31 Aug
|
Azooa
|
Canberra
? PRINCIPAL ENTERPRISE ARCHITECT – CRYPTOGRAPHIC SERVICES / PKI TECHNICAL LEAD | DFAT | CANBERRA | NV1/NV2
Are you a senior Architect with strong experience across Public Key Infrastructure (PKI), Hardware Security Modules (HSMs), certificate management, key management and associated trust services — holding an active NV1 or higher clearance and available to work onsite in Canberra?
Azooa is preparing a response for RFQ LH-07503 with the Department of Foreign Affairs and Trade (DFAT) and is seeking suitably qualified contractors for a Principal Enterprise Architect – Cryptographic Services / PKI Technical Lead engagement.
This is a senior Principal / EL2-equivalent opportunity within DFAT’s Cyber Security, Cloud and Networks Branch, focused on assessing, enhancing and maturing the Department’s enterprise cryptographic services capability.
? Location: Canberra, ACT
? Working arrangement: 100% onsite – 5 days per week
? Clearance: Active NV1 minimum | NV2 preferred
? Estimated start: 26 October 2026
? Initial term: 12 months
? Extensions: 2 × 12 months
⏰ Maximum hours: 40 hours per week
? Potential tenure: Up to 3 years
ABOUT THE OPPORTUNITY
DFAT’s Cyber Security, Cloud and Networks Branch is responsible for delivering and operating critical cyber security, identity and trust services supporting departmental and business outcomes.
The successful contractor will support the assessment, enhancement and future delivery of DFAT’s enterprise cryptographic capability across areas including:
? Public Key Infrastructure – PKI
? Hardware Security Modules – HSMs
? Certificate lifecycle management
? Cryptographic key management
? Identity and high-assurance trust services
? Security and solution architecture
? Cryptographic governance
? Technical assurance
? Security risk management
? Operational process improvement
? Transition planning
? Future-state service design The role requires a senior technical leader capable of balancing solution architecture, cyber security, governance, policy, operational resilience and practical delivery requirements within a complex Australian Government environment.
CORE RESPONSIBILITIES The successful candidate will provide architectural and technical leadership for the delivery, governance and ongoing evolution of DFAT’s cryptographic services.
Key responsibilities include
• Provide technical leadership across enterprise PKI, HSM and cryptographic services
- Assess current cryptographic capabilities and undertake architecture, security, governance and operational gap analysis
• Define and maintain target-state cryptographic architectures
- Establish appropriate trust models, key-management approaches, security standards and availability requirements
- Develop practical capability improvement roadmaps and future-state plans
- Act as a senior technical authority for cryptographic and security architecture decisions
- Lead solution architecture and detailed technical design
- Ensure secure implementation, deployment and operational practices
- Identify and manage cryptographic risk, technology dependencies and operational resilience requirements
- Develop and maintain cryptographic governance artefacts, policies, standards, procedures and operating models
- Support PKI governance frameworks and certificate-management policies
- Establish security controls, assurance arrangements and risk-management processes
- Work across architecture, cyber security, infrastructure, engineering,
business, project and operational teams
- Support engineering teams through design, build, testing, assurance, release and transition to operations
- Produce architectural artefacts, technical designs, implementation guidance and operational documentation
- Support upgrades, maintenance, testing, issue resolution and continual service improvement
- Provide authoritative advice to technical and non-technical stakeholders
- Mentor engineering and operational personnel and transfer specialist knowledge.
KEY DELIVERABLES
Expected deliverables may include
✅ Current-state cryptographic capability assessments
✅ Architecture, security and operational gap analysis
✅ Target-state cryptographic architectures
✅ PKI architecture artefacts
✅ HSM architecture and integration designs
✅ Trust models
✅ Key-management architectures
✅ Certificate lifecycle-management approaches
✅ Cryptographic capability roadmaps
✅ Future-state service designs
✅ Governance frameworks
✅ Certificate policies / Certification Practice Statements
✅ Security-control and assurance frameworks
✅ Operating models and decision authorities
✅ Security-risk artefacts
✅ Solution architecture documents
✅ Detailed technical designs
✅ Implementation and transition plans
✅ Operational-readiness documentation
✅ Sustainable support models
✅ Knowledge-transfer and capability-uplift materials
ESSENTIAL EXPERIENCE
We are particularly interested in candidates who can demonstrate senior-level experience across:
? Cryptographic Security Architecture
Strong experience assessing, designing or improving enterprise security and cryptographic services involving areas such as:
- Public Key Infrastructure
- Hardware Security Modules
- Certificate lifecycle management
- Cryptographic key management
- Identity and trust services
- High-assurance security environments
You should be comfortable defining current and target-state architectures, identifying technical and governance gaps, developing trust models and security controls, and translating business and security requirements into practical enterprise solutions.
