Principal Cyber Security Ops Engineer
Clerk Grade: 11/12
Annual Salary Range: $154,231 - $178,369 + superannuation
Employment Type: Temporary (12 months), Full-time
Location: Sydney
About Us
The NSW Data Analytics Centre (DAC) leads a whole-of-government approach to data analytics, connecting data, insights, and people to tackle the State's toughest challenges. DAC’s Advanced Analytics Platform drives improved health, safety, and social outcomes for NSW citizens.
We’re seeking a Principal Cloud Security (SecOps) Engineer who is passionate about cyber security, cloud security, and SecOps automation to strengthen DAC platforms, support ISO27001 compliance, and help drive security initiatives across an advanced cloud environment.
The Role
DAC is seeking a Principal Cloud Security (SecOps) Engineer to help drive cloud security uplift program and elevate security posture across Azure Cloud, SaaS platforms, and identity systems.
Role is hands-on security operations role responsible for the design, implementation and remediation of cloud security controls across Microsoft Azure and key SaaS platforms including Okta and Snowflake.
The role will work closely with Architecture, Infrastructure, and Security teams to identify risks, remediate vulnerabilities, enhance security monitoring, and ensure Cloud and SaaS environments align with defined security standards.
Key Responsibilities
Azure Cloud Security
-
Improve Azure security posture by addressing Microsoft Defender for Cloud, Azure Policy, and CSPM recommendations.
-
Harden Azure subscriptions aligned to CIS benchmarks by implementing CIS controls.
-
Implement Privileged Identity Management (PIM), and Conditional Access policies to enforce least-privilege at scale.
-
Define security baselines and secure-by-default cloud operating model including security checklist for a product assessment or project implementation.
SaaS Security
-
Support threat assessment of SaaS products like OKTA and Snowflake. Remediate gaps identified via OKTA Threat Insight and Snowflake Trust Centre Assessment
-
Deploy and operationalise SSPM tooling (AppOmni) to continuously assess and remediate SaaS misconfigurations at scale.
-
Monitor SaaS security configurations and remediate misconfigurations.
Identity & Access Hardening
-
Support implementation of Zero trust identity strategy across Entra ID, Okta and enforcing password less authentication across systems where applicable.
-
Detect and remediate identity risks like privileged account sprawl, stale permissions, over-permissioned service accounts, and credential misconfigurations.
-
Establish PAM processes, and just-in-time access workflows in OKTA and Entra ID.
Vulnerability Management
-
Drive end-to-end vulnerability management including asset ingestion and scanning via Qualys, SLA tracking etc
-
Analyse vulnerability reports from Microsoft Defender, Qualys. And address open OS and application-level vulnerabilities across Crown Jewels.
-
Perform regular Cloud and SaaS vulnerability assessments.
Security Monitoring & Incident Response
-
Author and continuously tune SIEM (MS Sentinel) rules across cloud, identity, and SaaS telemetry.
-
Investigate security alerts and support incident response activities.
-
Improve log collection, visibility and monitoring across Azure and SaaS platforms.
-
Support threat detection and continuous monitoring initiatives.
Security Compliance & Governance
-
Support implementation of ISO 27001, Essential Eight, CIS Controls and other relevant security frameworks.
-
Participate in security risk assessments and threat modelling exercises.
-
Assist with audit activities and evidence collection.
What We’re Looking For
Essential Skills:
-
Deep hands-on experience with Microsoft Azure Security Services (Defender for Cloud, Sentinel, Entra ID, Azure Policy, Networking, PIM). Experience securing Azure cloud environments.
-
Hand-on experience implementing identity security, Zero Trust and privileged access management. Experience implementing Conditional Access, MFA, PIM and PAM.
-
Experience with vulnerability management platforms such as Qualys, Microsoft Defender.
-
Experience with SIEM, security monitoring and incident response.
-
Hands-on experience with Okta and Snowflake security.
-
Knowledge of SaaS Security Posture Management (SSPM) solutions.
-
Knowledge of cloud security frameworks including CIS Benchmarks, ISO 27001, and Essential Eight.
-
Strong analytical, troubleshooting and communication skills.
Relevant certifications such as Microsoft Azure Security Engineer (AZ-50- , SC-200, SC-300, CISSP, CCSP or equivalent are highly desirable.
Why Join DAC?
-
Work on cutting-edge digital platforms that drive real-world outcomes.
-
Collaborate with a team of experts in a supportive, inclusive environment.
-
Make an impact on state-of-the-art cloud security initiatives.
How to apply
If you're excited about this opportunity, we'd encourage you to apply. Please submit your current resume and a brief cover letter highlighting your relevant skills, experience, and what you can bring to the role.
Salary Grade 11/12, with the base salary for this role starting at $154231 base plus superannuation
For enquiries relating to recruitment please contact Meg Rapley via
[email protected].
Visit the Capability Application Tool to prepare for the recruitment process by accessing practice application and interview questions based on the focus capabilities listed in the role description.
A talent pool may be created as part of this recruitment process and will be valid for up to 18 months. The talent pool may be used to fill future ongoing or temporary vacancies of the same or similar role.
Closing Date: Tuesday 1 September 2026 at 9:59am
Careers at Department of Customer Service
A career at the Department of Customer Service (DCS) gives you the opportunity to help improve government services and be part of reform that benefits people across NSW. We are focused on delivering excellent customer service, digital transformation, and regulatory reform. Come join us and influence the future of our great state.
Belong in our diverse and inclusive workplace
The strength of our workforce lies in its diversity and embracing difference, while the key to our success is leveraging the contributions of employees with different backgrounds and perspectives.
You can view our full diversity and inclusion statement here.
We provide adjustments to the recruitment process for candidates, including individuals with disability. If you require an adjustment during the recruitment process, including alternate formats or have questions about the support available, please contact Talent Operations on 02 8276 8130 or
[email protected].
For more information, please visit
Information on some of the different types of disabilities
Information on adjustments available for the recruitment process