YD

Senior Security Engineer

Yolk Digital
Posted 1 hour ago
AustraliaHybridEngineering & Development
Is this job info correct?

Applications Close: 11:59pm Wednesday 16 September 2026


Job Details

Yolk Digital is engaged by the Department of Industry, Science and Resources to provide an experienced Senior Security Engineer to the Platform Services team, where you'll help operate, maintain and continually improve the department's ICT infrastructure and endpoint security platforms, with a strong focus on secure, reliable and supportable services.


Your work spans the enterprise Windows Server estate, endpoint protection and application control technologies (Airlock Digital, Symantec Endpoint Protection and Microsoft Defender), identity and privileged access management platforms (Microsoft Identity Manager, Unify Broker, CyberArk and Secret Server) and the surrounding infrastructure services: Active Directory, Entra ID, DNS, PKI, Group Policy, DFS, SCOM, SCCM/MECM and Intune.


You'll partner closely with Platform Services colleagues, Cyber Security, infrastructure and application teams, project delivery areas, vendors and business stakeholders. The role balances business-as-usual support with project delivery, security uplift, vulnerability remediation, platform lifecycle management, documentation and knowledge transfer, so you'll be as comfortable assessing a CVE and planning its remediation as you are hardening a Server Core host or taking a policy change through change management.


Location

ACT. Hybrid. Flexible work is generally supported in line with business needs. Remote working arrangements may be considered on a case-by-case basis in consultation with the supervising manager. Maximum 40 hours per week.


Duration

6 months, commencing 5 October 2026, with two 12 month extension options.


Citizenship

Australian Citizen


Clearance

Baseline


Key Responsibilities

  • Support and maintain enterprise endpoint security platforms, including application control, endpoint protection, endpoint detection and response (EDR), host-based firewalls, vulnerability management and device control technologies.
  • Administer and support technologies such as Airlock Digital, Symantec Endpoint Protection and Microsoft Defender, including platform configuration, policy maintenance, agent health and lifecycle management.
  • Plan and deliver security platform patching, upgrades, policy changes and agent deployments through established change management processes.
  • Assess and implement application whitelisting, application unblocking, antivirus exclusion and security policy requests in consultation with system owners and Cyber Security.
  • Monitor and respond to CVEs, vendor advisories, security findings and vulnerabilities, including impact assessment, remediation planning, testing and implementation.
  • Provide operational and project support across enterprise Windows Server environments and related infrastructure services, including Windows servers without a GUI (Server Core).
  • Support Windows Server lifecycle and modernisation activities, including upgrades, migrations, patching, hardening, compatibility assessment and transition to supported operating system versions.
  • Administer and troubleshoot technologies including Active Directory, Entra ID, DNS, PKI, Group Policy, DFS, SCOM, SCCM/MECM and Intune.
  • Support and maintain enterprise identity management platforms, including Microsoft Identity Manager and Unify Broker.
  • Contribute to the support and maintenance of privileged access management solutions such as CyberArk and Secret Server.
  • Undertake troubleshooting and provide technical advice on identity, authentication, access and privileged access issues and workflows.


Skills & Experience

  • Administration of enterprise endpoint security platforms: application control, endpoint protection, EDR, vulnerability management, host-based firewalls and device control
  • Hands-on experience with Airlock Digital, Symantec Endpoint Protection, Microsoft Defender for Endpoint and Microsoft Defender Vulnerability Management
  • Responding to CVEs, vendor advisories and security findings, from impact assessment through remediation, testing and change implementation
  • Detailed Windows Server experience across Active Directory, Entra ID, DNS, PKI, Group Policy, DFS, SCOM, SCCM/MECM, Intune and Azure Virtual Desktop
  • Supporting identity and privileged access management platforms such as Microsoft Identity Manager, Unify Broker, CyberArk and Secret Server


Essential Criteria

1. Enterprise endpoint security platforms: Demonstrated experience administering and supporting enterprise endpoint security platforms, including application control, endpoint protection, EDR, vulnerability management, host-based firewalls, device control and security policy ma

nagement.

2. Security product experience: Experience with Airlock Digital application control, Symantec Endpoint Protection, Microsoft Defender for Endpoint, Microsoft Defender Vulnerability Management or comparable enterprise security products.

3. Vulnerability and incident response: Experience responding to CVEs, vendor advisories, security findings and production issues, including impact assessment, troubleshooting, remediation, testing, change implementation and vendor engagement.

4. Windows Server and Microsoft platform depth: Detailed Windows Server understanding and experience including Active Directory, Entra ID, DNS, PKI, DFS, Microsoft System Centre products and Intune (SCOM, SCCM/MECM) and Azure Virtual Desktop.


Desirable Criteria

  • Australian Government cyber security requirements: Knowledge of Australian Government cyber security requirements, including the Information Security Manual, Essential Eight maturity model and ACSC security guidance, with experience contributing to implementation or assurance of security controls. Experience working in an Australian Government or similarly regulated environment.
  • Red Hat Enterprise Linux and automation: Experience administering Red Hat Enterprise Linux, including patching, security hardening, lifecycle management and enterprise service integration, with demonstrated experience using Ansible or similar automation and configuration management tools to deploy, configure, patch and maintain infrastructure.
  • DevOps, hybrid management and IAM/PAM: Experience with infrastructure-as-code, source control, CI/CD pipelines, Azure DevOps, Azure Arc or related DevOps and hybrid management practices. Experience with IAM and PAM principles, access governance and access control, including knowledge and experience with IAM technology such as MIM, Unify Broker and Entra ID.
  • Technical documentation: Strong experience in writing technical documentation including SOPs and design documentation.


Application Instructions

Upload a one page pitch addressing all criteria specified. This includes responding to the Job Details, Key Responsibilities, and Essential Criteria. The pitch cannot be more than 5000 characters.


If you have worked at the Department of Industry, Science and Resources before, include with your application the branch and division you worked in, your role and your dates.


Structure your pitch using the STAR format (Situation, Task, Action, Result) and sell your capability rather than listing duties. Target each of the four Essential Criteria directly: name the endpoint security platforms you have administered (application control, EDR, vulnerability management, host-based firewalls, device control and policy management); the specific products you have run, such as Airlock Digital, Symantec Endpoint Protection, Microsoft Defender for Endpoint or Defender Vulnerability Management; concrete examples of taking a CVE or vendor advisory from impact assessment through remediation, testing and change implementation; and the depth of your Windows Server, Active Directory, Entra ID, DNS, PKI, DFS, System Centre, Intune and Azure Virtual Desktop experience. Where you can, address the Desirable Criteria as well, particularly Essential Eight and ISM experience, Red Hat and Ansible work, DevOps practices and IAM/PAM tooling, and your record of writing SOPs and design documentation.


Applications close 11:59pm Wednesday 16 September 2026. Apply via the website: https://yolkdigital.com.au/site-data/jobs/senior-security-engineer

Similar jobs