Sobre este puesto de Systems Security Engineer en Anduril Industries
Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.
About the Team
We are seeking an Infrastructure Security Engineer to drive security engineering and operational security across both our Australian and corporate ICT environments. You will work alongside a small infrastructure team responsible for designing, hardening and operating networks accredited under the Australian Government’s Protective Security Policy Framework (PSPF) and the ASD Information Security Manual (ISM), as well as supporting security tooling on the corporate network.
The ideal candidate has hands-on experience with security platforms spanning endpoint protection, SIEM, vulnerability management, identity and access management, and privileged access management. They are comfortable operating in environments subject to Australian Government security frameworks and can translate ISM controls and Essential Eight maturity targets into practical engineering outcomes.
About the Job
What You’ll Do
- This is not an ISSO or ISSM role. This is a technical, hands-on security engineering position.
- Own and operate security tooling across Australian and corporate networks, including deployment, configuration, tuning, patching and lifecycle management.
- Administer and mature the Australian network’s security stack, including application whitelisting, SIEM, vulnerability scanning, endpoint antivirus and privileged access management.
- Support corporate network security platforms, including endpoint detection and response, identity and access management, privileged access management, and device trust and compliance.
- Drive Essential Eight maturity uplift across Australian environments, with a focus on application control, patching, privileged access restriction, multi-factor authentication and regular backups.
- Develop and maintain SIEM use cases, detection rules, correlation searches and dashboards to provide actionable visibility across the environment.
- Conduct regular vulnerability assessments, analyse findings, prioritise remediation and track closure through the Plan of Action and Milestones (POAM) register.
- Perform security hardening of Windows Server, Active Directory, virtualisation platforms, storage infrastructure and network devices in accordance with ASD hardening guidance and the ISM.
- Contribute to security architecture assessments, threat modelling and risk assessments for new and existing systems.
- Collaborate with infrastructure engineers to integrate security into system designs, change plans and standard operating procedures.
- Support system accreditation activities, including preparation of security documentation (SSPs, SRMPs, IRPs, DLDs) and evidence gathering for assessments.
- Brief security posture, risks and recommendations to management and government stakeholders.
- Assist with security incident response, investigation and post-incident review.
Required Qualifications
- Three or more years of experience in one or more of the following: cyber security engineering, security operations, systems security, infrastructure security or security architecture.
- Hands-on experience with at least three of the following security platform types:
- Application whitelisting or application control
- SIEM and log management
- Vulnerability scanning and assessment
- Endpoint detection and response (EDR)
- Privileged access management (PAM)
- Identity and access management (IAM)
- Strong understanding of Active Directory, Group Policy, Windows Server hardening and Kerberos authentication.
- Familiarity with Australian Government security frameworks: the ISM, PSPF, Essential Eight Maturity Model and associated ASD guidance.
- Excellent verbal and written communication skills, with the ability to produce clear security documentation and brief both technical and non-technical audiences.
- A collaborative, low-ego approach to working in a small team where everyone shares the load.
- The ability to obtain and maintain a NV2 security clearance.
Preferred Qualifications
- An existing NV2 security clearance.
- Experience working in or supporting high-security environments accredited under Australian Government frameworks.
- Experience with Windows Server and VMware vSphere administration and security hardening.
- Experience with enterprise backup and recovery platforms and an understanding of data protection requirements under the ISM.
- Familiarity with device trust and compliance tooling.
- Experience developing SIEM dashboards, alerts, detection content and integrations.
- Scripting skills in PowerShell, Python or Bash for automation of security operations tasks.
- Familiarity with PKI, certificate lifecycle management and TLS/mTLS implementation.
- Experience with ASD’s hardening guidance for Active Directory (including the joint ASD/CISA/NSA advisory on detecting and mitigating AD compromises).
- Experience supporting system accreditation under the ISM and PSPF, including preparation of Security System Plans (SSPs) and security risk management documentation.
- Relevant industry certifications such as GIAC (GSEC, GCIH, GCIA), CompTIA Security+/CySA+, Microsoft SC-200 or equivalent.
- Experience with configuration management and patching platforms.
The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:
Benefits
At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.
Protecting Yourself from Recruitment Scams
Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.
To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:
-
No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.
- Please always verify communications:
- Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an
@anduril.comaddress. - Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to [email protected].
- Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an
-
Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain is @anduril.com before providing any personal information or clicking on links.
-
What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to [email protected]. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.
Data Privacy
To view Anduril's candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/.
By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.