About the job Senior Identity Access Management Infrastructure Engineer
Senior Identity Access Management Infrastructure Engineer
Australian citizenship required. No PR or Work Visa holders. Must be able to obtain Baseline security clearance.
What to Submit
-
A tailored resume in docx format
-
A one page (5000 character) summary response to the selection criteria below.
RFQ Details
-
RFQ ID: LH-05170
-
Agency: Department of Industry, Science and Resources
-
Closing Date: Monday, 08 December 2025 11:59pm (Canberra time)
-
Estimated Start Date: Monday, 19 January 2026
-
Initial Contract Duration: 6 months
-
Extension Term: 12 months
-
Number of Extensions: 2
-
Experience Level: Senior EL1 equivalent
-
Security Clearance: Must be able to obtain Baseline
-
Location of Work: ACT
-
Working Arrangements: Hybrid flexible work supported; remote working may be considered on a case-by-case basis in consultation with the supervising manager
-
Maximum Hours: 40 hours per week
Job Details
We are seeking a technically skilled and security-conscious Identity and Access Engineer to join our Platform Services team.
This role is central to maintaining secure, scalable, and modern identity services across the department.
The team is also responsible for Windows Server environments, security tools and privileged access management, which this role will contribute to. You will work closely with colleagues across the ICT area and business areas in a dynamic and collaborative environment.
Key Duties and Responsibilities
-
Maintain and manage enterprise identity management platforms including Microsoft Identity Manager (MIM), Unify Broker.
-
Undertake troubleshooting and provide advice to stakeholders on identity and access issues and workflows, with a focus on MIM and integration with HR System.
-
Drive continual improvement of identity and access workflows, models and configurations to improve security posture and user experience.
-
Collaborate with infrastructure, cyber security, HR and application teams to deliver secure identity services.
-
Contribute meaningfully to strategic planning and decision-making regarding identity and access management strategies, governance and roadmaps.
-
Create and contribute to quality documentation such as change records, procedures, designs, security assessments and knowledge articles.
-
Actively share knowledge and support the upskilling of staff within the team.
-
May contribute to the support and maintenance of Privileged Access Management (PAM) solutions such as CyberArk and Secret Server and broader server management activities.
Technical Skills
Please only present candidates with expert-level experience with Microsoft Identity Manager (MIM) as specified in the essential criteria. Applications and CVs without this skill will not be considered.
Selection Criteria
Max 5000 characters total in one-page pitch (individual responses not required)
Essential Criteria
-
Over 5 years of expert-level experience and demonstrated hands-on proficiency with core IAM technologies, including Microsoft Identity Manager (MIM), Unify Broker, advanced PowerShell scripting for automation and integration, and Entra ID for modern identity solutions.
-
Strategic understanding of access governance and access control in a complex government environment and contributing productively to strategic planning. These capabilities are essential, as the staff members primary responsibility will be managing identity and access integration with the Human Resources (HR) system and account provisioning using MIM and Unify broker technologies.
-
Demonstrated ability to mentor and upskill staff.
Desirable Criteria
-
Understanding of Cyber Security tools and methodologies including application whitelisting, host-based firewalls, vulnerability scanners and device control.
-
Understanding of Australian Government Cyber Security requirements, processes and artefacts including ISM, Essential 8 and ACSC hardening guides.
-
Strong experience in writing technical documentation including SOPs and design documentation.
-
Experience in Windows Server environment maintenance including Active Directory, Entra ID, DNS, PKI, ADFS, File and Print, DFS, Microsoft System Centre products and Intune (SCOM, SCCM/MECM) and GPO with Advanced Group Policy Management (AGPM).