? Governance, Policy & Operating Models
Experience developing sustainable governance arrangements for security, cryptographic, identity or trust services, including:
- Policies and standards
- Certificate policies
- Certification Practice Statements
- Key-management requirements
- Procedures
- Control frameworks
- Assurance arrangements
- Operating models and decision authorities
? Delivery & Operational Readiness
Demonstrated experience across the secure technology lifecycle, including:
- Architecture and design
- Implementation
- Testing
- Security assurance
- Transition to operations
- Continual improvement
- Technical risk and dependency management
- Operational resilience
- Knowledge transfer and capability uplift
? Technical Leadership
You should have experience operating as a senior technical authority and be comfortable:
- Providing authoritative technical advice
- Explaining complex cryptographic issues to technical and non-technical stakeholders
- Resolving competing architecture, security and delivery priorities
- Influencing architecture, engineering, project, procurement and operational stakeholders
- Mentoring personnel and transferring specialist knowledge
HIGHLY DESIRABLE
Experience in one or more of the following would be highly regarded:
⭐ Australian Government or Defence environments
⭐ Enterprise PKI / Certificate Authority environments
⭐ Hardware Security Modules
⭐ Cryptographic key-management technologies
⭐ Australian Government Information Security Manual – ISM
⭐ Gatekeeper PKI Framework
⭐ ICAO Doc 9303 / ICAO Public Key Directory
⭐ PKI supporting ePassports or electronic travel documents
⭐ Biometric identity systems
⭐ Country Signing Certification Authority – CSCA
⭐ Document Signing Certificates
⭐ Certificate Revocation List lifecycle management
⭐ Cryptographic key ceremonies
⭐ Multi-person control
⭐ HSM-based key protection
⭐ Cryptographic disaster recovery and assurance
⭐ Cryptographic agility
⭐ Post-quantum cryptography readiness
⭐ Active NV2 clearance
Candidates with strong adjacent experience across security architecture, cryptographic services, infrastructure architecture, PKI governance, identity and trust, or senior cyber technical leadership are also encouraged to apply where they can demonstrate the required architecture, governance and high-assurance security capability.
SECURITY CLEARANCE
? Minimum: Existing active NV1
? Preferred: Active NV2
Candidates who do not currently hold an active NV1 or higher clearance cannot be submitted for this opportunity.
ENGAGEMENT DETAILS
RFQ: LH-07503
Buyer: Department of Foreign Affairs and Trade
Role: Principal Enterprise Architect – Cryptographic Services / PKI Technical Lead
Level: Principal / EL2 equivalent
Location: Canberra ACT
Arrangement: 100% onsite
Remote working: Not available
Interstate-based candidates: Not being considered
Initial contract: 12 months
Extensions: 2 × 12 months
DFAT also operates a contractor stand-down period during December and January, generally around 4–6 weeks at DFAT’s discretion .
? INDICATIVE RATE GUIDANCE
Based on recent Azooa contract wins and current Federal Government value-for-money positioning , our indicative maximum recommended bidding levels are:
Pty Ltd: up to $160/hour + GST
PAYG: up to $158/hour
These are recommended maximum bidding levels rather than target rates .
Candidates may nominate higher rates; however, rate competitiveness forms part of the overall value-for-money position. Higher rates are more likely to be supportable where the candidate brings exceptional specialist expertise across PKI, HSMs, cryptographic architecture, high-assurance environments, NV2 clearance or closely aligned DFAT/Defence experience .
Senior PKI Architects, Security Architects, Enterprise Architects, Cryptographic Services Architects, PKI Technical Leads, Identity & Trust Architects and HSM/Cryptographic Services specialists are encouraged to apply.
Please also feel free to share this prospect with suitably qualified professionals within your network.
#Azooa #DFAT #CyberSecurity #PKI #Cryptography #EnterpriseArchitecture #SecurityArchitecture #HSM #PublicKeyInfrastructure #CyberSecurityJobs #CanberraJobs #GovernmentJobs #NV1 #NV2 #DefenceJobs #ICTJobs #SolutionArchitecture #InformationSecurity #IdentitySecurity
📌 Cyber Security Architect (Canberra)
🏢 Azooa
📍 Canberra