Role: ICT Security Lead (Technical) (Internal Title: ICT Security, Risk & Compliance Lead)
Location: Murarrie, Brisbane
Employment Type: Full-time, Permanent
Our Role
At Goodstart, we're committed to keeping the information of our children, families and people safe. We're looking for an experienced ICT Security Lead (Technical) to join our cybersecurity team and play a hands-on role in strengthening Goodstart's security environment and cyber resilience.
Reporting to the ICT Manager – Security & Risk, you'll work across our technology environment to implement and improve security controls, respond to incidents, remediate vulnerabilities and strengthen our overall security posture.
This is a hands-on technical cybersecurity role, with a strong focus on identity and access security, Microsoft security technologies, vulnerability management and the implementation of the Essential Eight.
You'll work across technologies including Microsoft Entra ID, Microsoft Defender and Microsoft Sentinel, while partnering with infrastructure, application and business teams to drive security improvements through to completion.
We're looking for someone who enjoys getting hands-on with technology and solving complex security challenges, but who can also build strong relationships and translate technical security risks into practical, business-focused actions.
Your Impact
- Design, implement and continuously improve Microsoft Entra ID security controls, including Conditional Access, Privileged Identity Management (PIM) and Privileged Access Management (PAM).
- Configure and manage Microsoft Defender and Microsoft Sentinel, including security policies, analytics rules, KQL queries and playbooks.
- Implement and mature Essential Eight security controls, including application control, patching, macro controls and restriction of administrative privileges.
- Lead the remediation of vulnerability and penetration testing findings, working with infrastructure, application and business owners to drive issues through to closure.
- Participate directly in security incident response, including triage, containment, investigation and evidence handling.
- Support the management and security of digital certificates, root certificates and authentication tokens across the technology environment.
- Identify security risks and provide practical, technically informed recommendations to technology teams and business stakeholders.
- Monitor and improve Goodstart's security controls, identifying opportunities to strengthen the organisation's cyber resilience and reduce security risk.
- Work collaboratively with teams across ICT to implement security improvements and ensure remediation actions are completed.
- Translate complex technical security findings into clear, practical advice for non-technical stakeholders.
- Contribute to the ongoing development of security engineering practices, standards and capabilities across Goodstart.
What Goodstart can offer you:
- Enjoy flexible work arrangements that support both your professional and personal commitments.
- Salary packaging benefits available through AccessPay (eligibility applies).
- Access to discounted childcare (up to 15%).
- Fitness Passport – access to gyms and pools for you and your family at a heavily discounted price.
- Discounted health care and access to employee wellbeing program with BUPA.
- Exclusive discounts on travel, gym memberships, Apple and Dell products, and more.
- Free annual flu shot (optional).
- Option to purchase extra leave for even greater work-life balance.
- First Nations Support and Cultural Leave.
- Work for a company that aspires to be globally recognised for early years practice and learning outcomes.
- Gain significant investment in your growth and development with ongoing support, tools, training and experiences that will enhance outcomes for children in their earliest years.
You'll bring to the table
We're looking for a technically hands-on cybersecurity professional who has built and implemented security capabilities, rather than someone whose experience is primarily focused on governance, risk or audit.
You'll bring:
- 5+ years' experience in cybersecurity engineering, information security or a similar hands-on technical security role.
- Strong hands-on experience designing and implementing Microsoft Entra ID, including Conditional Access, Privileged Identity Management (PIM) and Privileged Access Management (PAM).
- Hands-on experience with Microsoft Defender and Microsoft Sentinel, including security configuration, analytics rules, KQL and playbooks.
- Demonstrated experience implementing Essential Eight controls, rather than solely assessing or reporting on compliance.
- Proven experience managing and driving vulnerability and penetration testing remediation through to closure, including working with teams and stakeholders outside of your direct reporting line.
- Hands-on experience responding to cybersecurity incidents, including triage, containment, investigation and evidence handling.
- Strong understanding and practical experience with digital certificates, root certificates and token management.
- Strong understanding of modern identity security risks, including phishing-resistant authentication, token theft and session hijacking.
- Strong stakeholder management skills, with the ability to influence technical teams and business stakeholders to address security risks and competing priorities.
- Excellent communication skills, with the ability to explain technical security risks and recommendations clearly to non-technical audiences.
- Relevant tertiary qualifications in Information Technology, Cybersecurity or a related discipline, or equivalent practical experience.
- Industry certifications such as CISSP, CISM, Microsoft security certifications or similar will be highly regarded, but hands-on implementation experience is essential.
- Current QLD Blue Card (or the ability to obtain one).
How to apply
Click 'Apply Now' and submit your application.
We review applications as they're received and encourage you to apply as soon as possible to give yourself the best opportunity to progress through the recruitment process.
Have a question? Contact Faith in our Talent Acquisition Team via email: flethbridge@goodstart.org.au
At Goodstart we are deeply committed to Reconciliation and encourage Aboriginal and/or Torres Strait Islander people to apply. For further information and support email deadlycareers@goodstart.org.au.
If you are a placement agency or external recruiter, please refrain from submitting resumes to Goodstart unless you have a signed staffing agency agreement with us. Goodstart will not be responsible for or pay any placement fees for candidates submitted by agencies or external recruiters without an agreement.
Supporting our people and protecting our children
We're an equal opportunity employer that is proud of our inclusive and diverse work environment. We know that Goodstarters from diverse cultures, backgrounds and experiences strengthen our teams and help us grow.
Safety is our priority and we will take any action necessary to ensure that all children can feel safe and be safe, and are safeguarded from abuse, neglect and harm. As a Child Safe Organisation, all candidates must have or obtain a valid Working with Children Check.
Job Segment:
Engineer, Recruiting, Engineering, Human Resources