Sivakumar Saravanamuthu

♦ Cybersecurity Architect ► IRAP, Azure, AWS, ISM, NIST, Vulnerability Management, Strategy & Governance, Data Platforms, Automation, Infrastructure as Code (IaC),DevSecOps

Greater Melbourne Area

About

Twenty years in, and I still get a kick out of the moment a design clicks. When ASD ISM controls stop looking like a compliance tax and start looking like the thing holding a system up. I'm a Senior Security Architect. I work with Australian federal agencies, Government Business Enterprises, critical infrastructure, and large enterprise. Australian citizen, based in Melbourne. Most of my work is turning regulation into something buildable. ISM, PSPF, Essential Eight, IRAP, ISO 27001, NIST CSF, CPS 234. I lean SABSA because I want the business driver before the control. I also spend plenty of time inside engineering squads, threading OAuth 2.0, OIDC, mTLS, and conditional access through systems that are actually running. A few recent pieces of work. At Services Australia I'm leading the security architecture for the national uplift program responding to the Ashton Review. I also pushed back on a Symantec DLP renewal and built the business case that moved the agency onto Microsoft Purview under its existing M365 E5 entitlement. The three-datacentre HashiCorp Vault I put through ARB is now the enterprise secrets pattern. Before that, at Deloitte, I advised CISOs and Boards across ADHA, EnergyAustralia, Transport for NSW, BUPA, and Victoria's water sector. IRAP-aligned SSPs, Zero Trust for classified boundaries, a six-month job closing 2,000+ vulnerabilities against a regulatory deadline. I also pulled remediation time down by 40% by building security into Terraform, Ansible, and Azure DevOps pipelines instead of inspecting for it afterwards. I started out as an engineer. RHCE since 2006. CKA, CKAD, AWS Security Specialty, Azure Architect, CCNP. CISSP in progress. That's why I'm as happy with a board paper as I am with a Terraform module. The bit I enjoy is when risk stops being abstract. When "residual risk" becomes "these three things break if this control fails, and here's what that costs us." If any of that is close to something you're working on, I'm happy to talk.

Experience

  • Security Architect at Services Australia
    Jan 2025 - Present · 1 yr 7 mos

    I played a pivotal role in enhancing security architecture at Services Australia through strategic initiatives. • Designed an Azure Landing Zone that met strict Australian Government security requirements, integrating NIST-CSF and ASD-ISM controls. • Established comprehensive Essential 8 maturity guidelines, creating a roadmap for security posture improvement across diverse environments. • Led the architecture for a national project to mitigate security risks for frontline staff, fostering inter-agency collaboration.

  • Deloitte (2 yrs 11 mos)
    • Senior Cyber Architect / Cloud Security Architect
      Mar 2022 - Jan 2025 · 2 yrs 11 mos

      • Consulted with C-suite executives to enhance cybersecurity postures for major organisations in the energy, insurance, and government sectors. • Developed and implemented a Cloud Security Governance Framework, addressing audit findings and building internal capabilities. • Led critical vulnerability remediation efforts, prioritising over 2,000 vulnerabilities in alignment with CIS standards.

    • Security Architect
      Mar 2022 - Jan 2025 · 2 yrs 11 mos

      As a Security Architect, I led technical consulting for Deloitte's largest national accounts, reporting to the Partner for Security Architecture and Cloud. My focus spanned cloud security strategy, operations, GRC (Governance, Risk, and Compliance), and providing architectural oversight.

  • Senior Infrastructure Engineer at Kyndryl
    Jul 2021 - Feb 2022 · 8 mos

    • Led the technical implementation of Kyndryl’s largest Infrastructure as Code project in Australia for a major energy retailer. • Provided architectural and design oversight while driving hands-on thought leadership throughout the deployment process. • Developed a DevSecOps pipeline for vulnerability and patch management, enhancing security and operational efficiency. • Created Terraform and Ansible playbooks for cloud automation, ensuring streamlined infrastructure provisioning and management.

  • Senior Infrastructure Engineer at Kyndryl Australia (an IBM company)
    Jul 2021 - Feb 2022 · 8 mos

    Brought in post-contract to lead the technical implementation of Kyndryl’s largest Infrastructure as Code (IaC) project in Australia for a major energy retailer. I provided end-to-end architectural oversight and hands-on thought leadership throughout the deployment and operationalization phases.

  • Senior Cloud Engineer at CSL
    May 2018 - May 2021 · 3 yrs 1 mo

    • Spearheaded Red Hat infrastructure management for over 700 global RHEL VMs, enhancing support for manufacturing and scientific research sectors. • Led major infrastructure projects, providing technical oversight and thought leadership in deployment and architecture roles. • Drove advancements in automation, containerization, and virtualization, while implementing robust security practices.