This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a highly accomplished Lead Systems Engineer to serve as a technical authority and strategic technical architect for our hybrid infrastructure. This is a 'strong generalist' role designed for a professional who possesses deep technical mastery across the Microsoft 365 and AWS ecosystems, paired with the commercial acumen to drive long-term IT strategy. The successful candidate will lead the transition from legacy infrastructure to a modern Zero Trust architecture, ensuring our global environment is secure, automated, and cost-optimized. You will act as a bridge between complex technical execution and executive leadership, translating sophisticated infrastructure requirements into clear business outcomes.
Job Responsibility:
Act as a primary advisor to the leadership team, possessing the ability to articulate complex technical concepts to non-technical stakeholders with clarity and precision
Contribute to the development and execution of a multi-year IT strategy that aligns with organizational growth and security objectives
Conduct regular audits of Microsoft 365 licensing (Business vs. Enterprise) and cloud consumption (AWS/Azure) to identify cost-saving opportunities and ensure maximum return on investment
Lead by example, fostering a culture of high performance, thorough documentation, and continuous improvement within the engineering team
Provide expert-level administration of the Microsoft 365 tenant, with a focus on Intune (Endpoint Manager) for Autopilot and compliance, SharePoint Online architecture, and Exchange Online security
Act as the primary architect for Entra ID (Azure AD). Oversee the lifecycle of Enterprise Applications, including SAML/OIDC SSO integrations, App Registrations, and Conditional Access policies to ensure secure, seamless user authentication
Architect and manage Zscaler (ZIA & ZPA) environments to provide secure, seamless access to internet and private resources, replacing traditional VPN dependencies
Design and optimize our primary AWS footprint, focusing on Application Load Balancers (ALB), VPN Gateways, and Route 53. Maintain and govern Azure workloads and Entra ID (Azure AD) integrations
Oversee the integrity of Active Directory, Group Policy (GPOs), DHCP, and DNS. Manage the Microsoft PKI (AD CS) environment to support RADIUS (NPS) and certificate-based authentication (802.1X)
Drive operational efficiency through advanced PowerShell scripting and API integrations (Microsoft Graph). Manage and maintain Docker container environments for modern application delivery
Requirements:
Exceptional verbal and written communication skills
demonstrated ability to 'explain complex topics simply' to diverse audiences
A proactive approach to security validation, ensuring all infrastructure aligns with the ACSC Essential Eight and modern cybersecurity frameworks
7+ years in Systems Engineering, with at least 3 years in a Lead or Senior capacity managing enterprise-scale hybrid environments
Expert knowledge of Windows Server (2016-2022), Windows Desktop, and high-availability networking protocols (BGP, OSPF, VLANs)
Must hold, or be eligible to obtain, an Australian Government Baseline Security Clearance (requires Australian Citizenship)
What we offer:
Flexible working – We genuinely consider all flexibility requests
Growth – Career development opportunities across our expanding business
Discounts – Access to hundreds of major retailers including Woolworths, Airbnb, JB Hi-Fi, and Bupa
Paid leave – Parental, cultural, community service, study, corporate volunteering, and purchased leave
Culture – A workplace that values diversity, inclusion, and celebrates excellence