Description
π Multiple NV1 Software Developers / AI Engineers β Defence Cyber Security Automation
π Location: Defence-approved sites, Australia
π’ Work arrangement: Onsite β no remote work for this opportunity
π Security clearance: Active NV1 minimum
π
Contract: Through to no later than 30 May 2027
π₯ Multiple positions available
Azooa is preparing a response for RFQ 96895 β ETML34 DDG Cyber Assessment and Authorisation Digitisation and is seeking multiple suitably qualified Software Developers, Software Engineers and AI Engineers to support the design and development of a Defence cyber security Assessment & Authorisation digitisation capability.
This is genuine software engineering, AI/document automation and systems integration work β not solely a Cyber GRC advisory engagement.
The capability is expected to analyse Defence documentation, extract security and risk information, generate draft security artefacts, assess existing artefacts, identify compliance and evidence gaps, maintain end-to-end traceability, and provide dashboards and reporting.
π¨ π» Roles We Are Looking For
πΉ Senior AI Software Engineer
Python, AI application development, NLP, LLM-enabled applications, RAG/retrieval, document intelligence, information extraction, semantic search, backend development and APIs.
πΉ Senior Backend / Application Developer
Python, FastAPI, REST APIs, PostgreSQL, application services, workflow/rules engines, document processing, automated document generation and secure backend engineering.
πΉ Senior Full-Stack Developer
React, TypeScript, Python/FastAPI, PostgreSQL, REST APIs, dashboards, workflow applications, authentication/authorisation and secure application development.
πΉ Senior Integration Developer / Software Engineer
REST APIs, secure interfaces, IAM, OIDC/SAML, RBAC, systems integration, secure data exchange, audit logging and Defence environment integration.
πΉ Software Engineer β Cyber Security Automation
Secure software development combined with Cyber GRC automation, compliance workflows, control/evidence mapping, findings, remediation, traceability and reporting.
π οΈ Proposed Technology Stack
Our proposed technical direction currently includes:
Backend: Python | FastAPI | REST/OpenAPI
Frontend: React | TypeScript
Database: PostgreSQL | pgvector
AI: LLM applications | NLP | RAG | embeddings | semantic search | document intelligence
Integration: REST APIs | IAM | OIDC/SAML | RBAC
DevSecOps: Docker | CI/CD | automated testing | SAST | dependency scanning
Observability: Audit logging | security logging | monitoring
β οΈ Important: The RFQ does not prescribe Python, React, a particular AI model, cloud platform or commercial GRC product.
The final stack will depend on the approved Defence architecture and operating environment.
π€ What Could You Be Building?
The development team may work across:
Secure document ingestion and processingAI/NLP-assisted analysis of Defence documentationStructured information extractionAutomated generation of SAP, SRMP and SSP security artefactsAssessment of existing SAP, SRMP, SSP and SAR documentationCompliance and security gap-analysis functionalityISM / PSPF / DSPF / DCSAAF / DDG AAF mappingRequirements, controls and evidence mappingEvidence-management workflowsFindings and remediation managementEnd-to-end auditability and traceabilityDashboards and reportingBackend services and APIsAuthentication / authorisation / RBACSecure Defence systems integrationFunctional/integration testing, UAT and defect remediation
A key capability will be maintaining traceability across:
π Source Documentation β Requirements β Controls β Evidence β Risks β Findings β Recommendations β Security Artefacts
The outputs need to be explainable, auditable and suitable for review by Defence cyber security practitioners.
π Cyber / GRC Environment
Developers will work alongside Cyber GRC / A&A specialists, Cyber Security Engineers and Solution Architects.
The capability will support assessment against Defence and Commonwealth frameworks including:
ISM | PSPF | DSPF | DCSAAF | DDG AAF
Relevant NIST alignment may also apply.
Experience building Cyber GRC, cyber assurance, risk, compliance, evidence-management or security-automation platforms would therefore be particularly valuable.
π‘ Technical Skills We Are Interested In
Python | FastAPI | React | TypeScript | PostgreSQL | REST APIs | AI/LLMs | NLP | RAG | Document Intelligence | Semantic Search | Workflow Automation | Secure Application Development | IAM | RBAC | Systems Integration | Docker | CI/CD
Experience with Azure DevOps, GitLab, Kubernetes/OpenShift, Splunk, automated security testing or comparable enterprise technologies may also be valuable depending on the final solution architecture.
β
Mandatory Requirements
π Active NV1 security clearance or higher
π’ Ability and willingness to work onsite at Defence-approved locations
π» Strong hands-on software development / engineering experience
π‘οΈ Ability to work within secure, regulated or government technology environments
The Defence requirement specifies a minimum NV1 clearance, with services potentially operating up to and including SECRET.
β Highly Regarded
Experience across Australian Defence, Federal Government, PROTECTED/SECRET environments, AI/document automation, secure enterprise software, Cyber GRC platforms, Defence A&A/ATO, ISM environments, secure APIs, identity/access management or Defence systems integration will be highly regarded.
π Engagement Details
RFQ: 96895
Program: ETML34 DDG Cyber Assessment and Authorisation Digitisation
Clearance: Active NV1 minimum
Work arrangement: Onsite at Defence-approved locations
Contract till: 30 May 2027
Extensions: No extension options currently specified
π© Interested?
If you're an NV1-cleared AI Engineer, Python Developer, Backend Developer, Full-Stack Developer, Integration Developer or Software Engineer with current availability for a new Defence engagement, we'd like to hear from you.