About the Role
Support the Control Lead in strengthening vulnerability remediation governance, measurement, and improvement across the Group. Work closely with technology teams, IT service owners, and business stakeholders to ensure they understand their vulnerability posture, meet remediation expectations, and address control gaps.
Responsibilities
- Support the ongoing management and continuous improvement of the Vulnerability Management Standard and related control requirements.
- Govern vulnerability remediation activities by helping technology teams understand their vulnerability posture, remediation obligations, and control compliance requirements.
- Engage with IT service owners, technology domains, and business units to support timely, risk-based remediation of vulnerabilities.
- Assess and monitor control effectiveness, identify areas outside tolerance, and work with stakeholders to understand root causes and improvement actions.
- Develop and use dashboards, reporting, and metrics to provide visibility of remediation compliance, control performance, and security posture.
- Assess and respond to ServiceNow (SNOW) requests relating to vulnerability management, including requests to exclude assets from scanning or defer vulnerabilities in line with policy requirements.
- Support process improvement, assurance, and audit activities through evidence gathering, control validation, and continuous improvement initiatives.
Requirements
- Experience in cyber security, technology risk, vulnerability management, security operations, infrastructure, cloud, engineering, or technology controls.
- Understanding of vulnerability management concepts, including vulnerability identification, prioritisation, remediation governance, and risk-based decision making.
- Ability to confidently engage with technical stakeholders and constructively challenge assumptions around remediation timelines, risk acceptance, and control compliance.
- Comfort working with data, dashboards, and reporting to identify trends, insights, and areas requiring attention.
- A continuous improvement mindset and ability to help build practical, stable, and scalable processes.
- Curiosity, humility, and confidence to speak up, challenge constructively, and continue building knowledge.
Skills
- Understanding of cyber security risk frameworks and guidance, including ASD Essential Eight, ASD ISM, NIST, and related control frameworks.
- Experience with vulnerability prioritisation and risk assessment, including frameworks such as CVSS and EPSS.
- Familiarity with vulnerability scanning or exposure management tools such as Qualys, Wiz, or Microsoft Defender.
- Familiarity with patch management tools or processes, including Tanium or similar enterprise technologies.
- Understanding of vulnerabilities across servers, endpoints, cloud environments, web applications, and related technology platforms.
- Experience in technology controls, cyber controls, or risk governance.
- Strong technical cyber or technology backgrounds.
- CISSP, CISM, or CRISC certifications are advantageous.
Location
- At least half your time each month connecting in office
Work Type
- Flexibility to balance where work is done
- Flexible working options available
- Changing start and finish times
- Part-time arrangements
- Job share
Experience Level
- Experience in cyber security, technology risk, vulnerability management, security operations, infrastructure, cloud, engineering or technology controls.
- Experience in technology controls, cyber controls or risk governance will be highly regarded
- Candidates with strong technical cyber or technology backgrounds who can confidently engage with stakeholders are also welcome.
About the Company
- One of Australia’s leading cyber security teams, helping protect the Group, our customers and the community.
- The Cyber Controls Chapter Area sits within Group Security and is responsible for governing and continuously improving cyber control capabilities across the organisation.
