Title:
Senior Security Principal, Identity Security
At KBR – We do things that matter.
We deliver science, technology and engineering solutions to governments and companies around the world. KBR employs approximately 38,000 people worldwide with customers in more than 80 countries and operations in over 29 countries.
KBR is proud to work with its customers across the globe to provide technology, value-added services, and long-term operations and maintenance services to ensure consistent delivery with predictable results. At KBR, We Deliver.
Think.KBR.com
KBR in Australia
With over 65 years working on some of Australia’s largest and most complex projects, KBR has unmatched experience supporting the nation’s critical infrastructure, energy transition and national security priorities. KBR has around 2,000 employees throughout Australia, who are focused on delivering innovative technology and engineering solutions for a safer, more secure and sustainable future.
Learn more about KBR in Australia
Belong, Connect and Grow at KBR
At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together.
The Opportunity:
KBR is seeking a Senior Security Principal – Identity Security to join our global Cyber Security team as a senior technical authority. This principal-level role combines identity security architecture, engineering leadership, governance and operational excellence across complex, highly regulated enterprise environments.
You will play a key role in shaping KBR's identity security strategy by establishing technical standards, developing roadmaps and providing hands-on leadership across initiatives including Microsoft Entra ID, Active Directory, hybrid identity, authentication, privileged access management (PAM), identity governance, workload identities and certificate services.
Working closely with cyber security, infrastructure, cloud, applications, networking and business stakeholders, you will lead the design and implementation of secure identity solutions that reduce organisational risk, strengthen access controls and support enterprise transformation. The successful candidate will bring deep technical expertise, strategic thinking and a proven ability to influence security outcomes across large-scale, global environments.
This is a permanent full-time opportunity and can be based in Canberra, Brisbane, Adelaide, Sydney or Melbourne.
The successful candidate must hold an NV1 security clearance or higher.
Responsibilities:
- Serve as the senior technical authority for enterprise identity security architecture, engineering and governance.
-
Define and drive the enterprise identity security strategy, including technical standards, reference architectures and multi-year roadmaps.
-
Lead the design, implementation and optimisation of Microsoft Entra ID, Active Directory, hybrid identity and authentication services.
-
Strengthen identity and access management capabilities, including Conditional Access, MFA, passwordless authentication, Privileged Identity Management (PIM), RBAC and least-privilege access.
-
Establish and mature identity governance, identity lifecycle management and privileged access controls across the enterprise.
-
Provide architectural oversight for application identity, federation, single sign-on, workload identities, service accounts and certificate services.
-
Partner with cyber security, cloud, infrastructure and application teams to deliver secure identity solutions that support enterprise transformation.
-
Lead identity security initiatives, including tenant migrations, cloud transformation, mergers and acquisitions, and major technology projects.
-
Improve identity threat detection, monitoring, incident response and automation using Microsoft security technologies and scripting tools.
-
Mentor technical teams and provide strategic advice to senior stakeholders on identity security risks, architecture and best practice.
As the ideal candidate you will bring:
Essential
-
10+ years' experience in identity and access management (IAM), identity security, cyber security engineering, security architecture or a related field.
-
Proven experience designing, implementing and supporting enterprise identity and access management solutions within large, complex environments.
-
Demonstrated experience leading identity security initiatives, architecture reviews or enterprise transformation programs.
-
Strong expertise in Microsoft Entra ID, Active Directory and hybrid identity environments.
-
Experience with identity governance, privileged access management (PAM), Conditional Access and modern authentication technologies.
-
Sound understanding of federation, single sign-on (SSO), identity lifecycle management and application identity.
-
Experience with authentication and identity protocols including SAML, OAuth, OpenID Connect, MFA, FIDO2 and Windows Hello for Business.
-
Knowledge of public key infrastructure (PKI), certificate services and identity security best practices.
-
Strong communication, stakeholder engagement, problem-solving and technical leadership skills.
Desirable
-
Bachelor's degree in Cyber Security, Information Technology, Computer Science, Engineering or a related discipline, or an equivalent combination of qualifications, certifications and relevant experience.
-
Experience supporting multiple Microsoft tenants in government, defence or other highly regulated environments.
-
Hands-on experience with automation and scripting technologies such as PowerShell, Microsoft Graph, KQL, Logic Apps or Terraform.
-
Experience integrating identity security with enterprise technologies such as Microsoft Intune, Microsoft Purview, Palo Alto Networks, Cisco ISE or Zscaler.
-
Experience supporting mergers and acquisitions, divestments, tenant migrations, forest consolidations or other large-scale transformation initiatives.
-
Experience working within highly regulated sectors such as government, defence, aerospace, critical infrastructure, financial services or healthcare.
-
Industry certifications such as CISSP, CISM, CCSP, Microsoft Certified: Cybersecurity Architect Expert or Microsoft Certified: Identity and Access Administrator Associate.
-
Knowledge of Australian Government security frameworks, regulatory requirements or sovereign cloud environments.
All candidates will be required to hold and maintain an active NV1 Defence Security Clearance.
What we will offer you:
- A workplace culture certified as a Great Place To Work
-
Flexible working
-
Competitive salary (including annual reviews)
-
Paid parental leave
-
Income protection
-
Corporate rewards
-
Salary packaging/Novated leasing
-
Employee stock purchase plans
-
Flu shots, skin checks and discounted private health insurance
-
Career development: Online learning, mentorship and career pathways
If you’re ready to shape tomorrow, let’s get started. Apply Now!
Please note. Shortlisting will take place as applications are received, therefore the advertisement may close early if a suitable candidate is identified.
As a Major Service Provider of the Australian Defence Force, an AGSVA security clearance will be required and compliance to International Traffic in Arms Regulations (ITAR). As such, our hiring decisions are based on the key requirements of each role and candidates are selected based on their unique strengths and experiences.
Notice to Third Parties/Recruitment Agencies: KBR Australia does not accept unsolicited resumes or any liability associated with fees or costs from recruitment agencies, search firms or third parties who have not been engaged directly on this job opportunity. Candidates interested in applying are welcome to submit their application online.