Senior Endpoint Security Infrastructure Engineer
Summary
Hands-on infrastructure engineering role administering enterprise endpoint security platforms (Airlock Digital, Symantec, Microsoft Defender for Endpoint) and the Windows Server estate across BAU, security uplift and projects. Work spans EDR, application control, CVE remediation, Active Directory/Entra ID, PKI and SCCM/Intune in a Canberra-based hybrid role.
This is a hands-on technical role with a strong focus on endpoint security, Windows Server infrastructure, vulnerability remediation and identity/access technologies. You’ll work across BAU operations, security uplift initiatives, platform lifecycle activities and project delivery.
Key Responsibilities- Administer and support enterprise endpoint security platforms, including application control, endpoint protection, EDR, vulnerability management, host-based firewalls and device control.
- Support technologies such as Airlock Digital, Symantec Endpoint Protection and Microsoft Defender for Endpoint.
- Manage security platform patching, upgrades, policy changes and agent deployments.
- Assess and implement application whitelisting, unblocking, antivirus exclusions and security policy changes.
- Investigate CVEs, security vulnerabilities and vendor advisories, undertaking impact assessment, remediation, testing and implementation.
- Support and troubleshoot enterprise Windows Server environments, including Server Core.
- Support Windows Server upgrades, migrations, patching, hardening and lifecycle management.
- Administer technologies including Active Directory, Entra ID, DNS, PKI, Group Policy, DFS, SCOM, SCCM/MECM, Intune and Azure Virtual Desktop.
- Support identity and privileged access management platforms and contribute to technical documentation, SOPs and knowledge transfer.
You’ll bring 5+ years of relevant infrastructure/platform engineering experience, with strong hands-on experience supporting enterprise endpoint security technologies.
Ideally, you will have experience across:
- Microsoft Defender for Endpoint / Defender Vulnerability Management, Airlock Digital, Symantec Endpoint Protection or comparable enterprise security platforms.
- Windows Server, Active Directory and Entra ID.
- SCCM/MECM, SCOM, Intune, DNS, PKI and Group Policy.
- CVE assessment, vulnerability remediation, security hardening and change management.
- Australian Government security frameworks including Essential Eight, ISM and ACSC guidance.
- IAM/PAM technologies such as MIM, Unify Broker, CyberArk or Secret Server.
- RHEL and automation/configuration management using Ansible or similar tools.
- Infrastructure-as-Code, source control, CI/CD, Azure DevOps and/or Azure Arc.
- Developing clear technical documentation, SOPs and design documentation.
This opportunity is based in Canberra/ACT with hybrid working arrangements.
A current and active Baseline Security Clearance is mandatory for this role.
If you’re an experienced Infrastructure/Platform Engineer with strong endpoint security and Microsoft infrastructure expertise, we’d love to hear from you.
Apply now