End User Computer Security Engineer - 12 Month Fixed Term Contract

  • Full-time

Company Description

We’ve been around since 1988, and today we’re one of Australia’s largest profit‑to‑member super funds.

That means everything we do is focused on delivering better outcomes for our members – not shareholders.

Closing date:  9th October 2026

Please note Rest does not accept speculative resumes from recruitment agencies 

Rest will review applications prior to the closing date and may close the role earlier 

Job Description

  • Join Rest, a purpose-driven organisation helping more than 2 million Australians achieve a better retirement

  • Protect and enhance the security of the technology thousands of Rest employees rely on every day.

  • 12 Month Fixed Term Contract - Sydney Located - Hybrid Working 

At Rest, we help more than 2 million Australians to build a better financial future. With around $112 billion in funds under management, we focus on delivering strong long-term outcomes for our members — from their first job through to retirement*. Your best at Rest means focusing on what matters, being trusted to get on with it, and knowing your work genuinely makes a difference. That’s how we operate every day, guided by our values: Be Daring, Keep It Simple, Take Action and Have Grit.

Join us as a End User Computer Security Engineer on a 12 Month Fixed Term Contract where you’ll Engineer and sustain security controls across Rest’s end-user computing estate, including Windows, macOS, mobile devices, browsers and productivity services. Embed security into endpoint standards and operational processes while preserving usability and reliable service delivery.

Accountabilities/Responsibilities

  • Define, implement and sustain hardened security baselines across Windows, macOS, mobile devices, browsers and productivity platforms, aligned to the Essential Eight, CIS benchmarks and Rest standards.
  • Engineer and optimise endpoint detection and response, device compliance, application control, encryption, local privilege, privileged access and browser security controls.
  • Integrate endpoint telemetry with SIEM and incident response processes, investigate control gaps and incidents, and provide actionable evidence to support response and assurance activities.
  • Own the remediation of prioritised endpoint, operating system, browser, productivity-platform and device-control findings identified through security tooling and the vulnerability management process.
  • Coordinate and deploy fixes with Endpoint Services and M365 teams, automate configuration validation and remediation, and verify effective closure while maintaining reliable service delivery and user experience.
  • Lead end-user compute risk exemption activities by assessing residual risk, documenting business justification and compensating controls, coordinating approvals, and monitoring exemptions through review or expiry.
  • Provide security standards, exceptions, playbooks, evidence and secure operating guidance that embed security within endpoint operations and support consistent decision-making.

Qualifications

What we are looking for; 

The successful candidate will bring strong endpoint-security engineering capability, practical automation experience and a proven ability to balance security risk with reliable service delivery and user experience

Experience, skills and qualifications

  • Demonstrated experience engineering and operating Microsoft Intune, Defender for Endpoint, Entra ID and Conditional Access in a complex enterprise environment.
  • Strong knowledge of Windows and macOS security, mobile device management, browser security and productivity-platform controls.
  • Proficiency in PowerShell and Microsoft Graph, with experience automating configuration validation, remediation and evidence collection.
  • Practical experience with the Essential Eight, CIS benchmarks, EDR/XDR, BitLocker or FileVault, application control, privileged access and vulnerability management.
  • Proven ability to troubleshoot complex endpoint issues and balance security, reliability and user experience.
  • Strong documentation, communication and stakeholder-engagement skills, including the ability to develop standards, playbooks, risk exemptions and secure operating guidance.
  • Relevant Microsoft endpoint or security certification is desirable.

Additional Information

.What you'll find at Rest

  • Hybrid working
  • 5 Rest Days (wellbeing days) each year in addition to annual leave
  • Eligible employees are entitled to 22 weeks paid parental leave (gender neutral)
  • Continued super contributions during parental leave
  • Learning and development opportunities, including AI & Data Academy, leadership programs, LinkedIn Learning, study assistance and professional memberships
  • Income Protection Insurance
  • Option to purchase additional leave
  • Recognition through our Rest Excellence Awards

If you share our values and this sounds like the kind of place you’d do your best work, we’d like to hear from you. Apply now.

Rest is committed to creating a flexible work environment and culture that embraces diversity, equity, and inclusion - where people feel welcome, safe to be themselves and inspired to do their best.

We value the different backgrounds, lived experiences and abilities our diverse team brings. We welcome and encourage applications from candidates of all ages, cultural backgrounds, faiths, gender identities, sexual orientations and thinking styles. This includes people with disability, neurodiverse individuals, Aboriginal & Torres Strait Islander peoples and those with disrupted work history due to career or other breaks.

We welcome applications from all candidates. To be considered, you will need the right to work in Australia.

*Funds under management as at 30 June 2026. Rest is recognised as a superannuation leader across a range of areas including performance, responsible investment and member value. Find out more at https://rest.com.au/why-rest/awards.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice