Infrastructure & Cybersecurity Engineer

🗓️ Posted 2026-08-19 Brisbane QLD Full-time Hybrid ICT

Company shared salary

A$9,167–A$11,667/mo (A$110,000–A$140,000/yr)

Market rate

A$8,333–A$14,167/mo (A$99,996–A$170,004/yr)

Based on similar roles (title + domain + location).

About the Company

Buckham & Duffy (B&D) is a Brisbane-based technology consulting and software delivery firm. We partner with government, international development organisations, industry associations, and mid-market enterprises to deliver technology strategy, custom SaaS products, and digital transformation programs. We're a tight team of 20 professionals who value sharp thinking, low ego, and getting things done. We're scaling our security and infrastructure practice, and we need a strong technical engineer to do it with us. This is a hands on role with a lot of self-direction. You'll be working on our internal cyber capacity and hardening as well handling the cyber/infrastructure programs that we run for our clients. We develop a lot of custom internal tooling to assist with the delivering and maintenance of our infrastructure and cyber setups so we're looking for a creative thinker who looks to drive outcomes; not just run benchmark suites. You'll need a solid Linux and AWS backing as all our digital assets are Linux OS based and cloud infrastructure is mostly AWS with a small amount of Azure. If you're the type of person that maintains a homelab, you'll fit in well here. We have a strong focus on maintainability so Terraform and Ansible are at the core of everything we do.

Responsibilities

  • Administer Linux servers and Proxmox virtualisation across multiple environments.
  • Deploy and manage self-hosted services (mostly docker compose stacks running FOSS platforms)
  • Harden and operate cloud environments across AWS, Microsoft 365 and Azure - identity, conditional access, tenant baselines, workload controls.
  • Apply CIS Benchmarks and equivalent hardening standards as the default baseline.
  • Operate and tune SIEM platforms: triage alerts, develop rules, manage log sources, report on posture.
  • Monitor and validate backups
  • Configure and maintain firewalls, VPNs, and network segmentation .
  • Run basic vulnerability scanning and penetration testing , validate findings, and drive remediation.
  • Lead incident response coordination with our development team
  • Drive monthly reporting to our clients on continuous improvement activities

Requirements

  • 3+ years in a hands-on technical security or infrastructure engineering role.
  • Demonstrable experience hardening and operating AWS, Microsoft 365, and Azure environments.
  • Practical SIEM administration experience (rule tuning, log sources, alert triage).
  • Strong Linux administration skills - comfortable in the cli
  • Experience with Proxmox or a comparable virtualisation platform (VMware, Hyper-V, KVM).
  • Working knowledge of CIS Benchmarks or equivalent hardening standards.
  • Firewall and networking experience covering segmentation, VPNs, and rule management.
  • Familiarity with vulnerability scanning and basic penetration testing tooling and methodology.
  • Clear written and verbal communication, including the ability to brief non-technical stakeholders.
  • IAAS experience, ideally Terraform
  • Ansible
  • Security certifications (Security+, AZ-500, AWS Security Specialty, OSCP, SSCP, or equivalent).
  • Experience supporting government or regulated clients (IRAP, ISM, Essential Eight, ISO 27001).
  • Prior consulting or MSP delivery experience.