Back to job board
ContractArchitecture

Principal Enterprise Architect

Location
Canberra, Australian Capital Territory
Clearance
Active NV1
Rate / salary
On application
Applications close
2026-09-11
Role detail

About this opportunity

One of our federal clients is seeking an experienced Principal Enterprise Architect to join the team in Canberra ACT.

This is a contract role, with 12 + 12 + 12 months duration and this is an on-site Canberra based role which requires 5 days in office.

Role Description:
The Cyber Security, Cloud and Networks Branch within a Federal Department’s Information Management and Technology Division is seeking a Technical Lead to support a program of work focused on the assessment, enhancement and maturation of the Department’s cryptographic services capability, including Public Key Infrastructure (PKI), Hardware Security Modules (HSMs) and related trust services.

The role will contribute to capability assessment, architecture development, documentation uplift, operational process improvement, transition planning and future‑state service design. Working across business, project, engineering and operational teams, the successful candidate will provide technical leadership to identify capability gaps, develop practical and sustainable solutions, and improve the maturity and long‑term sustainability of cryptographic services.

In addition to technical architecture responsibilities, the role will support the development and enhancement of PKI governance frameworks, certificate management policies, operational procedures, security controls and risk management processes. The successful candidate will collaborate with business analysts, project resources and operational teams to establish sustainable governance, procedural and assurance practices that support the secure operation of cryptographic services.

Given the specialised nature of the domain, the Federal Department is seeking candidates with strong experience in cryptographic services, PKI governance, security architecture, infrastructure security, risk management or related technical leadership disciplines. Candidates should demonstrate the ability to balance technical solution design with the development of governance, policy and procedural controls required to operate cryptographic services within a regulated and security‑sensitive environment.

Key Duties and Responsibilities

The Federal Department is seeking a Technical Lead to provide architectural leadership for the delivery, governance and ongoing evolution of enterprise cryptographic services, including Public Key Infrastructure (PKI), Hardware Security Modules (HSMs), certificate management, key management and related security capabilities. The role will be responsible for supporting both the technical and governance aspects of cryptographic capability uplift across the Department.

The role will work across business, architecture, engineering and operational teams to assess current capabilities, identify improvement opportunities, develop future‑state architectures, establish governance frameworks and support delivery outcomes. The successful candidate will provide technical leadership across multiple initiatives, balancing strategic planning, security risk management and policy development with practical implementation activities within a complex and highly regulated environment.

In addition to technical architecture responsibilities, the role will support the development and maintenance of governance artefacts including standards, policies, procedures, operating models and assurance processes required for the effective management of cryptographic services. This includes working collaboratively with business analysts, project resources and operational teams to define sustainable processes, controls and service management practices that underpin the secure operation of PKI and related trust services.

The Federal Department recognises that deep PKI expertise is a specialised capability. As such, applications are encouraged from candidates with strong experience in cryptographic services, PKI governance, security architecture, infrastructure architecture, cryptography or related technical leadership disciplines. Candidates should be able to demonstrate experience balancing technical solution design with governance, policy and procedural requirements in security‑sensitive or regulated environments.

Key Responsibilities and Duties
  • Provide technical leadership for the design, delivery and ongoing operation of enterprise PKI, HSM and cryptographic services.
  • Lead the development and maintenance of cryptographic governance artefacts, including policies, standards, procedures, operating models and security risk management processes to support the secure operation of PKI and related trust services.
  • Define, govern and maintain target cryptographic architectures, including trust models, key management approaches, availability requirements and security standards.
  • Assess current capabilities and conduct gap‑analysis activities to support roadmap development, business cases and future‑state planning.
  • Act as a senior technical authority for cryptographic and security architecture decisions, engaging with stakeholders across business, project and operational teams.
  • Lead solution architecture and detailed technical design activities, ensuring secure implementation, deployment and operational practices.
  • Identify and manage cryptographic risks, platform dependencies and operational resilience requirements.
  • Support engineering teams through design, build, testing, release and transition‑to‑operations activities.
  • Produce and maintain architectural artefacts, technical designs, operational documentation and implementation guidance.
  • Support the ongoing operation and improvement of cryptographic services, including upgrades, maintenance, testing and issue resolution.
  • Ensure services align with organisational security policies, government standards and industry best practice.
  • Provide technical mentoring, knowledge transfer and capability uplift across engineering and operational teams.

Essential criteria

1.Cryptographic Security Architecture. 

Demonstrated experience leading the assessment, architecture and improvement of enterprise security or cryptographic services, such as Public Key Infrastructure, Hardware Security Modules, certificate lifecycle management, key management, identity or other high-assurance trust services. 

The candidate should demonstrate the ability to:
a. assess current-state capabilities and identify architectural, security, operational and governance gaps;
b. define target-state architectures, trust models, security controls and practical improvement roadmaps;
c. translate business, security and operational requirements into secure, supportable and proportionate solutions; and
d. apply relevant government or industry security standards and risk-management practices within complex enterprise environments.

2.Governance, Policy and Operating Model Design. 

Demonstrated experience developing and implementing governance arrangements for security, cryptographic, identity or trust services.

This should include experience producing or improving artefacts such as policies, standards, certificate policies, certification practice statements, key-management requirements, procedures, control frameworks, assurance arrangements, operating models and decision authorities.

The candidate should demonstrate an ability to translate business, regulatory, security and operational requirements into clear, sustainable and auditable controls and processes.

3.Delivery, Transition and Operational Readiness. 

Demonstrated experience leading or supporting secure technology services across the delivery lifecycle, including design, implementation, testing, assurance, transition to operations and continual improvement. 

The candidate should demonstrate experience:
a. managing technical risks, dependencies and operational resilience requirements;
b. developing architecture, design, implementation and operational documentation;
c. working with engineering and operational teams to establish maintainable support arrangements; and
d. supporting knowledge transfer, service transition and capability uplift.

4.Technical Leadership and Stakeholder Engagement. 

Demonstrated experience operating as a senior technical authority in a complex, multidisciplinary environment. 

The candidate should demonstrate the ability to:
a. provide authoritative and pragmatic technical advice;
b. communicate complex security and cryptographic matters to technical and non-technical stakeholders;
c. resolve competing architectural, security, delivery and operational priorities;
d. influence business, architecture, engineering, project, procurement and operational stakeholders; and
e. mentor personnel and transfer specialist knowledge to internal teams.

5.Negative Vetting Level 1 (NV1) Security Clearance.

Application requirements:

• Latest copy of your CV
• A suitability statement addressing the skills/experiences. 
 
If you believe you are the right fit, apply today.
If you know someone who can be a great fit, refer them via our referral page on the website.

-------------------------------------------------------------------------------------------------
 
New Vision Software acknowledges the Traditional Owners of the lands on which we live and work. We pay our respects to Aboriginal and Torres Strait Islander Peoples, and to Elders past and present.

We welcome people of all cultures, religions, backgrounds, beliefs, ages, abilities, genders, sexual orientations and identities.

Apply now

Apply for Principal Enterprise Architect

Submit your details and CV — we review every application and respond either way.

Accepted formats: PDF, DOC, DOCX. Maximum 10MB.