WDAC Implementation Specialist

Michael Page

Sydney

Hybrid

AUD 120,000 - 160,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work 50% home
Long-term contracting
Fast-paced transformation team

Job summary

Michael Page is seeking a WDAC Implementation Specialist in Sydney to design, deploy, and manage WDAC policies across enterprise environments. You will work with Intune, ConfigMgr/SCCM, Group Policy, and PowerShell to ensure secure, compliant application control.

The role requires hands-on WDAC policy authoring, strong Windows security knowledge, and collaboration with cross-functional teams. Hybrid work and long-term contracting are offered.

Qualifications

  • ,

Responsibilities

  • Design, develop, and implement Windows Defender Application Control (WDAC) policies across enterprise environments.
  • Deploy and manage WDAC policies using Intune, ConfigMgr/SCCM, Group Policy, and PowerShell.
  • Perform audit-mode assessments and transition validated policies to enforcement mode with minimal business impact.
  • Investigate and resolve WDAC issues including blocked apps, policy conflicts, and exceptions.
  • Integrate WDAC with Defender for Endpoint, Defender Antivirus, and other security tools to strengthen protection.
  • Monitor WDAC and endpoint security logs with Advanced Hunting, KQL, and Event Viewer to improve policy effectiveness.
  • Collaborate with infrastructure, desktop, security, and application teams for rollout, tuning, and support.
  • Create and maintain technical docs, runbooks, and implementation guides.
  • Provide knowledge transfer and ongoing support to teams and stakeholders.
  • A successful WDAC Implementation Specialist should have: proven WDAC experience, strong Windows security knowledge, and hands-on policy authoring.

Skills

WDAC policy authoring
PowerShell automation
Endpoint security
Audit/enforcement mode
Troubleshooting WDAC
Windows security architecture
Zero Trust / ASD Eight

Tools

Intune
ConfigMgr/SCCM
Group Policy

Job description

  • Design, develop, and implement Windows Defender Application Control (WDAC) policies, including XML policy creation, configuration, testing, and binary conversion for deployment.
  • Deploy and manage WDAC policies across enterprise environments using Microsoft Intune, Endpoint Configuration Manager (ConfigMgr/SCCM), Group Policy, and PowerShell.
  • Execute audit-mode assessments, analyse application execution events, and transition validated policies into enforcement mode while minimising business disruption.
  • Investigate and resolve application control issues, including blocked applications, policy conflicts, software compatibility concerns, and exception management.
  • Integrate WDAC with Microsoft Defender for Endpoint, Microsoft Defender Antivirus, and broader endpoint security solutions to strengthen application control and endpoint protection.
  • Monitor and analyse WDAC, Code Integrity, and endpoint security logs using Advanced Hunting, KQL, Event Viewer, and Microsoft security tooling to continuously improve policy effectiveness.
  • Implement and maintain application whitelisting controls aligned with organisational security frameworks, Zero Trust principles, and compliance requirements.
  • Collaborate with infrastructure, desktop, security, and application teams to support WDAC rollout activities, policy tuning, and ongoing operational support.
  • Create and maintain technical documentation, operational procedures, implementation guides, and support runbooks.
  • Provide knowledge transfer, training, and ongoing support to technical teams and business stakeholders throughout the WDAC implementation lifecycle.

Key Responsibilities:

  • Design, develop, and implement Windows Defender Application Control (WDAC) policies, including XML policy creation, configuration, testing, and binary conversion for deployment.
  • Deploy and manage WDAC policies across enterprise environments using Microsoft Intune, Endpoint Configuration Manager (ConfigMgr/SCCM), Group Policy, and PowerShell.
  • Execute audit-mode assessments, analyse application execution events, and transition validated policies into enforcement mode while minimising business disruption.
  • Investigate and resolve application control issues, including blocked applications, policy conflicts, software compatibility concerns, and exception management.
  • Integrate WDAC with Microsoft Defender for Endpoint, Microsoft Defender Antivirus, and broader endpoint security solutions to strengthen application control and endpoint protection.
  • Monitor and analyse WDAC, Code Integrity, and endpoint security logs using Advanced Hunting, KQL, Event Viewer, and Microsoft security tooling to continuously improve policy effectiveness.
  • Implement and maintain application whitelisting controls aligned with organisational security frameworks, Zero Trust principles, and compliance requirements.
  • Collaborate with infrastructure, desktop, security, and application teams to support WDAC rollout activities, policy tuning, and ongoing operational support.
  • Create and maintain technical documentation, operational procedures, implementation guides, and support runbooks.
  • Provide knowledge transfer, training, and ongoing support to technical teams and business stakeholders throughout the WDAC implementation lifecycle.

