pinaka
pinaka~7h ago
New

Senior Endpoint Security Engineer – Platform Security | Canberra | Baseline

AustraliaAustralia·Canberrasenior
CybersecurityEndpoint Security Engineer
0 views0 saves0 applied

Quick Summary

Overview

Senior Endpoint Security Infrastructure Engineer Australian citizenship required. Must have an active Baseline (or higher) security clearance. Location: Canberra (Hybrid).

Technical Tools
CybersecurityEndpoint Security Engineer

Australian citizenship required. Must have an active Baseline (or higher) security clearance.

  1. A tailored resume in docx format
  2. A one page (5000 character) summary response to the selection criteria below.
  • RFQ ID: LH-07710
  • Agency: Department of Industry, Science and Resources
  • Closing Date: Wednesday, 16 September 2026 at 11:59pm Canberra time
  • Estimated Start Date: Monday, 5 October 2026
  • Initial Contract Duration: 6 months
  • Extension Term: 12 months
  • Number of Extensions: 2
  • Experience Level: Senior – EL1 equivalent
  • Security Clearance: Must have an active Baseline security clearance
  • Location of Work: ACT
  • Working Arrangements: Hybrid. Flexible work is generally supported in line with business needs. Remote working arrangements may be considered on a case-by-case basis in consultation with the supervising manager.
  • Maximum Hours: 40 hours per week

We are seeking a technically skilled and security-conscious Platform Engineer to join our Platform Services team. The role contributes to the operation, maintenance and continual improvement of the Department’s ICT infrastructure and endpoint security platforms, with a strong focus on secure, reliable and supportable services.

The position supports Windows Server environments, endpoint protection and application control technologies, identity and privileged access management platforms, and related infrastructure services. The successful candidate will work collaboratively with Platform Services colleagues, Cyber Security, infrastructure and application teams, project delivery areas, vendors and business stakeholders.

The role will balance business-as-usual support with project delivery, security uplift, vulnerability remediation, platform lifecycle management, documentation and knowledge transfer.

Responsibilities

~2 min read
  • Support and maintain enterprise endpoint security platforms, including application control, endpoint protection, endpoint detection and response (EDR), host-based firewalls, vulnerability management and device control technologies.
  • Administer and support technologies such as Airlock Digital, Symantec Endpoint Protection and Microsoft Defender, including platform configuration, policy maintenance, agent health and lifecycle management.
  • Plan and deliver security platform patching, upgrades, policy changes and agent deployments through established change management processes.
  • Assess and implement application whitelisting, application unblocking, antivirus exclusion and security policy requests in consultation with system owners and Cyber Security.
  • Monitor and respond to CVEs, vendor advisories, security findings and vulnerabilities, including impact assessment, remediation planning, testing and implementation.
  • Provide operational and project support across enterprise Windows Server environments and related infrastructure services including windows servers without a GUI (Server core).
  • Support Windows Server lifecycle and modernisation activities, including upgrades, migrations, patching, hardening, compatibility assessment and transition to supported operating system versions.
  • Administer and troubleshoot technologies including Active Directory, Entra ID, DNS, PKI, Group Policy, DFS, SCOM, SCCM/MECM and Intune.
  • Support and maintain enterprise identity management platforms, including Microsoft Identity Manager and Unify Broker.
  • Contribute to the support and maintenance of privileged access management solutions such as CyberArk and Secret Server.
  • Undertake troubleshooting and provide technical advice on identity, authentication, access and privileged access issues and workflows.

Candidates who do not meet the essential criteria, including a minimum of five years' relevant experience, will not be considered. Desirable criteria are considered an added benefit only. A current and active Baseline Security Clearance is mandatory for this role.

  1. Demonstrated experience administering and supporting enterprise endpoint security platforms, including application control, endpoint protection, EDR, vulnerability management, host-based firewalls, device control and security policy management.
  2. Experience with Airlock Digital application control, Symantec Endpoint Protection, Microsoft Defender for Endpoint, Microsoft Defender Vulnerability Management or comparable enterprise security products.
  3. Experience responding to CVEs, vendor advisories, security findings and production issues, including impact assessment, troubleshooting, remediation, testing, change implementation and vendor engagement.
  4. Detailed Windows Server understanding and experience including Active Directory, Entra ID, DNS, PKI, DFS, Microsoft System Centre products and Intune (SCOM, SCCM/MECM) and Azure Virtual Desktop.
  1. Knowledge of Australian Government cyber security requirements, including the Information Security Manual, Essential Eight maturity model and ACSC security guidance, with experience contributing to implementation or assurance of security controls. Experience working in an Australian Government or similarly regulated environment.
  2. Experience administering Red Hat Enterprise Linux, including patching, security hardening, lifecycle management and enterprise service integration, with demonstrated experience using Ansible or similar automation and configuration management tools to deploy, configure, patch and maintain infrastructure.
  3. Experience with infrastructure-as-code, source control, CI/CD pipelines, Azure DevOps, Azure Arc or related DevOps and hybrid management practices. Experience with IAM and PAM principles, access governance and access control, including knowledge and experience with IAM technology such as MIM, Unify Broker and EntraID.
  4. Strong experience in writing technical documentation including SOPs and design documentation.

We know the government ICT market and we keep things straightforward. We take time to understand your background, your goals and the type of role that suits you. We believe transparency is about more than rates and our margins are fair and always disclosed.

  1. Fair, disclosed margins
  2. Clear communication at every stage
  3. Honest advice on fit and competitiveness
  4. Visibility on submissions and process status
  5. A professional and respectful experience

You choose what's best for you.

  1. PAYG through Pinaka
  2. Third-party payroll
  3. Self-employed (own ABN)
    With a single, transparent and fixed margin, we ensure compliance to all state and payroll laws. So that is one less thing for you to worry about.

Already in a role but not happy with the setup?
Port in your contract to Pinaka for a simpler and more transparent experience. We also have some exciting limited time offers on top of the incredible margins we offer.

Our referral program for people who introduce strong candidates to us.
Refer a friend - Earn $1/hr per successful referral as long as you both with us. Refer as many friends as you want; no caps.

Location & Eligibility

Where is the job
Canberra, Australia
On-site at the office
Who can apply
AU

Listing Details

First seen
September 9, 2026
Last seen
September 9, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
52%
Scored at
September 9, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

pinakaSenior Endpoint Security Engineer – Platform Security | Canberra | Baseline