Principal Enterprise Architect (Cryptography) (Australian Capital Territory)

Principal Enterprise Architect (Cryptography) (Australian Capital Territory)

10 Sep
|
IT Alliance Australia
|
Australian Capital Territory

10 Sep

IT Alliance Australia

Australian Capital Territory

One of our Federal Government Clients is seeking to engage a Principal Enterprise Architect (Cryptography) – EL2

Please check below all the job details:

1. Contract Duration: 03 Years (12 Months initially + 24 Months extension)
2. Work Location: Canberra - purely Onsite 5 days office
3. Eligibility: You must need to have NV1 Security Clearance or above.
4. Tentative Start Date: 26th Oct 2026
5. Working Hours: 8 hours a day/ 40 hours a week

Key duties and responsibilities:

- The Department is seeking a Technical Lead to provide architectural leadership for the delivery, governance and ongoing evolution of enterprise cryptographic services, including Public Key Infrastructure (PKI), Hardware Security Modules (HSMs), certificate management, key management and related security capabilities. The role will be responsible for supporting both the technical and governance aspects of cryptographic capability uplift across the Department.
- The role will work across business, architecture, engineering and operational teams to assess current capabilities, identify improvement opportunities, develop future-state architectures, establish governance frameworks and support delivery outcomes. The successful candidate will provide technical leadership across multiple initiatives, balancing strategic planning, security risk management, policy development with practical implementation activities within a complex and highly regulated workplace.
- In addition to technical architecture responsibilities, the role will support the development and maintenance of governance artefacts including standards, policies, procedures, operating models and assurance processes required for the effective management of cryptographic services. This includes working collaboratively with business analysts, project resources and operational teams to define sustainable processes, controls and service management practices that underpin the secure operation of PKI and related trust services.
- DFAT recognises that deep PKI expertise is a specialised capability. As such, applications are encouraged from candidates with strong experience in cryptographic services, PKI governance, security architecture, infrastructure architecture, cryptography or related technical leadership disciplines. Candidates should be able to demonstrate experience balancing technical solution design with governance, policy and procedural requirements in security-sensitive or regulated environments.

Key responsibilities and duties:

- Provide technical leadership for the design, delivery and ongoing operation of enterprise PKI, HSM and cryptographic services.
- Lead the development and maintenance of cryptographic governance artefacts, including policies, standards, procedures, operating models and security risk management processes to support the secure operation of PKI and related trust services.
- Define, govern and maintain target cryptographic architectures, including trust models, key management approaches,



availability requirements and security standards.
- Assess current capabilities and conduct gap analysis activities to support roadmap development, business cases and future-state planning.
- Act as a senior technical authority for cryptographic and security architecture decisions, engaging with stakeholders across business, project and operational teams.
- Lead solution architecture and detailed technical design activities, ensuring secure implementation, deployment and operational practices.
- Identify and manage cryptographic risks, platform dependencies and operational resilience requirements.
- Support engineering teams through design, build, testing, release and transition-to-operations activities.
- Produce and maintain architectural artefacts, technical designs, operational documentation and implementation guidance.
- Support the ongoing operation and improvement of cryptographic services, including upgrades, maintenance, testing and issue resolution.
- Ensure services align with organisational security policies, government standards and industry best practice.
- Provide technical mentoring, knowledge transfer and capability uplift across engineering and operational teams.

Essential Criteria:

Cryptographic Security Architecture

Demonstrated experience leading the assessment, architecture and improvement of enterprise security or cryptographic services, such as Public Key Infrastructure, Hardware Security Modules, certificate lifecycle management, key management, identity or other high-assurance trust services.

The candidate should demonstrate the ability to:

1. Assess current-state capabilities and identify architectural, security, operational and governance gaps.
2. Define target-state architectures, trust models, security controls and practical improvement roadmaps.
3. Translate business, security and operational requirements into secure, supportable and proportionate solutions; and
4. Apply relevant government or industry security standards and risk-management practices within complex enterprise environments.

Governance, Policy and Operating Model Design

1. Demonstrated experience developing and implementing governance arrangements for security, cryptographic, identity or trust services.
2. This should include experience producing or improving artefacts such as policies, standards, certificate policies, certification practice statements, key-management requirements, procedures, control frameworks, assurance arrangements, operating models and decision authorities.
3. The candidate should demonstrate an ability to translate business,



regulatory, security and operational requirements into clear, sustainable and auditable controls and processes.

Delivery, Transition and Operational Readiness Demonstrated experience leading or supporting secure technology services across the delivery lifecycle, including design, implementation, testing, assurance, transition to operations and continual improvement.

The candidate should demonstrate experience:

1. Managing technical risks, dependencies and operational resilience requirements;
2. Developing architecture, design, implementation and operational documentation;
3. Working with engineering and operational teams to establish maintainable support arrangements; and
4. Supporting knowledge transfer, service transition and capability uplift.

Technical Leadership and Stakeholder Engagement Demonstrated experience operating as a senior technical authority in a complex, multidisciplinary environment.

The candidate should demonstrate the ability to:

1. Provide authoritative and pragmatic technical advice.
2. Communicate complex security and cryptographic matters to technical and non-technical stakeholders.
3. Resolve competing architectural, security, delivery and operational priorities.
4. Influence business, architecture, engineering, project, procurement and operational stakeholders; and
5. Mentor personnel and transfer specialist knowledge to internal teams.

Desirable Criteria: Government and High-Assurance Cryptographic Services. Experience in one or more of the following will be highly regarded:

1. Delivering or governing cryptographic, PKI, identity or trust services in Australian Government, Defence or another regulated or high-assurance environment.
2. Enterprise PKI, Certificate Authority, HSM, key-management or certificate-lifecycle-management technologies.
3. The Australian Government Information Security Manual, Gatekeeper PKI Framework, ICAO Doc 9303, ICAO Public Key Directory arrangements, or comparable security and trust frameworks.
4. PKI supporting epassports, electronic travel documents, biometric identity systems or other highassurance credentials.
5. CSCA, Document Signing Certificate and Certificate Revocation List lifecycle management.
6. Cryptographic key ceremonies, multi-person control, HSM-based key protection, disaster recovery and cryptographic assurance.
7. Current-state assessment, target-state architecture, operating-model development, technology roadmaps, requirements definition or procurement support for a cryptographic capability uplift.
8. Cryptographic agility or post-quantum cryptography readiness assessment.

The Next step is easy: If you are interested, you may send an email to [email protected] Referral incentive program: As always, we have the candidate referral incentive program through which you will get $1000 for each successful referral after the successful selection and joining of the referred candidates

📌 Principal Enterprise Architect (Cryptography) (Australian Capital Territory)
🏢 IT Alliance Australia
📍 Australian Capital Territory

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: principal enterprise architect (cryptography) (australian capital territory) / australian capital territory

Subscribe to this job alert:

Get the latest job offers by email for: principal enterprise architect (cryptography) (australian capital territory) / australian capital territory