Date: 14 Aug 2026
Location: Macquarie Park, Australia
#job-location.job-location-inline { display: inline; }
Company: Singtel Group
Optus is an Australian telecommunications company, delivering more than 11 million services to our customers every day across mobile, broadband, and digital solutions.
Optus is seeking a Lead DNS Engineer to provide hands-on technical leadership across our carrier-grade DNS environment.
This is a DNS-first senior individual contributor role responsible for the technical integrity, design, and implementation of DNS services across authoritative DNS, resolver DNS, cache DNS, DNS security controls, observability, and lifecycle uplift.
The successful candidate will operate as the senior engineering lead for DNS, combining architecture and standards with practical implementation. This role is expected to design solutions, build and improve configurations and automation, lead complex technical change, and materially reduce service risk across current and future DNS platforms.
The position is for an engineer who can move between strategy and execution — someone who can define the right design and then help implement it in production.
What You’ll Do
DNS architecture, design, and implementation
Design and implement solutions across authoritative DNS, recursive DNS, cache DNS, DNS policy services, and DNS control plane functions.
Define and maintain target-state architecture and engineering patterns for Consumer, Enterprise, and Internal DNS services.
Produce practical designs that can be implemented safely in production, including migration patterns, coexistence models, failover design, and rollback strategy.
Build and improve DNS configurations, service patterns, and deployment approaches across current and future DNS platforms.
DNS platform engineering and change delivery
Lead hands-on implementation of complex DNS changes, upgrades, migrations, and resilience improvements.
Improve DNS automation, validation, and deployment workflows to reduce manual risk and increase repeatability.
Work through deep technical details of zone management, zone publication, policy distribution, hidden master operation, and service cutover.
Support and technically lead platform transition programs, ensuring design intent is carried through into implementation.
Lifecycle uplift and technical risk reduction
Identify DNS lifecycle exposure across software, supporting components, and service dependencies, and drive practical remediation plans.
Reduce technical debt and simplify brittle service patterns through engineering change, not just documentation.
Improve service resilience, recovery readiness, and observability through targeted implementation work and design correction.
Support technology refresh and service modernisation by taking designs through to deployable outcomes.
DNS security, service correctness, and resilience
Design and implement improvements to DNS security controls including DNSSEC, TSIG, access control, RPZ policy handling, secure administration, and auditability.
Improve service correctness across authoritative, resolver, and cache paths, including failover behaviour, propagation behaviour, and dependency management.
Define and implement guardrails for safe DNS change, including validation, rollback expectations, and production-readiness checks.
Support major incidents, root cause analysis, and recurring issue elimination with a strong engineering focus on prevention.
Engineering leadership and cross-functional execution
Work closely with platform engineering, network engineering, security, operations, and vendor teams to turn DNS service requirements into deployable and supportable solutions.
Provide senior technical leadership during design, implementation, and stabilisation of DNS changes.
Improve engineering documentation, build standards, implementation patterns, runbooks, and migration artefacts.
Mentor engineers and contribute to lifting practical DNS engineering capability across the organisation.
What makes you the right fit for the role?
Deep hands-on expertise in DNS engineering across authoritative DNS, recursive DNS, cache DNS, and DNS service operations.
Strong understanding of DNS protocols, record types, zone design, split-horizon or split-view DNS, recursion behaviour, forwarding, and cache behaviour.
Proven experience designing and implementing production DNS services in large-scale enterprise, ISP, carrier, or service provider environments.
Strong knowledge of DNS security concepts including DNSSEC, TSIG, response policy mechanisms, access control, and service hardening.
Experience implementing resilient DNS designs including hidden masters, secondaries, anycast-based service delivery, failover patterns, and control/data plane separation.
Strong problem-solving capability across complex service incidents, technical debt, lifecycle uplift, and architectural remediation.
Experience building or improving DNS automation, validation, deployment, or migration workflows.
Experience producing high-quality engineering documentation such as design documents, standards, runbooks, migration plans, and risk assessments.
