About this role
The Cyber Security Engineer is responsible for designing, implementing, maintaining and improving the agency's cyber security controls, services and technologies. The role supports the protection of agency information, systems and data through the application of security engineering principles, technical expertise and risk-based approaches aligned to the Australian Government Information Security Manual (ISM), Protective Security Policy Framework (PSPF) and Essential Eight. Operating with a high degree of autonomy, the EL1 Cyber Security Engineer provides technical leadership on cyber security initiatives, manages security technologies, supports incident response activities, and contributes to the agency's cyber security uplift program. The role requires strong stakeholder engagement skills and the ability to translate complex technical matters into practical advice for both technical and non-technical audiences. Security Engineering and Architecture • Design, implement and maintain cyber security controls across cloud, on-premises and hybrid environments. • Develop secure architecture patterns and technical standards. • Review and assess ICT projects and system designs to ensure compliance with security requirements. • Provide security-by-design advice for new technologies and services. • Contribute to secure configuration baselines and hardening standards. Security Operations • Manage and optimise security technologies including: o Microsoft Defender Suite o Microsoft Sentinel o Microsoft Entra ID o Microsoft Intune o Firewalls and secure gateways o Endpoint Detection and Response (EDR) solutions o Vulnerability management tools • Monitor security events and support threat detection activities. • Assist with cyber security incident investigations, containment and remediation activities. • Develop and maintain security monitoring rules, alerts and automation workflows. Vulnerability and Risk Management • Conduct vulnerability assessments and coordinate remediation activities. • Analyse security risks and recommend appropriate mitigation strategies. • Support implementation and reporting against the Essential Eight Maturity Model. • Contribute to security risk assessments for systems, applications and third-party services. Governance, Compliance and Assurance • Support compliance with the PSPF, ISM and other relevant government security requirements. • Assist with security accreditation and system authorisation activities. • Develop and maintain security documentation, procedures and standards. • Contribute to internal and external security audits. Project and Stakeholder Management • Lead medium-complexity cyber security projects and technical workstreams. • Provide technical guidance to ICT teams and project managers. • Engage with internal stakeholders, managed service providers and government partners. • Prepare executive briefings, reports and recommendations. Leadership • Provide mentoring and technical guidance to APS employees and contractors. • Promote a positive security culture across the agency, solutions focussed • Contribute to workforce capability development and knowledge sharing. • Foster collaboration across ICT, security and business teams. Selection criteria Technical Cyber Security Expertise Demonstrated experience implementing and managing cyber security technologies and controls within complex ICT environments, ideally with experience within the APS. Security Risk and Assurance Proven ability to assess cyber security risks, develop mitigation strategies and support compliance with government security frameworks including the ISM and PSPF. Stakeholder Engagement and Communication Demonstrated ability to build relationships, provide trusted advice and communicate technical information effectively to both technical and non-technical stakeholders. Delivery and Problem Solving Strong analytical and problem-solving skills with the ability to prioritise competing work demands and deliver outcomes within agreed timeframes. Leadership and Collaboration Demonstrated ability to lead technical initiatives, mentor team members and work collaboratively across multidisciplinary teams.
Public Roles standardises this vacancy for easier discovery. The original advertiser controls the requirements, application process, and deadline. Report a problem through corrections.
Related active roles
Change Manager
Australian Securities and Investments Commission · Brisbane QLD, Melbourne VIC, Sydney NSW · Fixed term
Change Manager
Australian Securities and Investments Commission · Canberra ACT, Melbourne VIC, Sydney NSW · Fixed term
Assistant Director, Education (Partnerships)
Sport Integrity Australia · Various locations - ACT ACT · Permanent · $125,820–$137,127
Assistant Directors, Attraction and Recruitment
Australian Electoral Commission · Canberra ACT · Fixed term · $122,163–$137,165