A successful WDAC Implementation Specialist should have:

  • Proven experience implementing and supporting Windows Defender Application Control (WDAC) within large enterprise environments.
  • Strong understanding of Windows security architecture, application control, code integrity policies, application whitelisting, and endpoint security technologies.
  • Hands-on experience with WDAC policy authoring, XML policy management, audit versus enforcement mode, policy signing, supplemental policies, and managed installer configuration.
  • Strong experience administering and deploying solutions through Microsoft Intune, Endpoint Configuration Manager (ConfigMgr/SCCM), and PowerShell automation.
  • Experience troubleshooting application execution blocks, compatibility issues, policy exceptions, and endpoint security controls in production environments.
  • Knowledge of Microsoft Defender for Endpoint, Defender Antivirus, Advanced Hunting, KQL, and security event analysis.
  • Experience delivering security solutions within regulated or large-scale enterprise environments.
  • Understanding of Zero Trust security principles, ASD Essential Eight, ISM, and other relevant cybersecurity compliance frameworks.
  • Excellent documentation, communication, and stakeholder engagement skills, with the ability to work across technical and business teams.
  • Exposure to AppLocker, Ivanti Application Control, McAfee Application Control, or other application whitelisting technologies will be highly regarded.

A global technology services and consulting organisation with a significant international presence, delivering digital transformation, cloud, engineering, and business process solutions across a wide range of industries. The company is recognised for helping enterprises modernise operations, improve efficiency, and adopt emerging technologies at scale.

  • Hybrid environment with 50% work from home
  • Long-term contracting opportunity
  • Ability to work in a fast-paced digital transformation team

If this WDAC Implementation Specialist role in Sydney aligns with your skills and experience in the Technology industry, we encourage you to apply.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

WDAC Implementation Lead - Windows Endpoint Security
WDAC Implementation Lead - Windows Endpoint Security

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 120,000 - 150,000
WDAC & Endpoint Security Engineer (Intune/ConfigMgr)
WDAC & Endpoint Security Engineer (Intune/ConfigMgr)

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 110,000 - 170,000
WDAC Implementation
WDAC Implementation

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 120,000 - 150,000
WDAC Implementation Specialist / Endpoint Security Engineer
WDAC Implementation Specialist / Endpoint Security Engineer

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 110,000 - 170,000
Windows Endpoint Security Engineer: WDAC & App Control
Windows Endpoint Security Engineer: WDAC & App Control

FinXL • North Sydney Council

On-site
AUD 150,000 - 190,000
WDAC Policy Architect - Hybrid WFH | Long-Term Contract
WDAC Policy Architect - Hybrid WFH | Long-Term Contract

Michael Page • Sydney

Hybrid
AUD 120,000 - 160,000
Hybrid work 50% home
Long-term contracting
Fast-paced transformation team
Endpoint Security Engineer: WDAC, AppLocker & Intune
Endpoint Security Engineer: WDAC, AppLocker & Intune

NTT • Sydney

On-site
AUD 120,000 - 180,000
Application Control Security Analyst
Application Control Security Analyst

Ayan Infotech • Sydney

On-site
AUD 90,000 - 130,000
Security Engineer - Microsoft App Control
Security Engineer - Microsoft App Control

FinXL • North Sydney Council

On-site
AUD 150,000 - 190,000
Endpoint Security Engineer: WDAC & AppLocker Expert
Endpoint Security Engineer: WDAC & AppLocker Expert

NTT DATA, Inc. • Sydney

On-site
AUD 120,000 - 170,000