Strong communication skills with the ability to explain complex DNS concepts to engineering operations, architecture, and leadership audiences.
Leadership attributes
Strong engineering judgement
Structured and pragmatic problem solving
Ownership mindset for service quality and technical integrity
Ability to balance immediate operational realities with long-term design direction
Calm, credible presence during major incidents and critical changes
Collaborative approach across service, platform, and operations teams
Essential experience and capability
Deep hands-on expertise in DNS engineering across authoritative DNS, recursive DNS, cache DNS, and DNS service operations.
Strong understanding of DNS protocols, record types, zone design, split-horizon or split-view DNS, recursion behaviour, forwarding, and cache behaviour.
Proven experience designing and implementing production DNS services in large-scale enterprise, ISP, carrier, or service provider environments.
Strong knowledge of DNS security concepts including DNSSEC, TSIG, response policy mechanisms, access control, and service hardening.
Experience implementing resilient DNS designs including hidden masters, secondaries, anycast-based service delivery, failover patterns, and control/data plane separation.
Strong problem-solving capability across complex service incidents, technical debt, lifecycle uplift, and architectural remediation.
Experience building or improving DNS automation, validation, deployment, or migration workflows.
Experience producing high-quality engineering documentation such as design documents, standards, runbooks, migration plans, and risk assessments.
Strong communication skills with the ability to explain complex DNS concepts to engineering operations, architecture, and leadership audiences.
Desirable experience and capability
Strong systems and platform engineering capability across Linux-based infrastructure, service hardening, observability, and lifecycle management.
Working knowledge of server, OS, virtualisation, and platform operations relevant to carrier-grade DNS environments.
Familiarity with network and traffic engineering constructs such as BGP anycast, load balancing, routing daemons, HA clustering, and service advertisement models.
Experience with DNS platforms and products such as BIND, Unbound, Power DNS, F5 BIG-IP DNS or similar.
Exposure to automation and infrastructure tooling used to manage DNS at scale, including APIs, scripting, CI/CD, infrastructure-as-code, configuration management, and service onboarding workflows.
Experience with service observability platforms, telemetry pipelines, logging, SNMP-based monitoring, and performance analysis.
Experience working in regulated or highly available production environments where uptime, auditability, and service correctness are critical.
Ability to work effectively with platform, infrastructure, and operations teams to translate service requirements into deployable runtime patterns.
The good stuff….
Competitive remuneration and colleague discounts. Make life easier (and more affordable) with $80 monthly credit and 25% off Optus products and outstanding shopping discounts with our retail partners.
Flexible working arrangements with opportunities to work three days in the office, two days remote or home.
Vibrant and collaborative office campus that includes cafes, a convenience store, chill-out zones, GP, post office, gym, and on-site childcare centre.
Competitive leave policies, including additional 'Connected’ days to focus on culture, family, health, community, or whatever’s important to you.
We support growing families with inclusive, carer-neutral paid Parental Leave of up to 16 weeks.
Build meaningful connections through colleague-led networks and diversity initiatives including Culture Connect, Elevate Women, Disability Network, and Express Yourself (LGBTQIA+).
Put your wellbeing first with free access to counselling and support services, 24/7 — in-person, by phone, SMS, or video.
Free Optus bus from Macquarie University Metro Station (every 6-8 minutes); morning and afternoon.
At Optus, we are strengthened by others and that means valuing diversity and saying ‘yes’ to embracing individual differences. We are committed to ensuring that our application process provides an equal employment opportunity to all job seekers, including individuals from diverse gender, cultural and linguistic backgrounds, individuals with a disability, individuals identifying as being part of the LGBTQIA+ community, individuals who may have served in the armed forces or who identify as Aboriginal and/or Torres Strait Islander. We also want to do our best to make our recruitment process inclusive. If you require any adjustments or accessibility support to participate fairly and equitably in the recruitment process, please email
[email protected] or call 1800 309 170.
For more information on Diversity, Inclusion & Belonging at Optus, please visit https://www.optus.com.au/about/inclusion-diversity