Role Title
Principal Enterprise Architect
Location
Canberra, ACT
Working Arrangement
Onsite, 5 days per week in the office.
Clearance required
Must be able to obtain Negative Vetting Level 1 (NV1) Security Clearance.
Company overview
The Department of Foreign Affairs and Trade (DFAT) is seeking a Principal Enterprise Architect to join the Cyber Security, Cloud and Networks Branch within the Information Management and Technology Division. This role will support a critical program focused on assessing, enhancing and maturing the Department's enterprise cryptographic services capability, including Public Key Infrastructure (PKI), Hardware Security Modules (HSMs) and related trust services.
Job Description
DFAT is seeking an experienced Principal Enterprise Architect to provide technical leadership across the design, governance and ongoing evolution of enterprise cryptographic services. This role will work across business, architecture, engineering and operational teams to assess current capabilities, identify improvement opportunities, develop future-state architectures and establish governance frameworks that support secure and sustainable service delivery.
The successful candidate will have extensive experience in cryptographic services, PKI governance, security architecture, infrastructure security and risk management within complex and highly regulated environments. The role combines strategic architecture leadership with hands‑on involvement in governance, policy development, operational readiness and capability uplift initiatives.
Duties and Responsibilities
- Provide technical leadership for the design, delivery and ongoing operation of enterprise PKI, HSM and cryptographic services.
- Lead the development and maintenance of governance artefacts including policies, standards, procedures, operating models and security risk management processes.
- Define and maintain target cryptographic architectures, trust models, key management approaches and security standards.
- Assess existing capabilities and conduct gap analysis activities to support roadmap development and future-state planning.
- Act as the senior technical authority for cryptographic and security architecture decisions.
- Lead solution architecture and detailed technical design activities.
- Identify and manage cryptographic risks, platform dependencies and operational resilience requirements.
- Support engineering teams through design, build, testing, release and transition-to-operations activities.
- Produce and maintain architecture documentation, technical designs and implementation guidance.
- Support ongoing service improvement, upgrades, maintenance, testing and issue resolution activities.
- Ensure alignment with organisational security policies, government standards and industry best practice.
- Provide mentoring, knowledge transfer and capability uplift to engineering and operational teams.
- Engage and influence business, project, procurement, architecture and operational stakeholders.
Knowledge/Skills required
- Demonstrated experience leading enterprise security and cryptographic architecture initiatives.
- Strong expertise across PKI, HSMs, certificate lifecycle management, key management and trust services.
- Experience assessing current-state environments and defining target-state architectures and roadmaps.
- Strong understanding of security governance, policy development, risk management and operating model design.
- Experience developing standards, procedures, assurance frameworks and security controls.
- Proven ability to support technology services throughout the delivery lifecycle, including implementation, testing, transition and operational readiness.
- Strong stakeholder engagement and communication capabilities with both technical and non-technical audiences.
- Ability to provide authoritative and pragmatic technical advice in complex environments.
- Experience mentoring technical teams and supporting capability development.
- Knowledge of Australian Government security frameworks and highly regulated environments will be highly regarded.
- Experience with Defence, Government or other high-assurance cryptographic environments is desirable.
- SFIA Level 6 capability across:
- Solution Architecture (ARCH)
- Information Security (SCTY)
- Specialist Advice (TECH)
Employment benefits
- Opportunity to work on a nationally significant cryptographic capability uplift program.
- High-impact enterprise architecture role within a complex government environment.
- Exposure to specialised security, PKI and trust service technologies.
- Collaborative environment working with business, engineering and operational stakeholders.
- Opportunity to influence strategy, governance and future-state architecture across critical security services.
- Initial 12-month contract with extension options available.
Diversity and Inclusion
We value diversity and are committed to creating an inclusive environment for all employees.
Veterans
Defence and Federal Government industry experience is highly desirable We strong encourage veterans and individuals with Defence experience to apply. Your unique skills and background are highly valued, and we are committed to supporting your transition into this role.