We are building a next-generation, AI-first financial services platform on Microsoft’s ecosystem—where identity, endpoint, messaging, and AI interaction layers are unified under a Zero Trust security model.
This role is designed for a high-potential junior practitioner who will be trained to operate within enterprise-grade security, governance, and engineering standards.
You will contribute to a tightly controlled Microsoft environment spanning:
-
Microsoft 365 Business Premium
-
Exchange Online (secure communications layer)
-
Microsoft Entra ID (identity control plane)
-
Microsoft Intune (endpoint governance & compliance)
-
Microsoft Graph (secure API automation layer)
-
Microsoft Copilot (AI within controlled, compliant boundaries)
You will operate within a system aligned to Australian regulatory standards.
Your Mission
Support and progressively take ownership of a secure ecosystem where:
- Identity governs access
- Devices enforce trust
- APIs execute securely
- AI operates within guardrails
- Every action is logged, attributable, and auditable
Key Responsibilities
1. Identity & Access Control (Microsoft Entra ID)
-
Support RBAC and least-privilege access enforcement
-
Assist with Privileged Identity Management (PIM)
-
Maintain identity lifecycle (joiner, mover, leaver)
-
Implement and monitor Conditional Access policies
2. Endpoint Security & Device Compliance (Microsoft Intune)
-
Assist with device enrolment (corporate & BYOD)
-
Support compliance policies and posture enforcement
-
Manage application protection policies (MAM)
-
Support remote wipe, risk signals, and secure access controls
3. Secure Messaging & Collaboration (Exchange Online)
-
Configure mail flow rules and transport policies
-
Support anti-phishing protections (SPF, DKIM, DMARC)
-
Assist with Data Loss Prevention (DLP)
-
Ensure secure and auditable communications
4. Microsoft 365 Security, Compliance & Copilot Governance
-
Support Microsoft Defender and Secure Score initiatives
-
Assist with Microsoft Purview (retention, classification)
-
Help govern Microsoft Copilot usage within compliance boundaries
-
Contribute to AI-safe data access and governance
5. API & Automation Layer (Microsoft Graph)
-
Assist with secure Graph API interactions
-
Support identity-aware automation workflows
-
Ensure API authentication, authorization, and auditability
6. Data Protection
-
Support encryption standards (TLS 1.2+, encryption at rest)
-
Maintain secure authentication and identity token practices
-
Ensure zero exposure of sensitive data
7. User Experience (Security-First Design)
-
Help design friction-aware security workflows
-
Support intuitive onboarding and secure collaboration
-
Balance usability with strict policy enforcement
What We’re Looking For
Core Technical Foundations
-
Basic understanding of:
Microsoft 365 ecosystem
Entra ID (Azure AD)
Exchange Online
Microsoft Intune (preferred but not required)
-
Awareness of:
RBAC and identity governance
MFA, Conditional Access, Zero Trust
API fundamentals (Graph exposure is a plus)
Mindset (Critical)
-
Strong attention to detail and precision
-
High ethical standards and respect for data privacy
-
Comfortable working in structured, compliance-driven environments
-
Strong willingness to learn enterprise security and systems thinking
What Will Set You Apart
-
Exposure to:
Microsoft Graph API
PowerShell or scripting
Microsoft Defender / Purview
Copilot or AI governance
-
Interest in financial services or regulated industries
-
Understanding that identity is the primary security boundary
What You Will Gain
-
Hands-on experience with enterprise Microsoft architecture
-
Structured training in a high-security environment
-
Exposure to a multi-tenant SaaS platform
-
Practical experience in:
Identity-centric security
Endpoint trust enforcement
Secure API orchestration
AI governance in regulated systems
Why Join Us
This role is part of a strategic initiative to build one of the most advanced, secure, and compliant lending platforms in Australia.
You will work in an environment where:
-
Identity, device, API, and AI layers are tightly integrated
-
Every control is measurable and auditable
-
Every system decision must withstand regulatory and forensic scrutiny