LH-08069
buyict×2Senior Infrastructure Cloud Engineers
2 Senior Infrastructure Cloud Engineers
3 agency ads are matched to this contract. Sign up free to see which agency is advertising it, why it matched, and the ad itself.
Sign up freeYour CVs matching this role
0Sign in to see which of your uploaded CVs match this role.
Candidate Search
Find candidates for this role externally, then cache them here.
Sign in to search candidates for this role.
Job description
DEPARTMENT OF FINANCE WILL NOT CONSIDER OR INVITE ADDITIONAL SELLERS TO THIS RFQ. UNSOLICITED EMAILS AND REQUESTS WILL NOT BE ANSWERED. Finance is seeking two Infrastructure / Cloud Engineers to assess, design, configure and support the infrastructure, platform and cloud dependencies required for the Identity and Access Management Modernisation (IAMM) project. The roles will work across Microsoft Entra ID, Active Directory, AD Federated Services, servers, networking, endpoints, virtual desktops, remote access, monitoring, non-production environments and managed services to ensure identity changes are secure, resilient, supportable and operationally ready. The IAMM Project will modernise Finance’s identity and access management capabilities and transition from legacy Microsoft Identity Manager (MIM) and Active Directory Federation Services (AD FS) arrangements to a supported, cloud-ready architecture in which Microsoft Entra ID is Finance’s primary identity directory and modern identity platform. SAP HR remains the authoritative source of workforce attributes. Downstream on-premises Active Directory accounts and services will be retained only where required for legacy dependencies, prior to MIM reaching end of extended support on 9 January 2029. The project supports Finance’s ICT and Digital Strategy, Cyber Security Strategy, 10-Year ICT Roadmap and Infrastructure Modernisation Program. The project will: Establish Microsoft Entra ID as Finance’s primary identity directory and modern identity platform. Reduce reliance on MIM, AD FS and other legacy identity technologies. Strengthen cyber security through modern authentication, Conditional Access, phishing-resistant MFA, Identity Protection and identity governance capabilities. Integrate authoritative workforce identity sources and automate Joiner-Mover-Leaver processes. Migrate supported applications from AD FS to Microsoft Entra ID and Single Sign-On. Improve privileged access, access reviews, entitlement management, group governance, audit and reporting. Provide supported, sustainable operating arrangements, documentation, training and knowledge transfer. Support the Secure Access Service Edge (SASE), Laptop Refresh and Finance’s broader move towards cloud services and Zero Trust architecture. Note: SASE is being delivered by a concurrent multi-year program and will modernise how users securely access Finance systems and services, moving from traditional network-based access controls to an identity-centric, Zero Trust model. Key duties and responsibilities The successful candidates (as Infrastructure Cloud Engineers) will undertake the following duties and responsibilities: Assess infrastructure and cloud dependencies affecting identity synchronisation, authentication, administration, application access, integration and migration sequencing. Support the design and implementation of secure hybrid infrastructure patterns for Entra ID, Active Directory, retained legacy services and approved target integrations. Assess and document impacts across hybrid-joined and cloud-managed devices, Windows Hello for Business, Intune or co-management, iOS, Citrix, virtual desktops, remote desktop and remote-access services. Prepare, configure and maintain development, test, UAT, pre-production and production infrastructure required for proofs, integration testing and migration rehearsals. Coordinate network, firewall, DNS, certificate, proxy, load-balancing, connectivity, service-account and managed-service requirements for integration and SSO migrations. Implement or support non-production and production environments, monitoring, logging, alerting, backup, recovery, resilience, capacity and operational-support arrangements. Support secure administrative access, privileged workstations, tier separation, authentication-tier segmentation and least-privilege controls. Automate repeatable infrastructure and configuration activities using approved scripting, configuration-management and source-control practices. Contribute to infrastructure and cloud designs, risk assessments, controlled deployment run sheets, Requests for Change, rollback and recovery plans and production verification. Support controlled production implementation, issue resolution, troubleshooting, hyper-care and transition to Finance operational teams. Produce and maintain detailed infrastructure designs, as-built and as-configured documentation, configuration records, SOPs, support guides, recovery procedures and knowledge-transfer material. Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters. Essential criteria 1. Labour Hire Workers and Supplier Personnel MUST include in their response to the RFQ any potential conflicts of interest which may arise in performing duties during the term of the Contract. This includes (but is not limited to): owning interests and/or ongoing employment with ICT businesses who deliver services to the Commonwealth; have vested interests in ICT technologies; have l relationships with Buyer personnel involved in the Contract’s scope. Response to this question does not count towards a candidate’s word/page limit. Desirable criteria 1. All Candidates with respect to their Seller will be evaluated against the evaluation criterion listed in this “Desirable Criteria” section. The evaluation criteria are unweighted. Evaluation Criterion 1: The extent to which a candidate & seller demonstrates an understanding and appreciation of the Requirements (Role description + Key duties and responsibilities + Technical Skills). 2. Evaluation Criterion 2: The extent to which a candidate & seller demonstrates the capacity, capability, and experience to fulfil the Requirements (Role description + Key duties and responsibilities + Technical Skills) to a high standard and within any specified timeframes. • The Buyer will consider potential onboarding delays and impacts to timeframes if candidates does not possess a current security clearance. • The Buyer will consider non-compliance with details of the Working Arrangement. 3. Evaluation Criterion 3: The risk associated with a candidate and/or seller. Including (but not limited to) those identified during interviews; referee reports; non-compliance with contract terms and conditions; financial viability risks; conflicts of interest; and any other due diligence checks considered by the Buyer. 4. Evaluation Criterion 4: The pricing and whole-of-life costs associated with a candidate and/or seller. Opportunity summary Sellers can submit Up to 5 candidates Number of sellers invited Between 5 and 10 Number of candidates submitted Fewer than 10 Send us feedback About Accessibility Privacy Terms of use Disclaimer and copyright An initiative of the Digital Transformation Agency The Australian Government acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present. © Commonwealth of Australia
3 matches locked
Sign up to see which agency is advertising for this contract, the match evidence, and the ad itself.
Other open contracts for Department of Finance
- LH-08075Lead Information ArchitectACTcloses in 6 days
- LH-08068Lead Technical Business AnalystACTcloses in 8 days
- LH-08067Identity Solution ArchitectACTcloses in 8 days
- LH-08065Manager Technical Program / Project ManagerACTcloses in 8 days
- LH-08059MS Power Platform Application ArchitectACTcloses in 1 day