Job Description
\n
Security Engineer, runZero Platform
\n
Location: Sydney
\n
Contract: 6 Months + Highly Likely Extensions
About the Opportunity \n
A leading technology consultancy is seeking an experienced Security Engineer to design, implement and operate an enterprise asset-discovery capability using runZero .
\n
This is a hands‑on engineering role combining platform configuration, security automation, systems integration and site reliability engineering. You will help establish a scalable operating model that delivers accurate asset visibility across corporate, data‑centre, cloud, remote‑access, network, IoT and relevant operational technology environments.
Key Responsibilities \n
- \n
- Design and implement the runZero operating model, including environments, access controls, roles, sites, asset groups, tags and naming standards. \n
- Configure discovery coverage across corporate, cloud, data‑centre, remote‑access, network, IoT and relevant OT environments. \n
- Develop active‑scanning, passive‑discovery and integration patterns suited to different network zones and operational risk profiles. \n
- Establish appropriate scanning standards, approval controls, maintenance windows and exception processes. \n
- Configure asset classification, ownership, business context, criticality and lifecycle information. \n
- Develop reusable configuration patterns and maintain separation between production, testing and experimental changes. \n
- Integrate runZero with enterprise platforms such as CMDB, ServiceNow, Tenable, EDR, NAC, DNS/DHCP, cloud services, identity systems, SIEM and SOAR. \n
- Implement secure API‑based data ingestion and egress using service identities and least‑privilege access. \n
- Automate asset reconciliation, deduplication, enrichment, ownership mapping and data‑quality validation. \n
- Define integration contracts, schemas, field mappings, error handling, retry behaviour and support expectations. \n
- Build automated workflows for newly discovered assets, exposed services, control gaps, unauthorised devices and material changes. \n
- Use APIs, webhooks, scripts and workflow platforms to streamline administration and improve response times. \n
- Automate scan scheduling, configuration validation, asset tagging, reporting and lifecycle management. \n
- Design safe, repeatable automation that avoids duplicate records, tickets and configuration drift. \n
- Apply version control, peer review, automated testing, release controls and rollback procedures to platform changes. \n
- Establish service indicators, dashboards and alerts covering discovery coverage, data freshness, integration health, scanning and workflow reliability. \n
- Develop operational runbooks and support backup, recovery, disaster‑recovery and business‑continuity planning. \n
- Implement role‑based access, privileged‑access controls, administrative separation and auditable change history. \n
- Support architecture, security, privacy, risk and control‑assurance reviews. \n
Required Skills and Experience \n
- \n
- Strong experience engineering and operating enterprise security or asset‑discovery platforms. \n
- Practical expertise with runZero or a comparable asset‑discovery and attack‑surface visibility platform. \n
- Strong knowledge of active scanning, passive discovery and network‑zone risk management. \n
- Experience integrating security platforms with CMDB, ServiceNow, vulnerability‑management, endpoint, network, cloud, identity and SIEM/SOAR technologies. \n
- Demonstrated API, webhook, scripting and workflow‑automation capability. \n
- Experience with asset reconciliation, deduplication, enrichment and data‑quality controls. \n
- Sound understanding of least‑privilege access, service identities, secrets management and role‑based access control. \n
- Experience applying infrastructure‑as‑code or configuration‑as‑code practices, version control, testing and controlled releases. \n
- Strong operational knowledge across monitoring, alerting, incident runbooks, recovery, performance and capacity management. \n
Desirable Experience \n
- \n
- Experience supporting asset discovery across cloud, IoT or operational technology environments. \n
- Knowledge of ServiceNow, Tenable, EDR, NAC, DNS/DHCP, SIEM and SOAR integrations. \n
- Experience designing event‑driven and idempotent automation. \n
- Familiarity with security architecture reviews, privacy assessments, risk assessments and regulatory control requirements. \n
What’s on Offer \n
- \n
- A technically challenging role with significant ownership of an enterprise security platform. \n
- The opportunity to build scalable discovery, integration and automation capabilities. \n
- Broad collaboration across security, infrastructure, network, cloud and application teams. \n
- A role spanning engineering delivery, automation, operational resilience and security governance. \n
\n
#J-18808-Ljbffr