Infrastructure Engineer
Summary
Day-rate contract role in Sydney (hybrid) for an Infrastructure Engineer to remediate pen-test findings: hardening a hybrid Windows Server/Azure environment, patch compliance (Intune, SCCM, Azure Update Manager), Azure WAF, Entra ID hardening, Qualys/Defender/Sentinel triage, and aligning to Essential Eight and ISO 27001.
Salary: Day Rate
Day Rate Contract - Infrastructure Engineer (Security) - Pen Test remediation - Sydney/HybridOur client is running a security remediation program off the back of a recent penetration test and needs an experienced Infrastructure Engineer to lead the technical fix-up. This isn't BAU support, you'll be closing pen test findings, hardening a hybrid Windows and Azure environment, and proving compliance uplift on a live project.
What you'll be doing:
- Remediating critical and high vulnerabilities from pen test findings across endpoints, on-prem servers, and Azure
- Managing patch and update compliance (Intune, SCCM, Azure Update Manager, WSUS/GPO)
- Implementing and tuning Azure WAF and Application Gateway against OWASP Top 10 threats
- Administering and hardening on-prem Windows Server, Active Directory, DNS/DHCP, and Hyper-V/VMware alongside Azure workloads
- Hardening Entra ID (Conditional Access, MFA, PIM) and reducing privileged access exposure across hybrid identity
- Running vulnerability scanning and EDR triage (Qualys, Defender, Sentinel)
- Aligning remediation work to Essential Eight and ISO 27001 controls
- Managing change through CAB/TAB processes with proper rollback planning
- Strong Microsoft stack experience across on-prem Windows Server, AD/GPO, Azure, Entra ID, Intune, Defender, and SCCM
- Confidence working hybrid, not just a pure cloud background
- Practical security tooling exposure: SIEM (Sentinel), EDR, Qualys or equivalent VMDR
- Working knowledge of Essential Eight and ISO 27001 frameworks
- PowerShell scripting for automation and compliance reporting
- Comfortable in a live remediation environment with tight timeline