Enter a job title or keyword

Systems Security Engineer

Anduril


Job Location:

Sydney - Australia

Monthly Salary: Not provided by the employer
Posted: 12 September 2026 (6 hours ago)
Application Deadline: 10 December 2026
Vacancies: 1 Vacancy

Job Summary

About the Team

We are seeking an Infrastructure Security Engineer to drive security engineering and operational security across both our Australian and corporate ICT environments. You will work alongside a small infrastructure team responsible for designing hardening and operating networks accredited under the Australian Governments Protective Security Policy Framework (PSPF) and the ASD Information Security Manual (ISM) as well as supporting security tooling on the corporate network.

The ideal candidate has hands-on experience with security platforms spanning endpoint protection SIEM vulnerability management identity and access management and privileged access management. They are comfortable operating in environments subject to Australian Government security frameworks and can translate ISM controls and Essential Eight maturity targets into practical engineering outcomes.

About the Job
What Youll Do
  • This is not an ISSO or ISSM role. This is a technical hands-on security engineering position.
  • Own and operate security tooling across Australian and corporate networks including deployment configuration tuning patching and lifecycle management.
  • Administer and mature the Australian networks security stack including application whitelisting SIEM vulnerability scanning endpoint antivirus and privileged access management.
  • Support corporate network security platforms including endpoint detection and response identity and access management privileged access management and device trust and compliance.
  • Drive Essential Eight maturity uplift across Australian environments with a focus on application control patching privileged access restriction multi-factor authentication and regular backups.
  • Develop and maintain SIEM use cases detection rules correlation searches and dashboards to provide actionable visibility across the environment.
  • Conduct regular vulnerability assessments analyse findings prioritise remediation and track closure through the Plan of Action and Milestones (POAM) register.
  • Perform security hardening of Windows Server Active Directory virtualisation platforms storage infrastructure and network devices in accordance with ASD hardening guidance and the ISM.
  • Contribute to security architecture assessments threat modelling and risk assessments for new and existing systems.
  • Collaborate with infrastructure engineers to integrate security into system designs change plans and standard operating procedures.
  • Support system accreditation activities including preparation of security documentation (SSPs SRMPs IRPs DLDs) and evidence gathering for assessments.
  • Brief security posture risks and recommendations to management and government stakeholders.
  • Assist with security incident response investigation and post-incident review.
Required Qualifications
  • Three or more years of experience in one or more of the following: cyber security engineering security operations systems security infrastructure security or security architecture.
  • Hands-on experience with at least three of the following security platform types:
    • Application whitelisting or application control
    • SIEM and log management
    • Vulnerability scanning and assessment
    • Endpoint detection and response (EDR)
    • Privileged access management (PAM)
    • Identity and access management (IAM)
  • Strong understanding of Active Directory Group Policy Windows Server hardening and Kerberos authentication.
  • Familiarity with Australian Government security frameworks: the ISM PSPF Essential Eight Maturity Model and associated ASD guidance.
  • Excellent verbal and written communication skills with the ability to produce clear security documentation and brief both technical and non-technical audiences.
  • A collaborative low-ego approach to working in a small team where everyone shares the load.
  • The ability to obtain and maintain a NV2 security clearance.
Preferred Qualifications
  • An existing NV2 security clearance.
  • Experience working in or supporting high-security environments accredited under Australian Government frameworks.
  • Experience with Windows Server and VMware vSphere administration and security hardening.
  • Experience with enterprise backup and recovery platforms and an understanding of data protection requirements under the ISM.
  • Familiarity with device trust and compliance tooling.
  • Experience developing SIEM dashboards alerts detection content and integrations.
  • Scripting skills in PowerShell Python or Bash for automation of security operations tasks.
  • Familiarity with PKI certificate lifecycle management and TLS/mTLS implementation.
  • Experience with ASDs hardening guidance for Active Directory (including the joint ASD/CISA/NSA advisory on detecting and mitigating AD compromises).
  • Experience supporting system accreditation under the ISM and PSPF including preparation of Security System Plans (SSPs) and security risk management documentation.
  • Relevant industry certifications such as GIAC (GSEC GCIH GCIA) CompTIA Security/CySA Microsoft SC-200 or equivalent.
  • Experience with configuration management and patching platforms.

The salary range for this role is an estimate based on a wide range of compensation factors inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience education and/or training critical skills and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Andurils total compensation package. Additionally Anduril offers top-tier benefits for full-time employees including:

Benefits

At Anduril we invest in our people. Our comprehensive competitive benefits package (available at little to no cost to employees) ensures youre supported in health recovery and whatever comes next.For more information Explore Our Benefits.

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. Weve observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

To ensure your safety and help you navigate your job search with confidence please keep the following critical points in mind:

  • No Financial Requests:Anduril will never solicit payment or demand personal financial details (such as banking information credit card numbers or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

  • Please always verify communications:
    • Direct from Anduril: If you receive an email from one of our recruiters it will only come from an @ address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role their email will clearly identify their agency. If you suspect any suspicious activity please verify the agencys authenticity by reaching out to .
  • Exercise Caution with Unsolicited Outreach:If you receive any communication that appears suspicious contains grammatical errors or makes unusual requests do not engage. Always confirm the senders email domain is @ before providing any personal information or clicking on links.

  • What to Do If You Suspect Fraud:Should you encounter any questionable or fraudulent outreach claiming to be from Anduril please report it immediately to. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

Data Privacy

To view Andurils candidate data privacy policy please visit submitting your application you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk integrity and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists adverse media public-record information and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology intellectual property and organizational security.


Required Experience:

IC