Cyber Security Architect
$160 per hourAzooa
PRINCIPAL ENTERPRISE ARCHITECT – CRYPTOGRAPHIC SERVICES / PKI TECHNICAL LEAD | DFAT | CANBERRA | NV1/NV2
Are you a senior Architect with strong experience across Public Key Infrastructure (PKI), Hardware Security Modules (HSMs), certificate management, key management and associated trust services — holding an active NV1 or higher clearance and available to work onsite in Canberra?
Azooa is preparing a response for RFQ LH-07503 with the Department of Foreign Affairs and Trade (DFAT) and is seeking suitably qualified contractors for a Principal Enterprise Architect – Cryptographic Services / PKI Technical Lead engagement.
This is a senior Principal / EL2-equivalent opportunity within DFAT’s Cyber Security, Cloud and Networks Branch, focused on assessing, enhancing and maturing the Department’s enterprise cryptographic services capability.
Location: Canberra, ACT
Working arrangement: 100% onsite – 5 days per week
Clearance: Active NV1 minimum | NV2 preferred
Estimated start: 26 October 2026
Initial term: 12 months
Extensions: 2 × 12 months
Maximum hours: 40 hours per week
Potential tenure: Up to 3 years
ABOUT THE OPPORTUNITY
DFAT’s Cyber Security, Cloud and Networks Branch is responsible for delivering and operating critical cyber security, identity and trust services supporting departmental and business outcomes.
The successful contractor will support the assessment, enhancement and future delivery of DFAT’s enterprise cryptographic capability across areas including:
Public Key Infrastructure – PKI
Hardware Security Modules – HSMs
Certificate lifecycle management
Cryptographic key management
Identity and high-assurance trust services
Security and solution architecture
Cryptographic governance
Technical assurance
Security risk management
Operational process improvement
Transition planning
Future-state service design
The role requires a senior technical leader capable of balancing solution architecture, cyber security, governance, policy, operational resilience and practical delivery requirements within a complex Australian Government environment.
CORE RESPONSIBILITIES
The successful candidate will provide architectural and technical leadership for the delivery, governance and ongoing evolution of DFAT’s cryptographic services.
• Provide technical leadership across enterprise PKI, HSM and cryptographic services
• Assess current cryptographic capabilities and undertake architecture, security, governance and operational gap analysis
• Define and maintain target-state cryptographic architectures
• Establish appropriate trust models, key-management approaches, security standards and availability requirements
• Develop practical capability improvement roadmaps and future-state plans
• Act as a senior technical authority for cryptographic and security architecture decisions
• Lead solution architecture and detailed technical design
• Ensure secure implementation, deployment and operational practices
• Identify and manage cryptographic risk, technology dependencies and operational resilience requirements
• Develop and maintain cryptographic governance artefacts, policies, standards, procedures and operating models
• Support PKI governance frameworks and certificate-management policies
• Establish security controls, assurance arrangements and risk-management processes
• Work across architecture, cyber security, infrastructure, engineering, business, project and operational teams
• Support engineering teams through design, build, testing, assurance, release and transition to operations
• Produce architectural artefacts, technical designs, implementation guidance and operational documentation
• Support upgrades, maintenance, testing, issue resolution and continual service improvement
• Provide authoritative advice to technical and non-technical stakeholders
• Mentor engineering and operational personnel and transfer specialist knowledge.
KEY DELIVERABLES
Current-state cryptographic capability assessments
Architecture, security and operational gap analysis
Target-state cryptographic architectures
PKI architecture artefacts
HSM architecture and integration designs
Trust models
Key-management architectures
Certificate lifecycle-management approaches
Cryptographic capability roadmaps
Future-state service designs
Governance frameworks
Certificate policies / Certification Practice Statements
Security-control and assurance frameworks
Operating models and decision authorities
Security-risk artefacts
Solution architecture documents
Detailed technical designs
Implementation and transition plans
Operational-readiness documentation
Sustainable support models
Knowledge-transfer and capability-uplift materials
ESSENTIAL EXPERIENCE
Cryptographic Security Architecture
Strong experience assessing, designing or improving enterprise security and cryptographic services involving areas such as:
• Public Key Infrastructure
• Hardware Security Modules
• Certificate lifecycle management
• Cryptographic key management
• Identity and trust services
• High-assurance security environments
You should be comfortable defining current and target-state architectures, identifying technical and governance gaps, developing trust models and security controls, and translating business and security requirements into practical enterprise solutions.
