Cyber Security Engineer

Yolk Digital Australia — Australia · Posted ~4 hours ago

Skills

Cybersecurity engineering Cloud security Identity and access management Microsoft Entra ID Azure Security controls Security assurance Azure DevOps pipeline security Code assurance Security remediation SharePoint Online Azure DevOps Azure Foundry AI technologies

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A hands-on Cyber Security Engineer role focused on designing, implementing, validating, and improving security controls across cloud platforms, identity services, digital delivery environments, and emerging technologies. You will work closely with engineering and delivery teams, address security gaps, and create implementation artefacts supporting testing, deployment, operations, and maintenance.

Highlights

Hands-on security engineering role with broad exposure to cloud, identity, DevOps, resilience, and emerging AI technologies. Offers the opportunity to shape secure technical solutions from design through deployment and ongoing operations.

Description

Applications Close: Wednesday 9 September 2026 Job Details The Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts is looking for a Cyber Security Engineer to join its Information Technology and Data Division. You'll provide hands-on security engineering, professional advice and assurance across a portfolio of Digital Strategy projects spanning cloud identity and access management with Microsoft Entra ID, SharePoint Online records management, resilience for remote and regional systems, Azure DevOps pipeline security and code assurance, and emerging Azure Foundry and AI accelerator technologies. This is a build-and-implement role rather than a policy one. You'll design secure technology patterns, configure and validate controls, remediate gaps, and produce the implementation artefacts that carry each solution through testing, deployment, transition to operations and ongoing maintenance. You'll work alongside delivery teams to embed security gates, automated scanning and secure release practices into their existing ways of working, and you'll engineer secure patterns for identity, access and data protection in regional operating environments. Throughout, you'll implement controls and capture evidence against Australian Government cyber security requirements including the ISM, PSPF, Essential Eight, privacy, data protection and supply chain security obligations. Location ACT. Onsite. The worker must be in the office at least 3 days a week, and must start and finish work within standard working hours (7am to 7pm). Duration 6 months, commencing 29 September 2026, with 2 x 6 month extension options. Citizenship Australian Citizen Clearance NV1 Key Responsibilities * Implement secure technology patterns across Digital Strategy projects, including solution configuration, control implementation, testing, deployment support, transition to operations and operational readiness activities * Build, configure and validate security controls, remediate agreed gaps and produce implementation artefacts that support practical delivery, handover and ongoing maintenance * Implement secure SharePoint Online records management capabilities, including access models, retention and information protection settings, secure site patterns and integration with operational records processes * Configure Microsoft Entra ID capabilities for secure authentication, authorisation and access governance, including conditional access, application access patterns and integration with cloud services * Implement Azure DevOps pipeline security and code assurance capabilities, including automated scanning, security gates, remediation workflows and secure release practices aligned to delivery teams' ways of working * Engineer secure implementation patterns for Azure Foundry, AI accelerator and emerging technology solutions * Develop strategies for identity, access, data protection and deployment considerations for remote and regional operating environments * Implement controls and capture evidence against relevant Australian Government cyber security requirements, including the ISM, PSPF, Essential Eight, privacy, data protection and supply chain security obligations Skills & Experience * Enterprise security engineering and security architecture within large, complex environments * Design and implementation of Microsoft Entra ID Suite security and access management capabilities, including conditional access and application access patterns * Applying the ISM, PSPF and Essential Eight to enterprise information systems, including implementing controls and capturing evidence * Secure SharePoint Online records management, covering access models, retention and information protection settings * Azure DevOps pipeline security and code assurance, including automated scanning, security gates and secure release practices * Embedding security into low-code and RAD platforms * Cloud security across Azure, AWS and M365, as well as AI and Foundry resources * Identity, access and data protection patterns for remote and regional operating environments Essential Criteria 1. Candidate Capability and Technical Fit. The extent to which you meet the specified technical requirements (Job Details, Key Responsibilities, Skills & Experience). 2. Relevant Experience on EDRMS, RAN and Regional Infrastructure Uplift projects. Demonstrated experience in: * Enterprise security engineering and/or architecture * Design and implementation of Entra ID Suite security and access management capabilities * Applying the ISM, PSPF and Essential Eight to enterprise information systems * Embedding security into low-code/RAD platforms * Cloud security across Azure/AWS/M365 as well as AI and Foundry resources Application Instructions Each candidate must upload a one page pitch addressing all criteria specified. This includes responding to the Job Details, Key Responsibilities, and Essential Criteria. The pitch cannot be more than 5000 characters. Structure the pitch using the STAR format (Situation, Task, Action, Result) so each example shows what you did and what changed as a result. Sell your capability rather than listing duties: lead with the outcomes you delivered. Target the two Essential Criteria directly, with concrete instances of Entra ID security and access management design, applying the ISM, PSPF and Essential Eight to enterprise systems, embedding security into low-code or RAD platforms, and cloud security across Azure, M365 and AI or Foundry resources. Where you have worked on EDRMS, records management or regional infrastructure uplift projects, name them. If you have worked at the Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts before, include with your application the branch and division you worked in, and your role. Applications close Wednesday 9 September 2026. Apply via the website: https://yolkdigital.com.au/site-data/jobs/cyber-security-engineer