- Detection Engineering Lead
- Security Monitoring Architect
- Security Engineering Manager
- SOC Architect
- Microsoft Security Architect
- Blue Team Technical Lead
Desired:
- Azure Security
- Azure Monitor
- Log Analytics
- Microsoft Defender for Cloud
- Azure Landing Zones
3. Government Experience Targeting
This requirement strongly favours candidates who understand Australian Government security frameworks.
Prioritise
Federal Government
- Treasury
- Finance
- Home Affairs
- Defence
- Services Australia
- ATO
- Health
- Human Services
- PM&C;
Intelligence and National Security
- ASD
- ASIO
- ACIC
- AFP
Large Federal Integrators
- Accenture Federal
- Leidos
- KBR
- Novon
- Telstra Purple
- DXC
- Fujitsu
- Datacom
- NEC
- Deloitte
- PwC
- EY
- KPMG
4. Clearance Strategy
Ideal
- NV1 Active
Acceptable
- Baseline
- NV1 Expired
- NV2
Avoid making active clearance mandatory early in the search due to the niche skill combination.
5. Screening Questions
Security Monitoring
Describe the largest SIEM environment you have architected or uplifted. What log sources, telemetry pipelines and integrations were involved?
Microsoft Security
Have you designed or governed Microsoft Defender for Endpoint and Defender for Identity deployments? What was your involvement in architecture, onboarding and integration?
Architecture
Can you provide examples of architecture artefacts you personally created?
Candidates focused on:
- Governance
- Risk
- Auditing
without hands-on technical security design experience.
7. Boolean Search Strategy
Broad Search
("Cyber Security Architect" OR "Security Architect" OR "Security Solutions Architect") AND (SIEM OR Sentinel OR Splunk OR Rapid7) AND (Defender OR "Microsoft Security")
Microsoft Security Focus
("Security Architect" OR "Security Engineer") AND ("Defender for Endpoint" OR MDE) AND ("Defender for Identity" OR MDI)
SIEM Focus
("Security Architect" OR "Detection Engineer") AND (SIEM OR Sentinel OR Splunk OR Rapid7) AND (monitoring OR telemetry OR logging)
Government Focus
("Security Architect" OR "Cyber Security Architect") AND (ISM OR PSPF OR "Essential Eight") AND (government OR federal OR defence)
Architecture Focus
("Security Architect") AND (HLD OR LLD OR "architecture decision record" OR roadmap) AND (security)
8. Talent Pools to Target
Pool 1 (Highest Priority)
Cyber Security Architects with:
- Microsoft Defender
- Sentinel/Rapid7
- Government Security Frameworks
- NV1 Clearance
Expected market size in Canberra: Small but highly relevant.
Often have the architecture artefact and stakeholder experience sought in the criteria.
Recruitment Pitch
"Treasury is seeking a hands-on Cyber Security Architect to lead the design and uplift of enterprise security monitoring, Microsoft Defender capabilities, endpoint security and cyber platforms. The role combines architecture leadership with deep technical analysis, requiring someone who can move from high-level design and security strategy into log pipelines, telemetry, integrations, hardening standards and platform rationalisation. This is ideal for a security architect who enjoys owning technical outcomes rather than producing architecture documentation alone."
Most likely successful candidate profile: A Senior Security Architect or Lead Security Engineer from a Federal Government department, major consultancy, or systems integrator with deep Defender, Sentinel/Rapid7 and ISM/Essential Eight experience.