You’ll work across endpoint protection, application control, identity management, privileged access, Windows Server lifecycle, vulnerability remediation and platform uplift activities. The environment is complex, security?focused and highly collaborative — ideal for an engineer who enjoys balancing BAU support with project delivery and continuous improvement.
Key Responsibilities
- Support and maintain enterprise endpoint security platforms including application control, endpoint protection, EDR, host-based firewalls, vulnerability management and device control.
- Administer technologies such as Airlock Digital, Symantec Endpoint Protection
and Microsoft Defender, including configuration, policy maintenance, agent health and lifecycle management.
- Plan and deliver platform patching, upgrades, policy changes and agent deployments through established change management processes.
- Assess and implement application whitelisting, unblocking, antivirus exclusions and security policy changes in consultation with Cyber Security and system owners.
- Monitor and respond to CVEs, vendor advisories and security findings, including impact analysis, remediation planning, testing and implementation.
- Provide operational and project support across enterprise Windows Server
environments, including Server Core
deployments.
- Support Windows Server lifecycle activities: upgrades, migrations, patching, hardening, compatibility assessment and transition to supported OS versions.
- Administer and troubleshoot Active Directory, Entra ID, DNS, PKI, Group Policy, DFS, SCOM, SCCM/MECM
and Intune.
- Support and maintain enterprise identity management platforms including Microsoft Identity Manager
and Unify Broker.
- Contribute to the support and maintenance of privileged access management solutions such as CyberArk
and Secret Server.
- Provide technical advice and troubleshooting across identity, authentication, access and privileged access workflows.
- Active NV1 Security Clearance(mandatory).
- Strong experience in enterprise Windows Server environments, including Server Core.
- Hands-on experience with endpoint security platforms (Airlock Digital, Symantec, Defender).
- Solid understanding of application control, EDR, antivirus, host-based firewalls and vulnerability management.
- Experience with identity platforms (MIM, Unify Broker) and privileged access tools (CyberArk, Secret Server).
- Strong knowledge of AD, Entra ID, DNS, PKI, GPO, SCCM/MECM, Intune and related infrastructure services.
- Demonstrated ability to assess, plan and implement security uplift activities.
- Strong documentation skills and experience contributing to policies, procedures and technical guides.
- Ability to work collaboratively across Cyber Security, infrastructure, application teams, vendors and stakeholders.
- Strong problem-solving skills and a security-first mindset.
We are an inclusive employer committed to fostering a diverse and accessible workplace. We encourage applications from Aboriginal and Torres Strait Islander peoples, people with disabilities, LGBTQIA+ individuals, people of all ages, and those from culturally and linguistically diverse backgrounds.
#SCR-payton-vercoe
