Cyber Security Architect

Azooa

Canberra

On-site

AUD 207,000 - 227,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Azooa is seeking a senior Architect to lead cryptographic services for DFAT in Canberra, focusing on PKI, HSMs, and trust services. The role demands an active NV1 or higher clearance and 100% onsite work in Canberra.

You will drive architectural leadership across governance, policy, and operational delivery, ensuring secure enterprise cryptographic capabilities. The engagement targets up to 3 years with a 12‑month initial contract.

Qualifications

  • Senior-level experience across cryptographic services, architecture and governance.
  • Experience delivering enterprise cryptographic capabilities in complex government environments.
  • Ability to translate business and security requirements into practical enterprise solutions.

Responsibilities

  • Provide architectural and technical leadership for DFAT cryptographic services.
  • Define target-state cryptographic architectures and governance artefacts.
  • Lead secure design, deployment and operation of PKI and HSM architectures.

Skills

PKI architecture
HSMs
Identity & trust services
Governance
Solution architecture
Technical leadership
Compliance with government standards

Education

Bachelor's degree in Computer Science or related field

Tools

HSM integration tooling
Security architecture modelling tools

Job description

Are you a senior Architect with strong experience across Public Key Infrastructure (PKI), Hardware Security Modules (HSMs), certificate management, key management and associated trust services — holding an active NV1 or higher clearance and available to work onsite in Canberra?

Azooa is preparing a response for RFQ LH-07503 with the Department of Foreign Affairs and Trade (DFAT) and is seeking suitably qualified contractors for a Principal Enterprise Architect – Cryptographic Services / PKI Technical Lead engagement.

This is a senior Principal / EL2-equivalent opportunity within DFAT’s Cyber Security, Cloud and Networks Branch, focused on assessing, enhancing and maturing the Department’s enterprise cryptographic services capability.

Working arrangement: 100% onsite – 5 days per week

Maximum hours: 40 hours per week

Potential tenure: Up to 3 years

ABOUT THE OPPORTUNITY

DFAT’s Cyber Security, Cloud and Networks Branch is responsible for delivering and operating critical cyber security, identity and trust services supporting departmental and business outcomes.

The successful contractor will support the assessment, enhancement and future delivery of DFAT’s enterprise cryptographic capability across areas including:

  • Hardware Security Modules – HSMs
  • Cryptographic key management
  • Identity and high-assurance trust services
  • Security and solution architecture
  • Cryptographic governance
  • Security risk management
  • Operational process improvement

The role requires a senior technical leader capable of balancing solution architecture, cyber security, governance, policy, operational resilience and practical delivery requirements within a complex Australian Government environment.

CORE RESPONSIBILITIES

The successful candidate will provide architectural and technical leadership for the delivery, governance and ongoing evolution of DFAT’s cryptographic services.

Key responsibilities include:

  • Provide technical leadership across enterprise PKI, HSM and cryptographic services
  • Assess current cryptographic capabilities and undertake architecture, security, governance and operational gap analysis
  • Define and maintain target-state cryptographic architectures
  • Establish appropriate trust models, key-management approaches, security standards and availability requirements
  • Develop practical capability improvement roadmaps and future-state plans
  • Act as a senior technical authority for cryptographic and security architecture decisions
  • Lead solution architecture and detailed technical design
  • Ensure secure implementation, deployment and operational practices
  • Identify and manage cryptographic risk, technology dependencies and operational resilience requirements
  • Develop and maintain cryptographic governance artefacts, policies, standards, procedures and operating models
  • Support PKI governance frameworks and certificate-management policies
  • Establish security controls, assurance arrangements and risk-management processes
  • Work across architecture, cyber security, infrastructure, engineering, business, project and operational teams
  • Support engineering teams through design, build, testing, assurance, release and transition to operations
  • Produce architectural artefacts, technical designs, implementation guidance and operational documentation
  • Support upgrades, maintenance, testing, issue resolution and continual service improvement
  • Provide authoritative advice to technical and non-technical stakeholders
  • Mentor engineering and operational personnel and transfer specialist knowledge.
KEY DELIVERABLES
  • Current-state cryptographic capability assessments
  • Architecture, security and operational gap analysis
  • Target-state cryptographic architectures
  • PKI architecture artefacts
  • HSM architecture and integration designs
  • Trust models
  • Key-management architectures
  • Cryptographic capability roadmaps
  • Governance frameworks
  • Security-control and assurance frameworks
  • Operating models and decision authorities
  • Detailed technical designs
  • Implementation and transition plans
  • Operational-readiness documentation
  • Knowledge-transfer and capability-uplift materials
ESSENTIAL EXPERIENCE

We are particularly interested in candidates who can demonstrate senior-level experience across:

  • Cryptographic Security Architecture
  • Hardware Security Modules
  • Identity and trust services
  • High-assurance security environments

Strong experience assessing, designing or improving enterprise security and cryptographic services involving areas such as:

  • Hardware Security Modules
  • Identity and trust services
  • High-assurance security environments

You should be comfortable defining current and target-state architectures, identifying technical and governance gaps, developing trust models and security controls, and translating business and security requirements into practical enterprise solutions.

