicate complex security risks and concepts to technical and non-technical audiences.
Relevant Microsoft or security certifications such asSC-100, AZ-500, AZ-305, CISSP, CCSP or CISMwill be highly regarded.
Experience with architecture frameworks such asTOGAF, SABSA, AGAF or NEAFwill be highly regarded.
Knowledge ofZero Trust, Essential Eight, NIST Cybersecurity Framework and CIS Controlswill be highly regarded.
#J-*****-Ljbffr
📌 Security Architect (Canberra)
🏢 Talent
📍 Canberra