Cyber Security Architect (Canberra)

Cyber Security Architect (Canberra)

02 Oct
|
Resolve Recruit
|
Canberra

02 Oct

Resolve Recruit

Canberra

Talent Sourcing Strategy

Role: Cyber Security Architect (Security Monitoring, Endpoint Security & Security Platforms)

Client: Australian Government Treasury Environment

1. Ideal Candidate Profile

This is not a pure security operations role and not a traditional enterprise architect role.

The ideal candidate sits at the intersection of:

- Cyber Security Architecture
- Security Engineering
- Microsoft Security Stack
- SIEM & Monitoring Architecture
- Government Security Frameworks

Priority Backgrounds

Tier 1 Target Profiles

- Cyber Security Architect
- Security Solutions Architect
- Senior Security Architect
- Lead Security Engineer (Architecture Focus)
- Principal Security Consultant
- Security Platform Architect

Tier 2 Target Profiles

- Detection Engineering Lead
- Security Monitoring Architect
- Security Engineering Manager
- SOC Architect
- Microsoft Security Architect
- Blue Team Technical Lead

Tier 3 Adjacent Profiles

- Infrastructure Security Architect
- Cloud Security Architect
- Endpoint Security Architect
- Identity Security Architect
- Technical Security Lead

2. Must-Have Technical Stack

Security Monitoring / SIEM

Look for:
- Rapid7 InsightIDR
- Microsoft Sentinel
- Splunk
- QRadar
- Elastic SIEM
- ArcSight
- LogRhythm

Keywords:
- SIEM Architecture
- Security Monitoring
- Detection Engineering
- Threat Detection
- Threat Hunting
- Log Management
- Security Telemetry
- Windows Event Collection
- Security Analytics

Microsoft Security Ecosystem

Critical:
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Purview
- Microsoft Defender XDR
- Microsoft Security Suite

Strong indicators:
- Security Operations integration
- Sensor deployment
- Agent architecture
- Endpoint telemetry
- EDR
- Attack Surface Reduction

Infrastructure Security

Look for:
- Endpoint Hardening
- Server Hardening
- Vulnerability Management
- Security Baselines
- Administrative Workstations
- Security Configuration Management

Potential tools:
- Tenable
- Qualys
- Rapid7 Vulnerability Management
- Defender Vulnerability Management

Cloud Security

Desired:
- Azure Security
- Azure Monitor
- Log Analytics
- Microsoft Defender for Cloud
- Azure Landing Zones

3. Government Experience Targeting





This requirement strongly favours candidates who understand Australian Government security frameworks.

Prioritise

Federal Government

- Treasury
- Finance
- Home Affairs
- Defence
- Services Australia
- ATO
- Health
- Human Services
- PM&C;

Intelligence and National Security

- ASD
- ASIO
- ACIC
- AFP

Large Federal Integrators

- Accenture Federal
- Leidos
- KBR
- Novon
- Telstra Purple
- DXC
- Fujitsu
- Datacom
- NEC
- Deloitte
- PwC
- EY
- KPMG

4. Clearance Strategy

Ideal

- NV1 Active

Acceptable

- Baseline
- NV1 Expired
- NV2

Avoid making active clearance mandatory early in the search due to the niche skill combination.

5. Screening Questions

Security Monitoring

Describe the largest SIEM environment you have architected or uplifted. What log sources, telemetry pipelines and integrations were involved?

Microsoft Security

Have you designed or governed Microsoft Defender for Endpoint and Defender for Identity deployments? What was your involvement in architecture, onboarding and integration?

Architecture

Can you provide examples of architecture artefacts you personally created?

Look for

- HLDs
- LLDs
- Data-flow diagrams
- ADRs
- Roadmaps

Government Frameworks

How have you applied:
- ISM
- PSPF
- Essential Eight

to architecture decisions rather than simply compliance reporting?

Leadership

Tell me about a time you challenged a vendor recommendation because it did not fit the client's environment.

Robust candidates will have real examples.

6. Candidate Red Flags

Too Operational

Candidates whose experience is:

- Incident response only
- SOC analyst only
- Security operations only
- Threat hunting only

without architecture ownership.

Too Infrastructure Focused

Candidates who are:
- Infrastructure Architects
- Azure Architects
- Network Architects

with minimal security platform ownership.

Compliance Heavy

Candidates focused on:
- Governance
- Risk
- Auditing





without hands-on technical security design experience.

7. Boolean Search Strategy

Broad Search

("Cyber Security Architect" OR "Security Architect" OR "Security Solutions Architect") AND (SIEM OR Sentinel OR Splunk OR Rapid7) AND (Defender OR "Microsoft Security")

Microsoft Security Focus

("Security Architect" OR "Security Engineer") AND ("Defender for Endpoint" OR MDE) AND ("Defender for Identity" OR MDI)

SIEM Focus

("Security Architect" OR "Detection Engineer") AND (SIEM OR Sentinel OR Splunk OR Rapid7) AND (monitoring OR telemetry OR logging)

Government Focus

("Security Architect" OR "Cyber Security Architect") AND (ISM OR PSPF OR "Essential Eight") AND (government OR federal OR defence)

Architecture Focus

("Security Architect") AND (HLD OR LLD OR "architecture decision record" OR roadmap) AND (security)

8. Talent Pools to Target

Pool 1 (Highest Priority)

Cyber Security Architects with:
- Microsoft Defender
- Sentinel/Rapid7
- Government Security Frameworks
- NV1 Clearance

Expected market size in Canberra: Small but highly relevant.

Pool 2

Senior Security Engineers transitioning into architecture with:
- Defender
- SIEM
- Azure Security

Likely strongest sourcing channel.

Pool 3

Consulting Architects from:
- Deloitte
- PwC
- EY
- KPMG
- Accenture
- Leidos
- Fujitsu
- DXC

Often have the architecture artefact and stakeholder experience sought in the criteria.

Recruitment Pitch

"Treasury is seeking a hands-on Cyber Security Architect to lead the design and uplift of enterprise security monitoring, Microsoft Defender capabilities, endpoint security and cyber platforms. The role combines architecture leadership with deep technical analysis, requiring someone who can move from high-level design and security strategy into log pipelines, telemetry, integrations, hardening standards and platform rationalisation. This is ideal for a security architect who enjoys owning technical outcomes rather than producing architecture documentation alone."

Most likely successful candidate profile: A Senior Security Architect or Lead Security Engineer from a Federal Government department, major consultancy, or systems integrator with deep Defender, Sentinel/Rapid7 and ISM/Essential Eight experience.

📌 Cyber Security Architect (Canberra)
🏢 Resolve Recruit
📍 Canberra

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber security architect (canberra) / canberra

Subscribe to this job alert:

Get the latest job offers by email for: cyber security architect (canberra) / canberra