Job Title: Security Architect
Security Clearance: Must be able to obtain Negative Vetting Level 1 (NV1)
Duration: Initial 9 months with 2 x 12-month extensions
Industry: Information and Communications Technology (ICT)
Functional Expertise: Cyber Security Architecture
Sub-functional Expertise: Enterprise Security Architecture, Cloud Security, Security Assurance and Accreditation
Location of work: Canberra, ACT
Working arrangements: Hybrid. Candidates are required to work primarily onsite from the Canberra office. Remote work of up to two days per week may be negotiated after six months, subject to approval and applicable home-based work arrangements.
Closing date: 9AM Wednesday, 2 September 2026
Description:
Our client is seeking an experienced Security Architect to design, build and oversee security infrastructure, ensuring systems are resilient against threats. The role will provide security architecture leadership across enterprise ICT solutions, with a strong focus on Microsoft Azure, security assurance, accreditation, governance and compliance.
The successful candidate will have extensive experience delivering enterprise security architecture and cyber security outcomes within large and complex government or regulated environments. The role requires expertise in Australian Government security requirements, cloud security architecture, security operations integration, DevSecOps and stakeholder engagement.
Responsibilities:
- Support the definition of effective ICT security capabilities and solutions to meet capability and business requirements.
- Ensure solutions are fit for purpose from a security perspective and meet relevant security policies, accreditation frameworks and partner compliance requirements.
- Collaborate with enterprise solution and system architects, business stakeholders and delivery teams to drive holistic technology implementation.
- Support architecture strategies covering technology selection, system and solution architecture, development and deployment infrastructure, inter-program collaboration and implementation.
- Design and support implementation of security capabilities including federated Identity and Access Management, gateways and firewalls, Security Information and Event Management (SIEM), intrusion detection and prevention, threat and virus analysis, and encryption at rest and in transit on Azure Cloud.
- Coordinate security accreditation activities and develop key security documentation, including SSP Annex, SSP, SRMP and SOPS.
- Identify and communicate security risks and drivers to stakeholders.
- Identify technology solutions and development initiatives while maintaining a high-level, holistic view of security capabilities.
- Provide leadership to development and business specialists in delivering key security outcomes.
- Design and execute the transition of security management into service.
- Design and document security architecture components within the Technical Security Design.
- Deliver Security Architecture artefacts in accordance with applicable security accreditation frameworks.
- Provide advice supporting architectural decisions relating to technology selection, scope and security solution design.
- Manage architectural security risks, program security risks and security accreditation processes.
- Ensure alignment with enterprise security standards and strategies.
Requirements:
- Demonstrated experience designing and overseeing enterprise-wide ICT security solutions in a multi-agency environment.
- Ability to define programs of work that achieve tangible and measurable business benefits.
- Experience ensuring solutions meet applicable security policies and compliance requirements, including ISM and IRAP.
- Demonstrated ability to develop and manage security architecture technical designs.
- Experience engaging with enterprise security capabilities, including SIEM and SOC.
- Experience designing and supporting security capabilities using Scaled Agile and DevOps methodologies.
- Ability to obtain the required organisational suitability assessment prior to commencement.
- Hold or be willing to obtain an Australian Government NV1 security clearance.
- Ability to comply with applicable confidentiality and non-disclosure requirements prior to commencement.
Key Capabilities:
- Enterprise security architecture and cyber security.
- Microsoft Azure cloud security architecture.
- Protective security, security assurance and compliance.
- Security architecture design and governance.
- Zero Trust and defence-in-depth architecture.
- Security operations integration, including SOC, SIEM and SOAR.
- Threat detection, monitoring, incident response and vulnerability management.
- Agile, DevSecOps and Infrastructure-as-Code security practices.
- Automated security assurance, secure CI/CD, policy-as-code and cloud security guardrails.
- Senior stakeholder engagement and communication.
Essential Criteria:
- Demonstrated cyber security architecture experience
- Minimum 8 years' experience delivering enterprise security architecture and cyber security outcomes in large and complex government or regulated environments.
- Demonstrated ability to lead the design, assurance, and implementation of enterprise-wide ICT security solutions, including development of security roadmaps, architectural standards, and strategic security programs that deliver measurable business outcomes.
- Minimum 5 years' experience in cloud security architecture, including at least 3 years designing and governing security architectures within Microsoft Azure.
- Demonstrated experience designing enterprise-scale Azure environments, including hybrid cloud, multi-environment, and Protected-classification deployments.
- Protective Security and Compliance
- Demonstrated experience designing and assuring solutions that meet Australian Government security requirements, including:
- Information Security Manual (ISM).
- Protective Security Policy Framework (PSPF).
- IRAP assessment and accreditation processes.
- Security accreditation requirements for Protected systems.
- Security requirements associated with Systems of Government Significance and critical business systems.
- Ability to translate security and compliance requirements into practical architecture patterns, controls, and implementation guidance.
- Demonstrated experience designing and assuring solutions that meet Australian Government security requirements, including:
- Security Architecture Design and Governance
- Demonstrated ability to develop, maintain, and govern security architecture artefacts including:
- Target and transitional security architectures.
- Security design documentation.
- Security patterns and standards.
- Threat models and risk assessments.
- Architecture decision records and security exceptions.
- Demonstrated experience designing secure solutions using Azure security capabilities including:
- Microsoft Entra ID.
- Privileged Identity Management (PIM).
- Conditional Access.
- Azure Firewall.
- Private Endpoints.
- Key Vault.
- Microsoft Defender for Cloud.
- Ability to apply Zero Trust principles and defence-in-depth strategies across cloud platforms.
- Demonstrated ability to develop, maintain, and govern security architecture artefacts including:
- Security Operations Integration
- Experience integrating security architecture with enterprise security capabilities, including Security Operations Centres (SOC), SIEM, SOAR, threat detection, monitoring, incident response, and vulnerability management functions.
- DevSecOps and Secure Delivery
- Demonstrated experience embedding security controls within Agile, DevSecOps and Infrastructure-as-Code delivery practices.
- Experience implementing automated security assurance, secure CI/CD pipelines, policy-as-code, and cloud security guardrails.
- Stakeholder Engagement and Communication
- Proven ability to engage effectively with senior executives, enterprise architects, program delivery teams, vendors, security assessors, and operational stakeholders.
- Strong written and verbal communication skills, including the ability to present complex security concepts and risks to both technical and non-technical audiences.
Desirable Criteria:
- Relevant industry and Microsoft certifications, such as:
- Microsoft Certified: Cybersecurity Architect Expert (SC-100).
- Microsoft Certified: Azure Security Engineer Associate (AZ-500).
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305).
- CISSP/CCSP/CISM etc.
- Experience with architecture frameworks and methodologies, including: TOGAF/SABSA/AGAF/NEAF etc.
- Experience supporting IRAP assessments, security accreditation activities, and authority-to-operate (ATO) processes.
- Knowledge of contemporary security frameworks including Zero Trust, NIST Cybersecurity Framework, Essential Eight, and CIS Controls.
How to apply:
Please submit your application including your resume and a completed application form addressing the essential and desirable criteria. Ensure your application highlights your experience and any relevant certifications.
| Job type: | Contract |
|---|---|
| Emp type: | Full-time |
| Pay rate: | negotiable |
| Job published: | 20/08/2026 |