Job Description
Senior End User Computing Windows Desktop Engineer
Australian citizenship required. Must be able to obtain Baseline security clearance.
Location: Canberra (Onsite).
What to Submit
- A tailored resume in docx format
- A one page (5000 character) summary response to the selection criteria below.
RFQ Details
- RFQ ID: LH-07841
- Agency: Department of Industry, Science and Resources
- Closing Date: Friday, 25 September 2026 • 11:59pm, Canberra time
- Estimated Start Date: Monday, 19 October 2026
- Initial Contract Duration: 12 months
- Extension Term: 12 months
- Number of Extensions: 2
- Experience Level: Senior - EL1 equivalent
- Security Clearance: Must be able to obtain Baseline
- Location of Work: ACT
- Working Arrangements: Onsite. This role is based in Canberra, ACT. Flexible work (WFH) arrangements may be considered on a case-by-case basis in consultation with the supervising manager, subject to business needs, however, this role is not suitable for 100% remote delivery.
- Maximum Hours: 40 hours per week
Job Details
As a Senior End User Computing (EUC) Engineer, you will provide Level 3 engineering, automation and operational support across the department's end-user computing platforms and services. This role has a strong focus on engineering, automation and service modernisation through Azure DevOps, Azure Pipelines, Microsoft Purview Information Protection (MPIP) and PowerShell.
This recruitment round is specifically seeking candidates with strong, recent and hands-on experience in Azure DevOps, Azure Pipelines and Microsoft Purview Information Protection. These capabilities are critical to the team's current and future delivery objectives and will be assessed as priority requirements throughout the recruitment process.
You will work closely with technical teams and stakeholders across the department to deliver secure and reliable end-user services, improve operational efficiency through automation, and provide expert technical advice on supported platforms and technologies. The role requires a high degree of technical expertise, initiative and problem-solving capability, together with strong communication and stakeholder engagement skills.
Key Duties and Responsibilities
- Independently design, engineer, maintain and provide Level 3 support for complex end-user computing platforms, including the SOE, corporate devices, productivity services and remote access.
- Develop and support automation, deployment pipelines and configuration-as-code solutions using Azure DevOps, Azure Pipelines, Git and PowerShell, including automated deployment of Microsoft Purview Information Protection controls.
- Plan and implement upgrades, migrations, application deployments, patching and service changes across non-production and production environments.
- Monitor application, endpoint, platform and end-to-end service health, capacity and performance; proactively identify issues, diagnose root causes and implement sustainable remediation.
- Apply independent technical judgement to produce designs, evaluate options, manage technical risks and resolve complex issues.
- Work collaboratively with other technical teams, vendors, and Level 1 and Level 2 support staff to deliver changes, resolve incidents and improve support outcomes.
- Produce and maintain technical designs, implementation and test plans, operational procedures and support documentation, and uplift team knowledge through guidance, knowledge transfer and technical support where required.
Technical Skills
- Endpoint and Standard Operating Environment: Windows 11, Windows Server components supporting EUC services, Microsoft Intune, Microsoft Configuration Manager, Group Policy, Windows Autopilot, iOS and iPadOS device management, Apple Business Manager, BitLocker, Microsoft Defender for Endpoint, Microsoft Defender XDR and related monitoring and management tools.
- Application Control, Hardening and Essential 8 controls: Microsoft Defender, application whitelisting and execution control technologies, attack surface reduction (ASR) rules, Microsoft Office macro security controls and implementation of ACSC and vendor hardening guides for operating systems and applications.
- Azure Virtual Desktop and remote access: Azure Virtual Desktop host pools and published applications, Azure Monitor and Log Analytics, FSLogix, and enterprise VPN services.
- DevOps, automation and configuration as code: Azure DevOps, Azure Pipelines, PowerShell, and deployment automation across non-production and production environments.
- Information protection and compliance: Microsoft Purview Information Protection, sensitivity labels, label policies and Data Loss Prevention configurations.
- Productivity, messaging and collaboration: Microsoft 365 Apps for enterprise, Exchange Server, Exchange Online, Microsoft Teams, OneDrive for Business and associated administrative services.
- Application and patch management: application packaging and deployment technologies, Microsoft Intune, Microsoft Configuration Manager, Patch My PC, Windows Update services, Microsoft 365 Apps servicing channels, vulnerability remediation, and patch governance aligned to Essential 8 and organisational security requirements.
Selection Criteria
Essential criteria
- 1.Demonstrated expert, hands-on experience with Azure DevOps and Azure Pipelines, including source control, branching and pull-request practices, deployment stages, approvals, variables, service connections, troubleshooting and controlled releases across non-production and production environments.
- 2.Demonstrated hands-on experience administering and engineering Microsoft Purview Information Protection, including sensitivity labels, label policies and Data Loss Prevention configurations, together with the automation, testing, deployment and ongoing support of these capabilities.
- 3.Demonstrated experience managing and configuring Azure Virtual Desktop in an enterprise environment. Expert knowledge of Windows 11, Microsoft Intune and Group Policy, including configuration, compliance, MDM/MAM, application deployment, patching and Standard Operating Environment management.
- 4.Demonstrated experience managing Microsoft 365 Apps for enterprise, including servicing profiles, update channels, deployment.
- 5.Demonstrated ability to produce high-quality technical designs, standard operating procedures, implementation plans and operational documentation.
Desirable criteria
- 1.Experience with Australian Government IT Cyber Security processes including ISM, Essential 8 and ACSC hardening guides.
- 2.Experience with Exchange, Exchange Online.
Why choose Pinaka
We know the government ICT market and we keep things straightforward. We take time to understand your background, your goals and the type of role that suits you. We believe transparency is about more than rates and our margins are fair and always disclosed.
What you can expect from us...
- Fair, disclosed margins
- Clear communication at every stage
- Honest advice on fit and competitiveness
- Visibility on submissions and process status
- A professional and respectful experience
How you are paid...
You choose what's best for you.
- PAYG through Pinaka
- Third-party payroll
- Self-employed (own ABN)
- With a single, transparent and fixed margin, we ensure compliance to all state and payroll laws. So that is one less thing for you to worry about.
BYO CONTRACT
Already in a role but not happy with the setup?
Port in your contract to Pinaka for a simpler and more transparent experience. We also have some exciting limited time offers on top of the incredible margins we offer.
BETTER TOGETHER ™
Our referral program for people who introduce strong candidates to us.
Refer a friend - Earn $1/hr per successful referral as long as you both with us. Refer as many friends as you want; no caps.