Description
Description
Position: Cybersecurity DevOps Engineer - 12 Months Fixed Term role.
Datacom Location: Anywhere in Australia
Security Requirements: AU Citizens and Residents Only
Full Time, 12 Months Fixed-Term Position.
Our Why
Datacom works with organisations and communities across Australia and New Zealand to make a difference in people’s lives and help them to use the power of tech to innovate and grow.
About The Role (Your Why)
As a Cybersecurity DevOps Engineer, you will play a key role in delivering Datacom's cybersecurity uplift programme by embedding security controls into our software development and infrastructure delivery platforms.
Working at the intersection of cybersecurity, software engineering and platform operations, you will design and implement secure-by-default practices across our GitHub ecosystem, CI/CD pipelines, Infrastructure as Code (IaC) platforms and cloud environments.
This role is focused on automation, security engineering and continuous improvement.
You will help build the security guardrails that enable development teams to deliver quickly and safely while ensuring compliance with organisational policies and security standards.
You will work closely with developers, architects, platform engineers, system administrators and security specialists to uplift our DevSecOps capabilities, automate compliance activities and improve the security posture of both cloud and on-premises environments.
Our offices are based in Brisbane.
We like to bring people together in person when we can, but we are mindful of the benefits of working from home for work/life balance.
We therefore leave it to you and the team you join to decide what works best.
What You'll Do
At the moment, as a Cybersecurity DevOps Engineer, you will be focused on:
Designing, implementing and improving enterprise DevSecOps practices across development and infrastructure teamsBuilding and maintaining secure CI/CD pipelines that incorporate automated security controls and quality gatesAdministering and governing GitHub repositories, workflows and security controlsImplementing security controls through Infrastructure as Code (IaC) and platform automationDeveloping and maintaining Policy as Code capabilities to enforce security, compliance and organisational standardsIntegrating and managing security tooling, including SAST, software composition analysis and vulnerability scanning capabilitiesSupporting and enhancing our application security platforms, including Aikido and related security toolingEstablishing controls to detect, report and remediate configuration drift across cloud and infrastructure environmentsImplementing software supply chain security controls and secure development practicesDesigning and delivering automation workflows using tools such as GitHub Actions, n8n and other orchestration platformsAutomating security assurance activities including peer review enforcement, repository governance, branch protections and security review processesSupporting developers and delivery teams to adopt secure software development lifecycle (SSDLC) practicesWorking with security and governance teams to translate security requirements into automated technical controlsParticipating in architecture reviews, code reviews and solution design activitiesSupporting cybersecurity governance, risk management and continuous improvement initiativesContributing to security uplift projects and operational excellence programmes across the organisation
We are an agile organisation and continuously evolve to meet customer, technology and business needs.
This means the role will continue to grow alongside our platforms, services and security capabilities.
What You'll Bring
Required Experience
5+ years' experience in DevOps, DevSecOps, Platform Engineering, Security Engineering, Site Reliability Engineering or a similar roleBachelor's degree in Cybersecurity, Information Technology, Computer Science, Software Engineering or related disciplineStrong understanding of modern DevSecOps principles and secure software development lifecycle (SSDLC) practicesDemonstrated experience designing and supporting CI/CD pipelines in enterprise environmentsStrong experience with GitHub, GitHub Actions and repository governance practicesHands-on experience implementing Infrastructure as Code using technologies such as Terraform, Bicep, CloudFormation or equivalentExperience implementing and maintaining Policy as Code controls and automated compliance frameworksExperience integrating security controls into software delivery pipelinesExperience working with application security tooling including SAST, software composition analysis, secret detection and vulnerability management platformsStrong understanding of cloud security principles across Azure, AWS and GCPExperience designing and implementing automation solutions that improve operational efficiency and security outcomesExperience identifying, monitoring and remediating configuration drift across infrastructure environmentsStrong knowledge of cybersecurity principles, identity security, infrastructure security and cloud securityFamiliarity with security frameworks including ISO 27001, NIST CSF, ACSC Essential Eight, MITRE ATT&CK and government security frameworksStrong analytical, troubleshooting and problem-solving skillsExcellent stakeholder engagement, communication and collaboration skillsAbility to mentor team members and promote DevSecOps best practices across engineering teamsCommercial awareness with an understanding of project delivery, operational outcomes and continuous improvement
Nice to Have
Experience with Aikido or similar application security platformsExperience implementing secure software supply chain programmesExperience with Open Policy Agent (OPA), Azure Policy, HashiCorp Sentinel or equivalent Policy as Code technologiesExperience implementing repository governance at scaleExperience using automation and orchestration platforms such as n8n, GitHub Actions, Power Automate or similar technologiesExperience managing enterprise GitHub environmentsExperience with software assurance activities including SBOM generation and dependency managementExperience within a managed services or Tier 2 service provider environmentCloud certifications from AWS, Microsoft Azure or Google CloudSecurity certifications such as CISSP, CISM, CCSP, CSSLP, GCSA or relevant SANS certificationsExperience with container security, Kubernetes and cloud-native security controls
Why Join Us Here at Datacom?
Datacom is one of Australia and New Zealand’s largest suppliers of Information Technology professional services.
We have managed to maintain a dynamic, agile, small business feel that is often diluted in larger organisations of our size.
It's our people that give Datacom its unique culture and energy that you can feel from the moment you meet with us.
We care about our people and provide a range of perks such as social events, chill-out spaces, remote working, flexi-hours and professional development courses to name a few.
You’ll have the opportunity to learn, develop your career, connect and bring your true self to work.
You will be recognised and valued for your contributions and be able to do your work in a collegial, flat-structured environment.
We operate at the forefront of technology to help Australia and New Zealand’s largest enterprise organisations explore possibilities and solve their greatest challenges, so you will never run out of interesting new challenges and opportunities.
We want Datacom to be an inclusive and welcoming workplace for everyone and take pride in the steps we have taken and continue to take to make our environment fun and friendly, and our people feel supported.