Talent.com
The Recruitment Company
Security Services - The Recruitment CompanyThe Recruitment Company • North Sydney, NSW, AU
Search for other jobs
Security Services - The Recruitment Company

Security Services - The Recruitment Company

The Recruitment Company • North Sydney, NSW, AU
27 days ago
Job description

The opportunity

This is a permanent Vulnerability Manager opportunity for someone who wants to take genuine ownership of enterprise Vulnerability Management rather than simply run scans, distribute findings or produce monthly reports.

You’ll join a small Information Security team where VM has previously been shared across existing team members. This is a new dedicated position, created to provide long-term ownership, stronger prioritisation and more capacity to drive vulnerabilities through to resolution.

The role combines governance, risk analysis, technical understanding, tooling and stakeholder management. You won’t be expected to personally remediate every issue, but you will need enough technical depth to understand the vulnerability, assess the impact, work out what genuinely matters, identify the right technical owners and keep the issue moving through to closure.

Why this role stands out

  • New permanent headcount with genuine ownership of the VM capability
  • Long-term opportunity to build knowledge of the environment and improve outcomes over time
  • 100% cloud environment
  • Qualys as the main Vulnerability Management platform
  • Ownership across multiple security tools and penetration-testing activity
  • Small security team where you will be visible and able to make a real impact
  • Broader exposure to security projects and BAU beyond your core VM remit
  • Opportunity to grow across wider cyber disciplines rather than being pigeonholed into one narrow function

What you’ll be doing

  • Own vulnerabilities from identification and assessment through to remediation and closure
  • Analyse findings and determine what genuinely requires priority attention
  • Apply risk-based prioritisation rather than relying on severity scores alone
  • Work with Security, Infrastructure, Cloud, Application and Platform teams to drive remediation
  • Manage remediation targets, ageing, exceptions and escalation pathways
  • Operate and oversee VM tooling, including Qualys
  • Coordinate penetration testing and manage findings through to resolution
  • Maintain vulnerability governance, risk acceptance and exception processes
  • Improve reporting, workflows, automation and tooling
  • Provide clear vulnerability insights to technical and senior stakeholders
  • Contribute to wider security projects and initiatives when priorities require it

What you’ll bring

  • Around 5+ years’ experience in cyber security
  • At least 3 years’ experience in Vulnerability Management and/or Information Security governance
  • Practical experience working with enterprise VM processes and remediation
  • Experience with tools such as Qualys, Tenable, Rapid7 or similar
  • Strong understanding of vulnerability assessment, risk prioritisation and remediation governance
  • Enough technical knowledge to understand impact, likely remediation paths and when to engage specialist teams
  • Experience working across cloud, infrastructure, application or platform environments
  • Exposure to penetration testing and management of findings
  • Strong stakeholder communication and the confidence to push remediation through
  • Ability to prioritise competing demands and work effectively in a small team
  • Australian citizen or PR

Financial-services experience, ISO27001 exposure and certifications such as CISSP, CISM, CRISC or equivalent are advantageous rather than essential.

Who this will suit

This role will suit someone currently working in a permanent Cyber Security, Vulnerability Management or Security Operations position who is ready for broader ownership and wants to build longer-term capability within one organisation.

You may currently be a Senior Cyber Security Analyst, Vulnerability Analyst, Security Engineer or VM Specialist and be looking for the next step into a role where you can genuinely own the vulnerability lifecycle.

It is less likely to suit someone looking for a Head of Cyber position, a large-team leadership role, a purely strategic/GRC role or short-term project work.

Apply

If you have strong Vulnerability Management experience and enjoy taking ownership of risk through to remediation, I’d be keen to speak with you.

Amanda Evans
The Recruitment Company

Apply for This Job

Create a job alert for this search

Security Services - The Recruitment Company • North Sydney, NSW, AU