Lead Cryptography Security Engineer (PROJ-4806)

Canberra
11 September 2026
PV
Application ends: 1 October 2026
Apply Now
Deadline date:
1 October 2026
$160 - $180

Job Description

Remote is seeking an experienced Security Engineer / Cryptographic Systems Engineer (SFIA Level 5) to support the delivery of an enterprise-scale Key Management System across ASD’s multi-class security environment. The role will provide technical expertise in cryptographic technologies, key lifecycle management, hardware security modules, certificate services and encryption solutions, while working with architecture, cyber security, infrastructure, cloud, application and vendor teams to engineer, integrate and support a resilient, compliant and secure cryptographic capability. (LH-07705)

Role Description

Key duties and responsibilities:

Cryptographic Engineering

  • Design, deploy and configure enterprise key management infrastructure and supporting cryptographic services.

  • Implement cryptographic key lifecycle processes including generation, storage, rotation, archival, recovery and destruction.

  • Configure and support Hardware Security Modules (HSMs) and associated cryptographic services.

  • Implement encryption key management controls across enterprise systems and platforms.

  • Support cryptographic solution testing, validation and operational readiness activities.

  • Develop engineering standards, operational procedures and implementation guidance.

  • Ensure cryptographic services meet availability, performance and resilience requirements

System Integration

  • Integrate KMS capabilities with enterprise platforms, applications and infrastructure services.

  • Implement secure API-based integrations supporting cryptographic operations.

  • Support integration with identity, access management and authentication services.

  • Configure encryption services across cloud, hybrid-cloud and on-premises environments.

  • Support certificate management and machine identity services.

  • Troubleshoot and resolve integration and interoperability issues.            

  • Develop automation scripts and deployment mechanisms where required.

Security Engineering

  • Implement security controls in accordance with ASD ISM, PSPF and security architecture requirements.

  • Support secure configuration, hardening and ongoing maintenance of cryptographic systems.

  • Conduct security assessments and technical risk analysis.

  • Investigate security incidents affecting cryptographic infrastructure and services.

  • Support vulnerability management and remediation activities.

  • Participate in security reviews, design assurance and accreditation activities.

  • Ensure compliance with approved security baselines and standards.

Operations and Support

  • Provide technical support for enterprise cryptographic services.

  • Monitor system health, performance and availability.

  • Develop operational runbooks and support documentation.

  • Support disaster recovery, backup and business continuity arrangements.

  • Participate in change, release and configuration management processes.

  • Maintain technical documentation and engineering artefacts.

  • Provide specialist advice to operational and project teams.

Technical skills

  • Degree qualification in Cyber Security, IT, Computer Science, Engineering or related discipline.

  • Industry-recognised cyber security certification.

  • Cryptographic security or encryption-related training.

  • Cloud security certification (AWS, Azure or Google Cloud).

  • Vendor certification for KMS, HSM or encryption technologies.

  • ITIL Foundation or equivalent service management certification.

  • demonstrated SFIA Level 5 capability or equivalent


Essential criteria

Technical Capability and Expertise: Demonstrated capability to perform at SFIA Level 5 and provide independent specialist advice relating to the design, implementation, assurance and operation of cryptographic systems within secure ICT environments. The candidate should demonstrate experience in:

  • Designing, implementing and supporting cryptographic solutions within complex enterprise or classified environments.

  • Application of contemporary cryptographic principles, protocols and standards.

  • Public Key Infrastructure (PKI) design, management and lifecycle operations.

  • Key Management Systems (KMS) and Hardware Security Modules (HSMs).

  • Secure communications, encryption technologies and key distribution mechanisms.

  • Cryptographic assurance, validation and risk assessments.

  • Security architecture design and integration of cryptographic controls.

  • Application of ASD security frameworks, security principles and relevant government security requirements.

  • Identification and remediation of cryptographic vulnerabilities and weaknesses. Evidence may include project examples, achievements, technical certifications and demonstrated outcomes.

Relevant Experience and Delivery Record: Demonstrated experience delivering cryptographic engineering services within comparable environments. The candidate should demonstrate:

  • Experience supporting Commonwealth, Defence, National Security or similarly regulated environments.

  • Delivery of cryptographic capability projects across planning, implementation and operational phases.

  • Experience contributing to secure system accreditation, certification or assurance activities.

  • Delivery of security outcomes within complex stakeholder environments.

  • Proven ability to manage competing priorities and deliver high-quality outcomes within agreed timeframes. Responses should provide specific examples outlining the candidate's role, responsibilities and outcomes achieved.

Security Risk and Assurance Capability: Demonstrated ability to identify, assess and manage cryptographic and cyber security risks. The candidate should demonstrate:

  • Experience undertaking security risk assessments and security assurance activities.

  • Understanding of cryptographic threat modelling and vulnerability management.

  • Experience providing evidence-based security recommendations to technical and non-technical stakeholders.

  • Ability to analyse emerging threats and assess impacts on cryptographic systems and controls.

  • Experience supporting audit, compliance and assurance engagements.

Stakeholder Engagement and Communication: Demonstrated ability to engage effectively with a broad range of stakeholders and provide strategic and technical advice. The candidate should demonstrate:

  • Strong written and verbal communication skills.

  • Ability to translate complex cryptographic concepts into business-focused advice.

  • Experience engaging with senior executives, project teams, security practitioners and vendors.

  • Ability to prepare technical documentation, reports, risk assessments and briefing material.

Qualifications, Certifications and Professional Development: Demonstrated qualifications and professional development relevant to cryptography, cyber security and information security. Desirable qualifications may include:

  • Degree in Computer Science, Cyber Security, Information Security, Engineering, Mathematics or related discipline.

  • CISSP, CISM, CCSP or equivalent security certification.

  • Certified Cryptographic professional qualifications or relevant vendor certifications.

  • Demonstrated commitment to continuous professional development.

Desirable criteria

  • Experience working within ASD, Defence, National Intelligence Community or other Commonwealth agencies.

  • Familiarity with: Information Security Manual (ISM), Protective Security Policy Framework (PSPF), Essential Eight, Australian Cryptographic Evaluated Products Program (ACEPP), Secure-by-Design and Zero Trust principles.

  • Experience supporting cloud cryptography controls across Azure, AWS or other government-approved cloud platforms.

  • Experience with quantum-resistant cryptography assessments, transition planning or emerging cryptographic standards.