← all opportunities

LH-07952

buyict×1

Lead Security Engineer

1 Lead Security Engineer

Australian Digital Health Agencynv1Invited sellersHybridQLD, ACT, NSWcloses in 25 days

3 agency ads are matched to this contract. Sign up free to see which agency is advertising it, why it matched, and the ad itself.

Sign up free

Your CVs matching this role

0

Sign in to see which of your uploaded CVs match this role.

Candidate Search

Find candidates for this role externally, then cache them here.

Sign in to search candidates for this role.

Job description

The Australian Digital Health Agency requires the services of an experienced Security Engineer.   Security Engineers identify, assess and prioritise threat vulnerabilities identified through penetration testing and report findings to improve security architecture and enhance risk awareness. The Security Engineer will be required to undertake work that is very complex, sensitive and under broad management direction. This position plays a key role in establishing a modern defensible architecture to proactively protect the Agency against emerging and evolving threat landscape. The Security Engineer will be engaged at an Executive Level 1 (EL1) equivalent level.  This is the level expected of senior technical specialists with the Australian Public Service. The position sits under the Cyber Security Branch, within the Cyber Transformation and DevSecOps section.  The role requires a high level of engagement and collaboration to initiate impactful change.  The Security Engineer will work closely with Agency teams to build security into every stage of their product pipeline, while using modern defensible architectures and a DevSecOps approach. Key duties and responsibilities The key duties and responsibilities of the Security Engineer are as provided below, followed by the requirements necessary for the role: Key duties and responsibilities Develop cyber security standards to govern the implementation of Agency systems and software. Work with teams to create a set of consistent and reusable reference designs, and patterns. Work with internal cyber teams to identify and implement capability needed to support DevSecOps pipelines such as policy as code, continuous compliance, integrated risk process, dynamic evidence collection and reporting. Conducting threat modelling exercises to understand a products threat landscape, processing this information into relevant DevSecOps security mitigations. Prioritising and managing Cyber risk, providing teams with actionable recommendations for mitigating and minimising threats in their environment. Perform detailed maturity assessments of operational and software development teams, identifying gaps and creating remediation plans to iterate towards high performance and compliance. Develop and maintain application security tooling, providing support for adoption and integration with existing CI/CD pipelines, reporting tools, and assurance platforms. Provide expert implementation advice for cloud environments, continuous integration and continuous deployment pipelines, with a focus on building security into every stage of a products lifecycle. Continuously looking to innovate, looking for areas of opportunity to improve security using DevSecOps practices across the entire software supply chain and software development pipelines. Develop processes to review Agency code for vulnerabilities, security weaknesses, and ensuring adherence to secure coding standards. Review and remediate vulnerabilities identified by applications security tools, ensuring knowledge transfer back to development teams. Develop training programs and workshops to educate Agency teams, continuously improving their Cyber security and DevSecOps skillset. Develop data driven reporting dashboards to inform teams and management of their security performance, and overall capability to deliver efficient and scalable systems at speed. Champion of DevSecOps culture, challenging the Agency to continuously improve, partnering with teams instead of policing them to implement modern security. Effective management of change, collaborating with stakeholders to overcome obstacles and drive adoption of security initiatives, practices, and policies. Requirements  The Security Engineer will possess the following skills and experience. Essential A minimum of 3 years’ experience working with DevOps teams or Software Development teams, implementing secure by design principles and automated security testing capabilities. Strong Experience building CI/CD pipelines, experience with Azure DevOps and AWS Code Suite is preferred.  Strong communication skills capable of building relationships and influencing outcomes across technical and business stakeholders. Experience developing security controls across cloud, infrastructure, applications, networks and endpoints. Experience with conducting security reviews, validating control effectiveness, troubleshooting security issues and providing technical advice to projects and operational teams. Desirable Formal Cyber Security, Software Development, or DevOps training is highly desirable. Security Clearance: The Labour Hire Worker must be able to obtain and maintain Negative Vetting 1 (NV1) Merit Pool: A merit pool may be created as part of this procurement process to fill similar roles, if the Agency identifies a need for additional resources at a later date.  Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters. Essential criteria 1. A minimum of 3 years’ experience working with DevOps teams or Software Development teams, implementing secure by design principles and automated security testing capabilities. 2. Strong Experience building CI/CD pipelines, experience with AzureDevOps and AWS Code Suite is preferred. 3. Strong communication skills capable of building relationships and influencing outcomes across technical and business stakeholders. 4. Experience developing security controls across cloud, infrastructure, applications, networks and endpoints. 5. Experience with conducting security reviews, validating control effectiveness, troubleshooting security issues and providing technical advice to projects and operational teams. Desirable criteria 1. Formal Cyber Security, Software Development, or DevOps training is highly desirable. Opportunity summary Sellers can submit Up to 4 candidates Number of sellers invited Between 5 and 10 Number of candidates submitted Fewer than 10 Send us feedback About Accessibility Privacy Terms of use Disclaimer and copyright An initiative of the Digital Transformation Agency The Australian Government acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present. © Commonwealth of Australia

3 matches locked

Sign up to see which agency is advertising for this contract, the match evidence, and the ad itself.

Other open contracts for Australian Digital Health Agency

Related reading