Governance, Policy & Operating Models
Experience developing sustainable governance arrangements for security, cryptographic, identity or trust services, including:
• Policies and standards
• Certificate policies
• Certification Practice Statements
• Key-management requirements
• Procedures
• Control frameworks
• Assurance arrangements
• Operating models and decision authorities
Delivery & Operational Readiness
Demonstrated experience across the secure technology lifecycle, including:
• Architecture and design
• Implementation
• Testing
• Security assurance
• Transition to operations
• Continual improvement
• Technical risk and dependency management
• Operational resilience
• Knowledge transfer and capability uplift
Technical Leadership
• Providing authoritative technical advice
• Explaining complex cryptographic issues to technical and non-technical stakeholders
• Resolving competing architecture, security and delivery priorities
• Influencing architecture, engineering, project, procurement and operational stakeholders
• Mentoring personnel and transferring specialist knowledge
HIGHLY DESIRABLE
Australian Government or Defence environments
Enterprise PKI / Certificate Authority environments
Hardware Security Modules
Cryptographic key-management technologies
Australian Government Information Security Manual – ISM
Gatekeeper PKI Framework
ICAO Doc 9303 / ICAO Public Key Directory
PKI supporting ePassports or electronic travel documents
Biometric identity systems
Country Signing Certification Authority – CSCA
Document Signing Certificates
Certificate Revocation List lifecycle management
Cryptographic key ceremonies
Multi-person control
HSM-based key protection
Cryptographic disaster recovery and assurance
Cryptographic agility
Post-quantum cryptography readiness
Active NV2 clearance
Candidates with strong adjacent experience across security architecture, cryptographic services, infrastructure architecture, PKI governance, identity and trust, or senior cyber technical leadership are also encouraged to apply where they can demonstrate the required architecture, governance and high-assurance security capability.
SECURITY CLEARANCE
Minimum: Existing active NV1
Preferred: Active NV2
Candidates who do not currently hold an active NV1 or higher clearance cannot be submitted for this opportunity.
ENGAGEMENT DETAILS
RFQ: LH-07503
Buyer: Department of Foreign Affairs and Trade
Role: Principal Enterprise Architect – Cryptographic Services / PKI Technical Lead
Level: Principal / EL2 equivalent
Location: Canberra ACT
Arrangement: 100% onsite
Remote working: Not available
Interstate-based candidates: Not being considered
Initial contract: 12 months
Extensions: 2 × 12 months
DFAT also operates a contractor stand-down period during December and January, generally around 4–6 weeks at DFAT’s discretion .
INDICATIVE RATE GUIDANCE
Based on recent Azooa contract wins and current Federal Government value-for-money positioning , our indicative maximum recommended bidding levels are:
Pty Ltd: up to
$160/hour + GST
PAYG: up to
$158/hour
These are recommended maximum bidding levels rather than target rates .
Candidates may nominate higher rates; however, rate competitiveness forms part of the overall value-for-money position. Higher rates are more likely to be supportable where the candidate brings exceptional specialist expertise across PKI, HSMs, cryptographic architecture, high-assurance environments, NV2 clearance or closely aligned DFAT/Defence experience .
Senior PKI Architects, Security Architects, Enterprise Architects, Cryptographic Services Architects, PKI Technical Leads, Identity & Trust Architects and HSM/Cryptographic Services specialists are encouraged to apply.
Please also feel free to share this opportunity with suitably qualified professionals within your network.
#Azooa #DFAT #CyberSecurity #PKI #Cryptography #EnterpriseArchitecture #SecurityArchitecture #HSM #PublicKeyInfrastructure #CyberSecurityJobs #CanberraJobs #GovernmentJobs #NV1 #NV2 #DefenceJobs #ICTJobs #SolutionArchitecture #InformationSecurity #IdentitySecurity
- security architect Canberra 2600, ACT
- cyber security architect Canberra 2600, ACT
- business development manager cyber security Canberra 2600, ACT
- IT cyber security Canberra 2600, ACT
- manager cyber security Canberra 2600, ACT
- software engineer cyber security Canberra 2600, ACT
- remote cyber security Canberra 2600, ACT
- cyber security Canberra 2600, ACT
- cloud security architect
- security architect