Cyber Security Architect

Yolk Digital

Applications Close: 11:59pm Sunday 11 October 2026

Job Details

Yolk Digital is engaged by the Department of the Treasury to provide an experienced Cyber Security Architect to be the technical lead for cyber security architecture, shaping how the department detects, investigates and responds to threats across its core security platforms.

The role centres on the cyber security technology estate: SIEM and enterprise logging, Microsoft Entra and Active Directory security, Microsoft Purview, Defender for Endpoint and Defender for Identity, Azure and hybrid cloud security, proxy and secure web gateway services, CASB, network security integrations and vulnerability management. You'll also touch emerging areas such as artificial intelligence.

You'll sit primarily in the Cyber Security team and work with Cloud Infrastructure, Network Infrastructure, End User Computing, enterprise architecture and project teams. You'll investigate technical dependencies and gaps in Treasury's deployed environment, design security solutions that can actually be implemented, and guide those changes through to an operational outcome.

Your work will lift monitoring coverage, rationalise duplicated or legacy security tooling, and set clear technical requirements for procurements and managed security services, validated against what is really deployed rather than generic product claims.

Location

ACT. Onsite. Up to 40 hours per week.

Duration

12 months, commencing 2 November 2026, with 1 extension option of 12 months.

Clearance

NV1. You must be able to obtain Negative Vetting Level 1.

Citizenship

Australian Citizenship is required.

Key Responsibilities

Security Monitoring and SIEM Architecture

* Own and maintain the architecture for Treasury's enterprise security monitoring capability, including Rapid7 SIEM, Windows Event Collection, Azure and cloud telemetry, network security logs, proxy logs, Microsoft Defender data and other priority security sources.

* Define logging, telemetry, retention, data flow and integration requirements for new and existing systems, aligned with Treasury requirements and relevant ASD priority logging guidance.

* Identify monitoring blind spots, duplicated or misconfigured log sources, unsupported collection paths and gaps in event coverage.

* Design sustainable processes and technical patterns for onboarding systems and services into the SIEM.

* Ensure monitoring architecture supports threat detection, threat hunting, incident investigation, forensic readiness, audit and managed security services.

Endpoint and Server Security Architecture

* Provide architecture leadership for Microsoft Defender for Endpoint, Microsoft Purview and Microsoft Defender for Identity, including sensor architecture, onboarding, configuration baselines, telemetry coverage and operational integration, including into AI-enabled systems.

* Design security requirements for endpoints, servers, domain controllers, administrative workstations and specialised or non-user devices.

* Review endpoint and server hardening, attack surface reduction, endpoint detection and response, vulnerability exposure and security configuration management.

* Identify legacy agents, duplicated tooling, unsupported components and configuration gaps, reduce risk scores and develop practical rationalisation or remediation approaches.

* Ensure endpoint and identity security capabilities are incorporated into standard infrastructure deployment and support processes.

Cyber Security Platforms and Tooling

* Provide architecture leadership across Treasury's cyber security platforms, including SIEM, vulnerability management, Microsoft security tooling, network security services and cloud-native security controls.

* Assess whether security products and capabilities are correctly configured, integrated and used in accordance with Treasury's technical and operational requirements.

* Develop target architectures and technical roadmaps for the rationalisation, replacement or uplift of security platforms.

* Define specific and measurable technical requirements for procurements, vendor engagements and managed security services.

* Validate vendor and project designs against Treasury's deployed environment rather than relying on generic product capability statements.

Architecture Governance and Technical Delivery

* Lead cyber security architecture reviews for infrastructure, identity, endpoint, network, cloud, SaaS, application and data initiatives.

* Produce and maintain high-level designs, detailed designs, integration diagrams, security patterns, architecture decision records, technical standards and implementation roadmaps.

* Provide clear recommendations on technical risks, design choices, dependencies, implementation sequencing and remediation priorities.

* Validate that delivered solutions match approved designs and that architecture documentation accurately reflects the deployed environment.

* Provide hands-on technical analysis of configurations, data flows, access models, firewall and proxy dependencies, logging pathways and security control implementation.

* Apply the ISM, PSPF, Essential Eight, ASD guidance and Treasury security requirements in a technically practical manner.

Skills & Experience

* Cyber security architecture and engineering across complex enterprise environments

* SIEM architecture and enterprise security monitoring, including Rapid7 and Windows Event Collection or equivalent

* Microsoft Defender for Endpoint and Defender for Identity, including sensor design, configuration baselines and telemetry coverage

* Endpoint and server hardening, attack surface reduction, vulnerability exposure and security configuration management

* High-level and detailed designs, data-flow diagrams, architecture decision records, technical standards and roadmaps

* ISM, PSPF, Essential Eight and ASD guidance

* Cross-team technical leadership and clear written and verbal communication

Essential Criteria

1. Cyber Security Architecture and Engineering: Demonstrated experience designing, integrating and uplifting cyber security technologies across complex enterprise environments. Experience must span multiple security domains and include evidence of translating architecture into implemented, supportable operational outcomes.

2. Endpoint, Security Monitoring, Server and Microsoft Security Technologies: Demonstrated experience designing and maintaining enterprise security monitoring capabilities, including SIEM architecture, as well as with Microsoft Defender for Endpoint and Microsoft Defender for Identity, including architecture, deployment, sensor or agent design, configuration baselines, telemetry coverage and integration with security operations. Experience with endpoint and server hardening, attack surface reduction, vulnerability exposure and security configuration management is also required. Experience with Rapid7, Windows Event Collection or equivalent technologies is highly desirable.

3. Architecture Artefacts and Technical Assurance: Demonstrated experience producing technically accurate high-level and detailed designs, integration and data-flow diagrams, security patterns, architecture decision records, technical standards and implementation roadmaps. Demonstrated ability to validate that delivered solutions and supporting documentation align with approved designs and the deployed environment.

4. Government Security Frameworks: Demonstrated ability to apply the Australian Government Information Security Manual, Protective Security Policy Framework, Essential Eight and relevant ASD guidance to technical architecture, security control design and implementation decisions.

5. Cross-Team Technical Leadership: Demonstrated ability to work across cyber security, cloud, network, endpoint, enterprise architecture and project teams to investigate technical dependencies, resolve design constraints, challenge generic or vendor-led proposals and drive practical security outcomes.

6. Communication: Highly developed written and verbal communication skills, including the ability to explain complex technical issues, document defensible architecture decisions and provide clear technical direction to engineers, vendors, project teams and senior stakeholders.

Application Instructions

Upload a response to each of the six essential criteria. Each response cannot be more than 3000 characters.

How to write each response

* Use the STAR format: Situation, Task, Action, Result. Open with the environment you were working in, state what you were responsible for, describe what you personally did, and close with a measurable, operational outcome.

* Sell capability rather than listing duties. Treasury wants evidence you can turn architecture into something implemented and supportable.

* Answer the criterion as worded. Name the technologies (for example SIEM, Microsoft Defender for Endpoint and Identity, Entra, Rapid7 or Windows Event Collection) and the frameworks (ISM, PSPF, Essential Eight, ASD guidance) where you have genuinely used them.

* Show the artefacts you produced: high-level and detailed designs, data-flow diagrams, architecture decision records, standards and roadmaps.

* Give at least one example where you worked across teams, challenged a vendor-led or generic proposal, and drove a practical security outcome.

If you have worked at the Department of the Treasury before, include with your application the branch and division you worked in, your role and your dates.

https://yolkdigital.com.au/site-data/jobs/cyber-security-architect

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.