Experience developing sustainable governance arrangements for security, cryptographic, identity or trust services, including:

  • Policies and standards
  • Operating models and decision authorities
Delivery & Operational Readiness

Demonstrated experience across the secure technology lifecycle, including:

  • Architecture and design
  • Security assurance
  • Transition to operations
  • Technical risk and dependency management
  • Knowledge transfer and capability uplift

You should have experience operating as a senior technical authority and be comfortable:

  • Providing authoritative technical advice
  • Explaining complex cryptographic issues to technical and non-technical stakeholders
  • Resolving competing architecture, security and delivery priorities
  • Influencing architecture, engineering, project, procurement and operational stakeholders
  • Mentoring personnel and transferring specialist knowledge
HIGHLY DESIRABLE

Experience in one or more of the following would be highly regarded:

  • Australian Government or Defence environments
  • Enterprise PKI / Certificate Authority environments
  • Hardware Security Modules
  • Cryptographic key-management technologies
  • Australian Government Information Security Manual – ISM
  • PKI supporting ePassports or electronic travel documents
  • Biometric identity systems
  • Country Signing Certification Authority – CSCA
  • Certificate Revocation List lifecycle management
  • Cryptographic disaster recovery and assurance
  • Cryptographic agility

Candidates with strong adjacent experience across security architecture, cryptographic services, infrastructure architecture, PKI governance, identity and trust, or senior cyber technical leadership are also encouraged to apply where they can demonstrate the required architecture, governance and high-assurance security capability.

SECURITY CLEARANCE

Candidates who do not currently hold an active NV1 or higher clearance cannot be submitted for this opportunity.

ENGAGEMENT DETAILS

RFQ: LH-07503

Buyer: Department of Foreign Affairs and Trade

Role: Principal Enterprise Architect – Cryptographic Services / PKI Technical Lead

Location: Canberra ACT

Arrangement: 100% onsite

Remote working: Not available

Initial contract: 12 months

DFAT also operates a contractor stand-down period during December and January, generally around 4–6 weeks at DFAT’s discretion.

Based on recent Azooa contract wins and current Federal Government value-for-money positioning, our indicative maximum recommended bidding levels are:

Pty Ltd: up to $160/hour + GST

PAYG: up to $158/hour

These are recommended maximum bidding levels rather than target rates.

Candidates may nominate higher rates; however, rate competitiveness forms part of the overall value-for-money position. Higher rates are more likely to be supportable where the candidate brings exceptional specialist expertise across PKI, HSMs, cryptographic architecture, high-assurance environments, NV2 clearance or closely aligned DFAT/Defence experience.

Senior PKI Architects, Security Architects, Enterprise Architects, Cryptographic Services Architects, PKI Technical Leads, Identity & Trust Architects and HSM/Cryptographic Services specialists are encouraged to apply.

Please also feel free to share this opportunity with suitably qualified professionals within your network.

#Azooa #DFAT #CyberSecurity #PKI #Cryptography #EnterpriseArchitecture #SecurityArchitecture #HSM #PublicKeyInfrastructure #CyberSecurityJobs #CanberraJobs #GovernmentJobs #NV1 #NV2 #DefenceJobs #ICTJobs #SolutionArchitecture #InformationSecurity #IdentitySecurity

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Enterprise Architect - Cryptographic Services
Principal Enterprise Architect - Cryptographic Services

www.clearedrecruitment.com.au • Canberra

On-site
AUD 250,000 - 320,000
Long-term contract
Work on nationally significant systems
Engagement with senior stakeholders
+1
Principal Enterprise Architect
Principal Enterprise Architect

Client 1 • Canberra

On-site
AUD 180,000 - 240,000
Senior PKI & HSM Architect – Canberra Onsite
Senior PKI & HSM Architect – Canberra Onsite

Azooa • Canberra

On-site
AUD 207,000 - 227,000
Technical Lead
Technical Lead

Whizdom Recruitment • Canberra

On-site
AUD 140,000 - 180,000
Technical Lead
Technical Lead

Whizdom • Canberra

On-site
AUD 150,000 - 190,000
Security Architect
Security Architect

Talent • Canberra

Hybrid
AUD 180,000 - 240,000
Cyber Grc Analyst
Cyber Grc Analyst

Azooa • Canberra

On-site
AUD 182,000 - 193,000
Lead Cyber Security Architect – NV1
Lead Cyber Security Architect – NV1

ZSoft Technologies Pty Ltd • Canberra

On-site
AUD 150,000 - 190,000
Cyber Security Architects
Cyber Security Architects

Clicks IT Recruitment • Canberra

On-site
AUD 120,000 - 160,000
PKI Subject Matter Expert – Policy & Governance | Canberra (On-site) | NV1
PKI Subject Matter Expert – Policy & Governance | Canberra (On-site) | NV1

pinaka • Canberra

On-site
AUD 130,000 - 170,000