Job Description
Remote is seeking a Security Engineer / Cryptographic Systems Engineer (SFIA Level 4) to support the delivery of an enterprise-scale Key Management System across ASD’s multi-class security environment. The role will provide technical expertise in cryptographic technologies, key lifecycle management, hardware security modules, certificate services and encryption solutions. Working closely with architecture, cyber security, infrastructure, cloud, application and vendor teams, the successful candidate will engineer, integrate and support secure, resilient and compliant cryptographic capabilities across multiple technology stacks and operational environments. ( LH-07708)
Role Description
Key duties and responsibilities:
Cryptographic Engineering
-
Design, deploy and configure enterprise key management infrastructure and supporting cryptographic services.
-
Implement cryptographic key lifecycle processes including generation, storage, rotation, archival, recovery and destruction.
-
Configure and support Hardware Security Modules (HSMs) and associated cryptographic services.
-
Implement encryption key management controls across enterprise systems and platforms.
-
Support cryptographic solution testing, validation and operational readiness activities.
-
Develop engineering standards, operational procedures and implementation guidance.
-
Ensure cryptographic services meet availability, performance and resilience requirements
System Integration
-
Integrate KMS capabilities with enterprise platforms, applications and infrastructure services.
-
Implement secure API-based integrations supporting cryptographic operations.
-
Support integration with identity, access management and authentication services.
-
Configure encryption services across cloud, hybrid-cloud and on-premises environments.
-
Support certificate management and machine identity services.
-
Troubleshoot and resolve integration and interoperability issues.
-
Develop automation scripts and deployment mechanisms where required.
Security Engineering
-
Implement security controls in accordance with ASD ISM, PSPF and security architecture requirements.
-
Support secure configuration, hardening and ongoing maintenance of cryptographic systems.
-
Conduct security assessments and technical risk analysis.
-
Investigate security incidents affecting cryptographic infrastructure and services.
-
Support vulnerability management and remediation activities.
-
Participate in security reviews, design assurance and accreditation activities.
-
Ensure compliance with approved security baselines and standards.
Operations and Support
-
Provide technical support for enterprise cryptographic services.
-
Monitor system health, performance and availability.
-
Develop operational runbooks and support documentation.
-
Support disaster recovery, backup and business continuity arrangements.
-
Participate in change, release and configuration management processes.
-
Maintain technical documentation and engineering artefacts.
-
Provide specialist advice to operational and project teams.
Technical skills
-
Degree qualification in Cyber Security, Information Technology, Computer Science, Engineering or related discipline.
-
Industry-recognised cyber security certification.
-
Cryptographic security or encryption-related training.
-
Cloud security certification (AWS, Azure or Google Cloud).
-
Vendor certification for KMS, HSM or encryption technologies.
-
ITIL Foundation or equivalent service management certification.
-
Demonstrated SFIA Level 4 capability
Essential criteria
Technical Knowledge and Cryptographic Engineering Capability: Demonstrated experience applying cryptographic principles and security engineering practices to support secure ICT systems and services. The candidate should demonstrate experience in:
-
Implementation and support of cryptographic solutions within enterprise or government environments.
-
Public Key Infrastructure (PKI) operations and certificate lifecycle management.
-
Encryption technologies used to protect data at rest and in transit.
-
Key management practices and cryptographic device administration, including Hardware Security Modules (HSMs).
-
Secure communications technologies and cryptographic protocols.
-
Security hardening and implementation of cryptographic controls.
-
Investigation and remediation of security weaknesses relating to cryptographic systems.
-
Application of contemporary cyber security principles and security-by-design approaches. Responses should provide examples of technologies used, responsibilities undertaken and outcomes achieved.
Relevant Experience and Service Delivery: Demonstrated experience delivering cryptographic engineering or cyber security services within complex ICT environments. The candidate should demonstrate:
-
Experience supporting security-focused projects and operational services.
-
Delivery of technical outcomes within agreed timeframes.
-
Experience working within multidisciplinary technical teams.
-
Participation in security implementation, integration, deployment or transition activities.
-
Ability to analyse technical issues and recommend practical solutions. Responses should clearly describe the candidate's role, contribution and measurable outcomes.
Security Assurance, Risk and Compliance Support: Demonstrated ability to support security assurance and risk management activities. The candidate should demonstrate:
-
Experience supporting security assessments, reviews or compliance activities.
-
Understanding of cyber security risk management principles.
-
Ability to identify, assess and document technical security risks.
-
Experience implementing security controls aligned with government or industry standards.
-
Contribution to documentation supporting system accreditation, certification or assurance processes.
Communication and Stakeholder Engagement: Demonstrated ability to communicate effectively with technical and non-technical stakeholders. The candidate should demonstrate:
-
Effective written and verbal communication skills.
-
Ability to produce technical documentation and security artefacts.
-
Experience working collaboratively with engineers, architects, project teams and business stakeholders.
-
Ability to explain technical concepts and security requirements in a clear and practical manner.
Qualifications, Certifications and Professional Development: Demonstrated qualifications and ongoing professional development relevant to cyber security and cryptography. Desirable qualifications include:
-
Degree, diploma or equivalent experience in Cyber Security, Information Technology, Computer Science, Mathematics, Engineering or related discipline.
-
Security-related certifications such as: Security, CISSP Associate, Certified Encryption Specialist (EC-Council), GIAC certifications, Vendor-specific security certifications Evidence of continuous learning and professional development will be viewed favourably.
Desirable criteria
-
Experience working within ASD, Defence, National Intelligence Community or other Commonwealth agencies
-
Familiarity with: Information Security Manual (ISM), Protective Security Policy Framework (PSPF), Essential Eight, Australian Signals Directorate guidance and security principles
-
Experience supporting cloud cryptography capabilities in Azure, AWS or other Government-approved cloud environments
-
Experience with cryptographic key management, certificate authorities or secure communications platforms.