Senior Endpoint Security Engineer | Airlock | Defender | Windows Server | ACT
Salary: Up to 30 Months Contract - Rates Negotiable
- 6-month initial contract + 2 x 12-month extension options
- Rates Negotiable
- Airlock Digital, Microsoft Defender, EDR, Windows Server, AD/Entra, SCCM/MECM & Intune
- Canberra-based hybrid role | Baseline preferred or eligible to obtain
This is a hands-on engineering role rather than a governance-only cyber security position.
You will work across enterprise endpoint security, application control, vulnerability remediation, Windows Server infrastructure, identity and privileged access platforms, supporting both operational services and project-based security uplift.
The environment includes technologies such as Airlock Digital, Symantec Endpoint Protection, Microsoft Defender for Endpoint, Microsoft Defender Vulnerability Management, Windows Server, Active Directory, Entra ID, SCCM/MECM, SCOM, Intune, PKI, DNS, CyberArk and Microsoft Identity Manager.
Essential experience
- Enterprise endpoint security platforms, including application control, endpoint protection, EDR, vulnerability management, host-based firewalls, device control and security policy management.
- Airlock Digital, Symantec Endpoint Protection, Microsoft Defender for Endpoint, Microsoft Defender Vulnerability Management, or comparable enterprise endpoint security technologies.
- Responding to CVEs, vendor advisories, vulnerabilities and production security issues, including impact assessment, troubleshooting, remediation, testing and controlled implementation.
- Strong Windows Server engineering and administration, including Windows Server Core.
- Active Directory, Entra ID, DNS, PKI, DFS, Group Policy, SCOM, SCCM/MECM, Intune and Azure Virtual Desktop.
- Enterprise troubleshooting, change management, patching, upgrades and lifecycle management.
- Australian Government Information Security Manual (ISM) requirements.
- Essential Eight maturity and ACSC security guidance.
- Federal Government or another highly regulated environment.
- Red Hat Enterprise Linux (RHEL) administration and hardening.
- Ansible or equivalent configuration-management and automation tooling.
- Infrastructure-as-code and source control.
- CI/CD, Azure DevOps and Azure Arc.
- IAM/PAM, access governance and privileged-access controls.
- MIM, Unify Broker, Entra ID, CyberArk or Secret Server.
- Administer and support enterprise endpoint protection and application-control platforms.
- Maintain security policies, endpoint agents, application whitelisting and application-unblocking controls.
- Assess antivirus exclusions and other security policy changes with Cyber Security and system owners.
- Monitor CVEs and vendor security advisories and coordinate remediation.
- Plan and deliver endpoint security platform patching, upgrades and agent deployments.
- Support and modernise enterprise Windows Server environments.
- Perform server upgrades, migrations, hardening, patching and compatibility assessments.
- Support identity and access technologies including Active Directory, Entra ID, MIM and Unify Broker.
- Contribute to privileged access management platforms such as CyberArk and Secret Server.
- Troubleshoot identity, authentication, access and privileged-access issues.
- Produce strong technical documentation, SOPs and design documentation.
- Work collaboratively with Platform Services, Cyber Security, infrastructure, application and project teams.
Location: Canberra ACT
Working arrangement: Hybrid/flexible arrangements may be supported according to operational requirements. This remains a Canberra-based position.
Start: 5 October 2026
Initial term: 6 months
Extensions: 2 x 12-month extension options
Hours: Up to 40 hours per week
Rate: Competitive market rate, negotiable according to experience
Security clearance
A current Australian Government Baseline clearance is highly desirable but is not essential at application stage.
Candidates who do not currently hold a Baseline clearance may still be considered where they are eligible to obtain one.
To apply
Please apply with an up-to-date CV that clearly shows your hands-on endpoint security and Windows infrastructure experience, including the specific security platforms and Microsoft technologies you have administered.
Please also identify your:
- Australian citizenship status
- Current security clearance, if applicable
- Availability / notice period
- Current or expected contract rate
Infinity Pro is an established Australian ICT recruitment and labour-hire specialist, operating since 2009 and supporting technology professionals across government and enterprise environments.
Best method to apply is using the application button on this advert.
We can be contacted on (02) 9687 1025 for a confidential discussion, however please ensure your current CV has been submitted.