> "Given the recent malware hitting the internet for macs, our aggressive firewalling already doesn't cut it for security".
Three odd trojans that need to be explicitly user-installed, rarely if ever met in the wild, and blocked by the daily-updated system are a threat to your über-firewall? I'm not downplaying the recent evolution in the area, but up until now you have to admit it's a dud.
> "They're backed up with a combination of rsync and a home-rolled login hook/git solution"
You do know that Time Machine works perfectly fine on spare bundles over AFP network shares, right? Besides, I wonder if your homebrew rsync solution handles hardlinks correctly in addition to alternate file streams and HFS+ extended attributes. I also wonder what your typical recovery scenarios look like.
> "Nether does a windows domain"
Any Windows computer needs at least an antivirus to combat the daily flow of trojans, and viruses, and worms. (And yes MSE is third-aprty in the sense that it's not there right from the start, enabled by default).
Given the current state of OS X malware, I'd venture to say that the current state of security in OS X is way more than adequate, out to the box.
As for general maintenance, manageability and user assistance, my experience has been such as it is one or two orders of magnitude down from Windows.