Lead Cyber Security Adviser

Location: ACT
Security Clearance: Negative Vetting 1 (NV1)
Contract Period: 6 months + 2 × 6 month extensions
Closing: 11:59pm Wednesday 9 September 2026

Current and former ADF personnel encouraged to apply

The Opportunity:

The Information Technology and Data Division (ITDD) requires a Cyber Security Engineer to provide professional advice, assurance and hands-on support across Digital Strategy projects, including:

  • Cloud identity and access management using Microsoft Entra ID

  • Records management (SharePoint Online)

  • Remote and regional system resilience

  • Azure DevOps pipelines and code assurance capabilities

  • Azure Foundry and AI accelerator technologies

Key Duties and Responsibilities:

The Cyber Security Engineer will be required to perform the following work:

  • Implement secure technology patterns across Digital Strategy projects, including solution configuration, control implementation, testing, deployment support, transition to operations and operational readiness activities.

  • Build, configure and validate security controls, remediate agreed gaps and produce implementation artefacts that support practical delivery, handover and ongoing maintenance.

  • Implement secure SharePoint Online records management capabilities, including access models, retention and information protection settings, secure site patterns and integration with operational records processes.

  • Configure Microsoft Entra ID capabilities for secure authentication, authorization and access governance, including conditional access, application access patterns and integration with cloud services.

  • Implement Azure DevOps pipeline security and code assurance capabilities, including automated scanning, security gates, remediation workflows and secure release practices aligned to delivery teams’ ways of working.

  • Engineer secure implementation patterns for Azure Foundry, AI accelerator and emerging technology solutions.

  • Develop strategies for identity, access, data protection and deployment considerations for remote and regional operating environments.

  • Implement controls and capture evidence against relevant Australian Government cyber security requirements, including the ISM, PSPF, Essential Eight, privacy, data protection and supply chain security obligations.

Essential Technical skills:

Practical experience configuring Microsoft Entra ID, conditional access, application access patterns, cloud service integrations and secure authentication/authorisation models.

Security control implementation and assurance: Ability to build, configure, test and validate security controls, remediate gaps, produce implementation artefacts and support transition to operations. Working knowledge of the ISM, PSPF, Essential Eight, privacy, data protection and supply chain obligations.

Ready to Learn More?

If you have the skills and experience we're looking for and would like to learn more about this opportunity, we'd love to hear from you.


Previous
Previous

Senior Orbus iServer System Administrator

Next
Next

Lead Microservices and AI Technical Architect