Case Study: Uplifting a deployed ICT capability through secure Windows and automation engineering
Client: Department of Defence, Directorate of Deployed ICT (D-ICT), Headquarters on the Move (HQOTM)
Project: Headquarters on the Move (HQOTM) capability uplift
How Profectus rapidly mobilised a cleared senior Windows and PowerShell automation engineer to uplift the Headquarters on the Move capability, introducing automation, CI/CD and secure engineering practice under stringent Defence security and accreditation constraints.
Client and context
The Directorate of Deployed ICT (D-ICT) is a specialist branch within Defence responsible for the design, delivery and sustainment of deployed information and communications technology capabilities used by the Australian Defence Force during operations, exercises and contingencies. Its mission is to ensure deployed headquarters, command elements and tactical units have secure, reliable and interoperable ICT services that mirror the enterprise environment, even in contested, remote or bandwidth-limited conditions.
D-ICT enables Defence to maintain command and control effectiveness beyond fixed facilities by integrating communications, computing and information systems into mobile and deployable platforms. The directorate required an experienced Windows and PowerShell automation engineer to support the uplift of the Headquarters on the Move (HQOTM) capability, a complex system of systems bridging the tactical communications network (TCN) and the battlefield telecommunications network (BTN), enabling secure command, control and data exchange while on the move across protected mobility platforms in deployed operations.
The engagement
Profectus was engaged to rapidly deploy a cleared, high-calibre automation engineer to augment the D-ICT internal team at its Deakin (ACT) facility, providing technical uplift and continuity as the capability transitions to production. Through our Defence-aligned recruitment process and technical vetting, Profectus mobilised the senior Windows and automation engineer within two weeks of request. The specialist remains actively embedded within the D-ICT engineering team, working collaboratively with Defence engineers and stakeholders to deliver ongoing technical delivery, support and mentoring.
The challenge
The precise operational challenges faced by the directorate are subject to top secret classification and cannot be disclosed. Broadly, D-ICT required advanced technical expertise to mature a highly specialised deployed ICT capability operating within sensitive environments:
- Bridging domains: connecting tactical and operational networks so that HQOTM could exchange information securely across classifications while on the move
- Integrity in motion: maintaining system integrity and configuration control in mobile conditions where consistency across deployed nodes is critical
- Modern sustainment: introducing automation, CI/CD and DevOps practices into an environment that had relied on manual build and deployment processes
- Security constraints: delivering all of this under stringent security, accreditation and operational constraints within classified environments
Our approach
Working alongside Defence engineers, the embedded specialist delivered technical uplift across four connected fronts.
Automated build and deployment
The engineer designed and documented HQOTM mission processing environment (MPE) node builds within secure virtualised environments, and developed PowerShell automation modules to streamline node deployment, configuration and patching, reducing manual overhead and improving environmental consistency across deployed nodes.
CI/CD and DevOps engineering
GitLab Actions CI/CD pipelines were implemented to enable automated testing, validation and version control, supported by structured code review and documentation standards aligned with modern DevOps methodologies. This embedded repeatable, traceable engineering practice into the D-ICT delivery model to accelerate future capability releases.
Secure engineering practice
Secure engineering principles were applied across configuration, automation and software deployment in line with the ISM, PSPF and DISP requirements. Automation artefacts were made traceable, repeatable and subject to change control, with secure handling of credentials, restriction of privileged access, validation of execution paths and enforcement of controlled deployment practices to reduce operational and security risk.
Governance and sustainment
The engineer authored standard operating procedures (SOPs), baseline lists of installation (BLIs) and a patch management plan to support sustainment and accreditation, strengthening compliance, auditability and traceability, and integrated HQOTM systems with interfacing applications across tactical and operational networks.
What we delivered
- Rapid mobilisation: a cleared senior Windows and automation engineer on-site within two weeks of request, embedded within the D-ICT engineering team
- Automation uplift: PowerShell automation modules and GitLab Actions CI/CD pipelines that streamlined node deployment, configuration, patching, testing and version control
- Assured configuration: controlled, auditable engineering with credentials, privileged access, execution paths and deployments managed to Defence security expectations
- Documented sustainment: SOPs, baseline lists of installation and a patch management plan, plus level 3 engineering support, mentoring and knowledge transfer to D-ICT personnel
Systems and methods
Windows Server 2022 · PowerShell · Pester · Ansible · GitLab Actions · Active Directory / ADFS · Group Policy · KVM / OpenStack · Azure DevOps · SharePoint administration
The result
The engagement is ongoing, with continued refinement of automation, build and sustainment processes as the capability progresses through production validation and operational readiness. By rapidly deploying a cleared, technically advanced specialist, Profectus is helping D-ICT strengthen automation maturity, enhance operational resilience and establish a sustainable foundation for the long-term evolution of deployed ICT capabilities, while building internal capacity through mentoring, documentation and structured handover so Defence teams can self-sustain the capability post-delivery.
