About the Role
DAC is seeking a Principal Cloud Security (SecOps) Engineer to help drive cloud security uplift programs and elevate security posture across Azure Cloud, SaaS platforms, and identity systems. This is a hands-on security operations role responsible for the design, implementation, and remediation of cloud security controls across Microsoft Azure and key SaaS platforms including Okta and Snowflake.
Responsibilities
- Improve Azure security posture by addressing Microsoft Defender for Cloud, Azure Policy, and CSPM recommendations.
- Harden Azure subscriptions aligned to CIS benchmarks by implementing CIS controls.
- Implement Privileged Identity Management (PIM), and Conditional Access policies to enforce least-privilege at scale.
- Define security baselines and secure-by-default cloud operating model including security checklist for a product assessment or project implementation.
- Support threat assessment of SaaS products like OKTA and Snowflake. Remediate gaps identified via OKTA Threat Insight and Snowflake Trust Centre Assessment.
- Deploy and operationalize SSPM tooling (AppOmni) to continuously assess and remediate SaaS misconfigurations at scale.
- Monitor SaaS security configurations and remediate misconfigurations.
- Support implementation of Zero trust identity strategy across Entra ID, Okta and enforcing password less authentication across systems where applicable.
- Detect and remediate identity risks like privileged account sprawl, stale permissions, over-permissioned service accounts, and credential misconfigurations.
- Establish PAM processes, and just-in-time access workflows in OKTA and Entra ID.
- Drive end-to-end vulnerability management including asset ingestion and scanning via Qualys, SLA tracking etc.
- Analyze vulnerability reports from Microsoft Defender, Qualys. And address open OS and application-level vulnerabilities across Crown Jewels.
- Perform regular Cloud and SaaS vulnerability assessments.
- Author and continuously tune SIEM (MS Sentinel) rules across cloud, identity, and SaaS telemetry.
- Investigate security alerts and support incident response activities.
- Improve log collection, visibility and monitoring across Azure and SaaS platforms.
- Support threat detection and continuous monitoring initiatives.
- Support implementation of ISO 27001, Essential Eight, CIS Controls and other relevant security frameworks.
- Participate in security risk assessments and threat modelling exercises.
- Assist with audit activities and evidence collection.
Requirements
- Deep hands-on experience with Microsoft Azure Security Services (Defender for Cloud, Sentinel, Entra ID, Azure Policy, Networking, PIM).
- Experience securing Azure cloud environments.
- Hands-on experience implementing identity security, Zero Trust and privileged access management.
- Experience implementing Conditional Access, MFA, PIM and PAM.
- Experience with vulnerability management platforms such as Qualys, Microsoft Defender.
- Experience with SIEM, security monitoring and incident response.
- Hands-on experience with Okta and Snowflake security.
- Knowledge of SaaS Security Posture Management (SSPM) solutions.
- Knowledge of cloud security frameworks including CIS Benchmarks, ISO 27001, and Essential Eight.
- Strong analytical, troubleshooting and communication skills.
Skills
- Microsoft Azure Security Services
- Defender for Cloud
- Sentinel
- Entra ID
- Azure Policy
- Networking
- PIM
- Identity Security
- Zero Trust
- Privileged Access Management (PAM)
- Conditional Access
- MFA
- Qualys
- Microsoft Defender
- SIEM
- Security Monitoring
- Incident Response
- Okta
- Snowflake Security
- SaaS Security Posture Management (SSPM)
- CIS Benchmarks
- ISO 27001
- Essential Eight
Location
- Sydney
Work Type
- Temporary
- Full-time
Experience Level
- Principal
Education Level
- Microsoft Azure Security Engineer (AZ-500)
- SC-200
- SC-300
- CISSP
- CCSP
Salary/Compensations
- $154,231 - $178,369 + superannuation
About the Company
- The NSW Data Analytics Centre (DAC) leads a whole-of-government approach to data analytics, connecting data, insights, and people to tackle the State's toughest challenges. DAC’s Advanced Analytics Platform drives improved health, safety, and social outcomes for NSW citizens.
- A career at the Department of Customer Service (DCS) gives you the opportunity to help improve government services and be part of reform that benefits people across NSW. We are focused on delivering excellent customer service, digital transformation, and regulatory reform. Come join us and influence the future of our great state.
- The strength of our workforce lies in its diversity and embracing difference, while the key to our success is leveraging the contributions of employees with different backgrounds and perspectives.
Equal Opportunity
- We provide adjustments to the recruitment process for candidates, including individuals with disability.
