Sign up to save this job, get alerts, and apply with an optimized CV.
Systems Security Engineer
Full Time
Executive
Job description
Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years. About the Team We are seeking an Infrastructure Security Engineer to drive security engineering and operational security across both our Australian and corporate ICT environments. You will work alongside a small infrastructure team responsible for designing, hardening and operating networks accredited under the Australian Government’s Protective Security Policy Framework (PSPF) and the ASD Information Security Manual (ISM), as well as supporting security tooling on the corporate network. The ideal candidate has hands-on experience with security platforms spanning endpoint protection, SIEM, vulnerability management, identity and access management, and privileged access management. They are comfortable operating in environments subject to Australian Government security frameworks and can translate ISM controls and Essential Eight maturity targets into practical engineering outcomes. About the Job What You’ll Do * This is not an ISSO or ISSM role. This is a technical, hands-on security engineering position. * Own and operate security tooling across Australian and corporate networks, including deployment, configuration, tuning, patching and lifecycle management. * Administer and mature the Australian network’s security stack, including application whitelisting, SIEM, vulnerability scanning, endpoint antivirus and privileged access management. * Support corporate network security platforms, including endpoint detection and response, identity and access management, privileged access management, and device trust and compliance. * Drive Essential Eight maturity uplift across Australian environments, with a focus on application control, patching, privileged access restriction, multi-factor authentication and regular backups. * Develop and maintain SIEM use cases, detection rules, correlation searches and dashboards to provide actionable visibility across the environment. * Conduct regular vulnerability assessments, analyse findings, prioritise remediation and track closure through the Plan of Action and Milestones (POAM) register. * Perform security hardening of Windows Server, Active Directory, virtualisation platforms, storage infrastructure and network devices in accordance with ASD hardening guidance and the ISM. * Contribute to security architecture assessments, threat modelling and risk assessments for new and existing systems. * Collaborate with infrastructure engineers to integrate security into system designs, change plans and standard operating procedures. * Support system accreditation activities, including preparation of security documentation (SSPs, SRMPs, IRPs, DLDs) and evidence gathering for assessments. * Brief security posture, risks and recommendations to management and government stakeholders. * Assist with security incident response, investigation and post-incident review. Required Qualifications * Three or more years of experience in one or more of the following: cyber security engineering, security operations, systems security, infrastructure security or security architecture. * Hands-on experience with at least three of the following security platform types: * Application whitelisting or application control * SIEM and log management * Vulnerability scanning and assessment * Endpoint detection and response (EDR) * Privileged access management (PAM) * Identity and access management (IAM) * Strong understanding of Active Directory, Group Policy, Windows Server hardening and Kerberos authentication. * Familiarity with Australian Government security frameworks: the ISM, PSPF, Essential Eight Maturity Model and associated ASD guidance. * Excellent verbal and written communication skills, with the ability to produce clear security documentation and brief both technical and non-technical audiences. * A collaborative, low-ego approach to working in a small team where everyone shares the load. * The ability to obtain and maintain a NV2 security clearance. Preferred Qualifications * An existing NV2 security clearance. * Experience working in or supporting high-security environments accredited under Australian Government frameworks. * Experience with Windows Server and VMware vSphere administration and security hardening. * Experience with enterprise backup and recovery platforms and an understanding of data protection requirements under the ISM. * Familiarity with device trust and compliance tooling. * Experience developing SIEM dashboards, alerts, detection content and integrations. * Scripting skills in PowerShell, Python or Bash for automation of security operations tasks. * Familiarity with PKI, certificate lifecycle management and TLS/mTLS implementation. * Experience with ASD’s hardening guidance for Active Directory (including the joint ASD/CISA/NSA advisory on detecting and mitigating AD compromises). * Experience supporting system accreditation under the ISM and PSPF, including preparation of Security System Plans (SSPs) and security risk management documentation. * Relevant industry certifications such as GIAC (GSEC, GCIH, GCIA), CompTIA Security+/CySA+, Microsoft SC-200 or equivalent. * Experience with configuration management and patching platforms. The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including: Benefits At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits. Protecting Yourself from Recruitment Scams Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information. To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind: * No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates. * Please always verify communications: * Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address. * Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to [email protected]. * Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain is @anduril.com before providing any personal information or clicking on links. * What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to [email protected]. Data Privacy To view Anduril's candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/. By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.
Required skills
ism
ai
python
bash
powershell
active directory
kerberos
tls
autonomy
windows server
networking
ict
risk assessments
mtls
standard operating procedures
data protection
siem
edr
gcih
iam
pki
security operations
vulnerability management
pam
privileged access management
identity and access management
cisa
configuration management
vulnerability assessments
computer vision
endpoint protection
network devices
group policy
vmware vsphere
application control
security incident response
security documentation
security hardening
patching
comptia security+
gsec
security architecture
threat modelling
multi-factor authentication
backups
certificate lifecycle management
nv2 security clearance
ssps
change plans
infrastructure security
operational security
giac
gcia
microsoft sc-200
sensor fusion
comptia cysa+
defense technology
system designs
pspf
essential eight
nsa
virtualisation platforms
endpoint detection and response
storage infrastructure
cyber security engineering
systems security
protective security policy framework
asd information security manual
poam
system accreditation
srmps
irps
dlds
siem and log management
vulnerability scanning and assessment
windows server hardening
australian government security frameworks
essential eight maturity model
asd guidance
enterprise backup and recovery
device trust and compliance
asd hardening guidance
ad compromises
security system plans
patching platforms
Sign up to apply
Create a free account to apply for this job and get access to:
- AI-powered CV optimization for this specific job
- Save jobs and create custom alerts
- See your CV match score for each job
Company information
- Company
- Andurilindustries
- Location
-
Sydney, Australia
Germany - Posted
- 4 days ago
Interested in this position?
Create your free account and tailor your CV to match this job.