← all opportunities

LH-07730

buyict×1Closed

Lead Security Architect

1 Lead Security Architect

Department of FinanceInvitation not statedACTclosed 14 Sept 2026

3 agency ads are matched to this contract. Sign up free to see which agency is advertising it, why it matched, and the ad itself.

Sign up free

Your CVs matching this role

0

Sign in to see which of your uploaded CVs match this role.

Candidate Search

Find candidates for this role externally, then cache them here.

Sign in to search candidates for this role.

Job description

DEPARTMENT OF FINANCE WILL NOT CONSIDER OR INVITE ADDITIONAL SELLERS TO THIS RFQ. UNSOLICITED EMAILS AND REQUESTS WILL NOT BE ANSWERED.  The Department of Finance (Buyer) is seeking a self-motivated and experienced Security Architect to lead the assessment, identification and implementation solutions to improve the Buyer’s cyber security posture and support an enterprise approach to cyber security architecture and practices.    The Security Architect is responsible for ensuring security requirements, principles, and controls are embedded into the Buyer’s enterprise architecture, technology investments, and digital transformation initiatives. The Security Architect provides strategic security architecture leadership, ensuring technology solutions are secure by design, aligned to enterprise objectives, and compliant with government security obligations.  The Security Architect works closely with Enterprise Architects, Solution Architects, Cyber Security teams, other security architects and project delivery teams to develop target-state security architectures, security standards, and architectural roadmaps that enable secure and resilient business outcomes.  The Security Architect ensures security is integrated into enterprise architecture and technology decision-making from the outset, rather than being applied as a compliance activity after solutions are designed. The role reduces organisational risk, improves consistency of security controls across the technology portfolio, supports regulatory compliance, and enables the delivery of secure, resilient, and trusted digital services. It also strengthens the maturity of the organisation's enterprise architecture capability by providing a dedicated security architecture function aligned to strategic business outcomes.  Key duties and responsibilities The successful candidate (as Security Architect) will undertake the following duties and responsibilities:  Lead the design and assurance of secure technology solutions for ICT projects, ensuring alignment with security policies, standards, and business objectives.  Provide security architecture advice across cloud, infrastructure, applications, data, identity, and integration domains.  Identify, assess, and mitigate security risks throughout the solution lifecycle, ensuring appropriate controls are implemented.  Develop security patterns, standards, reference architectures, and design guidance to support consistent and secure delivery outcomes.  Conduct security architecture reviews and support governance processes, including risk assessments and design assurance activities.  Collaborate with project teams, enterprise architects, cyber security specialists, and business stakeholders to ensure security requirements are embedded by design.  Contribute to cyber security strategy, security uplift initiatives, and the continual improvement of the organisation's security architecture capability.  Advise on security architecture with explicit consideration to the ISM, PSPF and leading security practices such as Zer-Trust Architecture.   Any other responsibility or instruction given by the Enterprise Architect. Chief Information Security Officer or other APS Officials.  Desirable skills and experience of the successful candidate:  Highly Desirable  Demonstrated experience designing and assuring secure ICT solutions across complex technology environments.  Strong knowledge of cyber security principles, risk management, identity and access management, cloud security, and security architecture practices applied at an enterprise level.  Proven ability to engage stakeholders and provide trusted security advice throughout project and solution delivery lifecycles.  Experience with cyber security technologies, practices and concepts in a multi-cloud hybrid technology environment.   Experience uplifting cyber security posture for government organisations by applying cyber security strategies and practices such as Zero-Trust Architecture.   Desirable Criteria  Experience developing security architectures, security standards, and enterprise cyber security roadmaps and strategies.  Knowledge of Australian Government security frameworks and standards, including ISM, PSPF, Essential Eight, and IRAP.  Relevant certifications such as SABSA, CISSP, CCSP, Azure Security Engineer, AWS Security Specialty, or equivalent.  Experience and knowledge with enterprise architecture concepts and qualifications (such as TOGAF).  Experience implementing security controls that directly improve cyber security posture and maturity across an enterprise.   Evaluation Notes:  Candidates are encouraged to explicitly address desirable skills and experience in their RFQ response, demonstrating their possession of these traits.   The “evaluation criteria” later detailed in the RFQ (understanding, capacity & capability, risk, price) represents the broader criteria adopted by the Buyer when assessing a Seller’s response for Value for Money.  Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters. Essential criteria 1. Labour Hire Workers and Supplier Personnel MUST include in their response to the RFQ any potential conflicts of interest which may arise in performing duties during the term of the Contract. This includes (but is not limited to): owning interests and/or ongoing employment with ICT businesses who deliver services to the Commonwealth; have vested interests in ICT technologies; have l relationships with Buyer personnel involved in the Contract’s scope. Response to this question does not count towards a candidate’s word/page limit. Desirable criteria 1. All Candidates with respect to their Seller will be evaluated against the evaluation criterion listed in this “Desirable Criteria” section. The evaluation criteria are unweighted. Evaluation Criterion 1: The extent to which a candidate & seller demonstrates an understanding and appreciation of the Requirements (Role description + Key duties and responsibilities + Technical Skills). 2. Evaluation Criterion 2: The extent to which a candidate & seller demonstrates the capacity, capability, and experience to fulfil the Requirements (Role description + Key duties and responsibilities + Technical Skills) to a high standard and within any specified timeframes. * The Buyer will consider potential onboarding delays and impacts to timeframes if candidates does not possess a current security clearance. * The Buyer will consider non-compliance with details of the Working Arrangement. 3. Evaluation Criterion 3: The risk associated with a candidate and/or seller. Including (but not limited to) those identified during interviews; referee reports; non-compliance with contract terms and conditions; financial viability risks; conflicts of interest; and any other due diligence checks considered by the Buyer 4. Evaluation Criterion 4: The pricing and whole-of-life costs associated with a candidate and/or seller. Opportunity summary Sellers can submit Up to 2 candidates Number of sellers invited More than 10 Number of candidates submitted Fewer than 10 Send us feedback About Accessibility Privacy Terms of use Disclaimer and copyright An initiative of the Digital Transformation Agency The Australian Government acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present. © Commonwealth of Australia

3 matches locked

Sign up to see which agency is advertising for this contract, the match evidence, and the ad itself.

Other open contracts for Department of Finance

Related reading