Back to job board
ContractCyber Security

Cyber Security Architect

This opportunity will be responsible for providing technical and strategic architecture leadership across core cyber security platforms and services. The role focuses on the design, integration, uplift and ongoing technical coherence of security monitoring, identity, endpoint, cloud, emerging technology and secure internet access capabilities.

Location
Canberra, Australian Capital Territory
Clearance
NV1 Preferred
Rate / salary
On application
Applications close
2026-10-11
Role detail

About this opportunity

The position primarily works in Cyber Security, but may need to work across Cloud Infrastructure, Network Infrastructure, End User Computing, enterprise architecture and project teams. The Cyber Security Architect is expected to understand the client's deployed environment, investigate technical dependencies and gaps, develop implementable security designs and guide changes through to an operational outcome.

The primary focus is the cyber security technology estate, including SIEM and enterprise logging, Microsoft Entra and Active Directory security, Microsoft Purview, Microsoft Defender for Endpoint and Defender for Identity, Azure and hybrid cloud security, proxy and secure web gateway services, CASB, network security integrations, vulnerability management and related security tooling. 

The Cyber Security Architect (EL1 equivalent) may need to work across emerging technology areas such as artificial intelligence.

Key duties and responsibilities
Security Monitoring and SIEM Architecture
 Own and maintain the architecture for enterprise security monitoring capability, including Rapid7 SIEM, Windows Event Collection, Azure and cloud telemetry, network security logs, proxy logs, Microsoft Defender data and other priority security sources.
 Define logging, telemetry, retention, data flow and integration requirements for new and existing systems, aligned with the client's requirements and relevant ASD priority logging guidance.
 Identify monitoring blind spots, duplicated or misconfigured log sources, unsupported collection paths and gaps in event coverage.
 Design sustainable processes and technical patterns for onboarding systems and services into the SIEM.
 Ensure monitoring architecture supports threat detection, threat hunting, incident investigation, forensic readiness, audit and managed security services.

Endpoint and Server Security Architecture
Provide architecture leadership for Microsoft Defender for Endpoint, Microsoft Purview and Microsoft Defender for Identity, including sensor architecture, onboarding, configuration baselines, telemetry coverage and operational integration, including into AI-enabled systems.
 Design security requirements for endpoints, servers, domain controllers, administrative workstations and specialised or non-user devices.
 Review endpoint and server hardening, attack surface reduction, endpoint detection and response, vulnerability exposure and security configuration management.
 Identify legacy agents, duplicated tooling, unsupported components and configuration gaps, reduce risk scores and develop practical rationalisation or remediation approaches.
 Ensure endpoint and identity security capabilities are incorporated into standard infrastructure deployment and support processes.

Cyber Security Platforms and Tooling
Provide architecture leadership across cyber security platforms, including SIEM, vulnerability management, Microsoft security tooling, network security services and cloud-native security controls.
 Assess whether security products and capabilities are correctly configured, integrated and used in accordance with technical and operational requirements.
 Develop target architectures and technical roadmaps for the rationalisation, replacement or uplift of security platforms.
 Define specific and measurable technical requirements for procurements, vendor engagements and managed security services.
 Validate vendor and project designs against deployed environment rather than relying on generic product capability statements.

Architecture Governance and Technical Delivery
Lead cyber security architecture reviews for infrastructure, identity, endpoint, network, cloud, SaaS, application and data initiatives.
 Produce and maintain high-level designs, detailed designs, integration diagrams, security patterns, architecture decision records, technical standards and implementation roadmaps.
 Provide clear recommendations on technical risks, design choices, dependencies, implementation sequencing and remediation priorities.
 Validate that delivered solutions match approved designs and that architecture documentation accurately reflects the deployed environment.
 Provide hands-on technical analysis of configurations, data flows, access models, firewall and proxy dependencies, logging pathways and security control implementation.
 Apply the ISM, PSPF, Essential Eight, ASD guidance and security requirements in a technically practical manner.

Estimated start date: 2 November 2026 
Initial contract duration: 12 months 
Extension Term: 12 months   
APS Equivalent: EL1
Location of work: ACT, onsite.
Security Clearance: Must hold, (or be able to obtain) a Negative Vetting Level 1 (minimum) AGSVA Security Clearance.

Application Requirements
Latest CV ensuring it is current and accurate.
 A response to each criterion (3,000 character maximum for each) to demonstrate how your knowledge, skills and experience meet the criteria. Also consider the key duties and responsibilities required for the role.  

Essential criteria
1. Cyber Security Architecture and Engineering.
Demonstrated experience designing, integrating and uplifting cyber security technologies across complex enterprise environments. Experience must span multiple security domains and include evidence of translating architecture into implemented, supportable operational outcomes.

2. Endpoint, Security Monitoring, Server and Microsoft Security Technologies 
Demonstrated experience designing and maintaining enterprise security monitoring capabilities, including SIEM architecture, as well as with Microsoft Defender for Endpoint and Microsoft Defender for Identity, including architecture, deployment, sensor or agent design, configuration baselines, telemetry coverage and integration with security operations. Experience with endpoint and server hardening, attack surface reduction, vulnerability exposure and security configuration management is also required. Experience with Rapid7, Windows Event Collection or equivalent technologies is highly desirable.

3. Architecture Artefacts and Technical Assurance 
Demonstrated experience producing technically accurate high-level and detailed designs, integration and data-flow diagrams, security patterns, architecture decision records, technical standards and implementation roadmaps. Demonstrated ability to validate that delivered solutions and supporting documentation align with approved designs and the deployed environment.

4. Government Security Frameworks 
Demonstrated ability to apply the Australian Government Information Security Manual, Protective Security Policy Framework, Essential Eight and relevant ASD guidance to technical architecture, security control design and implementation decisions.

5. Cross-Team Technical Leadership 
Demonstrated ability to work across cyber security, cloud, network, endpoint, enterprise architecture and project teams to investigate technical dependencies, resolve design constraints, challenge generic or vendor-led proposals and drive practical security outcomes.

6. Communication 
Highly developed written and verbal communication skills, including the ability to explain complex technical issues, document defensible architecture decisions and provide clear technical direction to engineers, vendors, project teams and senior stakeholders.


Apply now

Apply for Cyber Security Architect

Submit your details and CV — we review every application and respond either way.

Accepted formats: PDF, DOC, DOCX. Maximum 10MB.