Enterprise Architect
Velan Consulting Pty Ltd
Velan Consulting Pty Ltd – Direct Supplier to Federal & Private Clients
Principal Enterprise Architect | Canberra Onsite | Australian Citizens with NV1 | Contract
Working Arrangement: Canberra –
5 days onsite. Remote/interstate candidates will not be considered.
About the Team
The Cyber Security, Cloud and Networks Branch (CRB) within the Information Management and Technology Division (IMD) delivers and operates key cyber security, identity, trust and infrastructure services in a complex, regulated and security-conscious environment.
About the Project
The successful candidate will support a program focused on reviewing, enhancing and delivering cryptographic services and related security capabilities. Responsibilities include capability assessments, architecture development, service improvement, technical documentation, operational processes, transition planning and sustainable support models.
The role works across business, project, cyber security, infrastructure, engineering and operational teams to improve organisational capability, strengthen technical governance and support the long-term management of critical cryptographic services.
The Department is seeking a Technical Lead to support the assessment, enhancement and maturation of enterprise cryptographic services, including:
- Public Key Infrastructure (PKI)
- Hardware Security Modules (HSMs)
- Certificate management
- Key management
- Identity and trust services
The role provides technical leadership across architecture, governance, policy, risk management and practical implementation. The successful candidate will assess current capabilities, identify gaps, develop future-state architectures, establish governance frameworks and support delivery outcomes.
The role also involves developing and maintaining policies, standards, procedures, operating models, assurance processes and security controls required for the secure operation of PKI and related trust services.
Candidates should have strong experience in cryptographic services, PKI governance, security architecture, infrastructure security, risk management or related technical leadership disciplines, particularly within regulated or security-sensitive environments.
Key Responsibilities
- Provide technical leadership for enterprise PKI, HSM and cryptographic services.
- Design, govern and maintain target cryptographic architectures, trust models and key-management approaches.
- Develop and maintain cryptographic policies, standards, procedures, operating models and risk-management processes.
- Assess current capabilities and perform gap analysis to support roadmaps, business cases and future-state planning.
- Act as a senior technical authority for cryptographic and security architecture decisions.
- Lead solution architecture and detailed technical design activities.
- Identify and manage cryptographic risks, dependencies and operational resilience requirements.
- Support engineering teams through design, build, testing, release and transition to operations.
- Produce architectural artefacts, technical designs, operational documentation and implementation guidance.
- Support ongoing service operation, upgrades, maintenance, testing and issue resolution.
- Ensure services align with organisational security policies, government standards and industry best practice.
- Provide technical mentoring, knowledge transfer and capability uplift.
Technical Skills
Demonstrated experience in security architecture, cryptography, PKI, HSMs, identity, cyber security or infrastructure security, preferably within regulated, security-sensitive or compliance-driven environments.
Experience designing, implementing, operating or enhancing security, cryptographic, identity or infrastructure services, as well as producing technical documentation, standards, procedures, operating models, implementation plans and governance artefacts.
Knowledge of relevant frameworks including Australian Government ISM and Gatekeeper.
Essential Criteria
1. Cryptographic Security Architecture
Experience leading the assessment, architecture and improvement of enterprise security or cryptographic services such as PKI, HSMs, certificate lifecycle management, key management, identity or high-assurance trust services.
Ability to:
- Assess current-state capabilities and identify architectural, security, operational and governance gaps.
- Define target-state architectures, trust models, security controls and improvement roadmaps.
- Translate business, security and operational requirements into secure and supportable solutions.
- Apply government/industry security standards and risk-management practices.
2. Governance, Policy & Operating Model Design
Experience developing and implementing governance for security, cryptographic, identity or trust services, including:
- Policies and standards
- Certificate policies / Certification Practice Statements
- Key-management requirements
- Procedures and control frameworks
- Assurance arrangements
- Operating models and decision authorities
Ability to translate business, regulatory, security and operational requirements into clear, sustainable and auditable controls.
3. Delivery, Transition & Operational Readiness
Experience across the secure technology lifecycle, including design, implementation, testing, assurance, transition to operations and continual improvement.
Experience with:
- Technical risks, dependencies and operational resilience
- Architecture, design and implementation documentation
- Engineering and operational support arrangements
- Knowledge transfer, service transition and capability uplift
4. Technical Leadership & Stakeholder Engagement
Experience operating as a senior technical authority in complex multidisciplinary environments.
Ability to:
- Provide authoritative and pragmatic technical advice.
- Communicate complex security/cryptographic matters to technical and non-technical stakeholders.
- Resolve competing architecture, security, delivery and operational priorities.
- Influence business, architecture, engineering, project, procurement and operational stakeholders.
- Mentor personnel and transfer specialist knowledge.
5. Security Clearance
- Negative Vetting Level 1 (NV1) required
Desirable Criteria
Experience in one or more of the following is highly regarded:
- Cryptographic, PKI, identity or trust services in Australian Government, Defence or other high-assurance/regulated environments.
- Enterprise PKI, Certificate Authority, HSM, key management or certificate lifecycle management.
- Australian Government Information Security Manual (ISM) or Gatekeeper PKI Framework.
- ICAO Doc 9303, ICAO Public Key Directory or comparable trust frameworks.
- PKI supporting ePassports, electronic travel documents, biometric identity systems or high-assurance credentials.
- CSCA, Document Signing Certificate and Certificate Revocation List lifecycle management.
- Cryptographic key ceremonies, multi-person control, HSM-based key protection, disaster recovery and cryptographic assurance.
- Current-state assessments, target-state architecture, operating-model development, technology roadmaps, requirements definition or procurement support.
- Cryptographic agility or post-quantum cryptography readiness.
- NV2 Security Clearance.
Application
Email your CV in Word format along with:
- Residency status
- Security clearance
- Current location
- Availability
- Role preference
- Current and expected salary
- Reason for job change
- Any constraints
Send applications to Sign in to view email
Cheers,
Velan Consulting Recruitment Team
For employers only
Is this your company's job post? Verify ownership to manage this listing and receive applications directly.
Claim this listingLooking to apply for this job? Use the Apply button above.