Senior Consultant - Exposure Management & Asset Visibility at NCS Australia | AU | Rezi

Senior Consultant - Exposure Management & Asset Visibility at NCS Australia

Senior Consultant - Exposure Management & Asset Visibility

NCS Australia · AU

3 days ago

Senior Consultant - Exposure Management & Asset Visibility

NCS Australia · AU

3 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Deliver an enterprise exposure management and asset visibility capability for a major Australian client, transforming raw asset data into actionable risk insights for security leadership. This is a hands-on role where you will be the technical authority, leading design, deployment, and operational handover.

Responsibilities

  • Design and deploy an agentless asset discovery and exposure management platform across corporate IT, cloud, OT, and unmanaged device estates.
  • Plan and execute safe active scanning in fragile environments, including production OT and legacy embedded systems, without operational disruption.
  • Build and tune asset fingerprinting, classification, and ownership models across a large, heterogeneous estate.
  • Integrate discovery data with the client’s existing CMDB, vulnerability management, EDR, and SIEM tooling via API.
  • Develop risk prioritisation logic, dashboards, and executive reporting that map findings to NIST CSF, the Essential Eight, and the client’s regulatory obligations.
  • Identify unmanaged, unagentable, and end-of-life assets, and drive remediation plans with asset owners.
  • Validate network segmentation integrity and map attack paths across IT and OT boundaries.
  • Produce operational runbooks and transition the capability to the client’s BAU security team.

Requirements

  • Seven or more years in cyber security, with at least three in asset visibility, exposure management, or vulnerability management delivery.
  • Hands-on experience with one or more CAASM or asset intelligence platforms (e.g., Armis, Claroty xDome, Forescout, Nozomi Networks, Axonius, Sevco, JupiterOne, Lansweeper, or Tenable OT Security).
  • Strong practical networking skills: TCP/IP, routing and switching, VLANs, network segmentation, and the ability to read a packet capture.
  • Working knowledge of OT and industrial protocols (Modbus, DNP3, BACnet, EtherNet/IP) and the operational sensitivities of scanning production control systems.
  • Experience integrating security tooling via REST APIs.
  • Scripting in Python or PowerShell for data enrichment and reporting.
  • Familiarity with vulnerability management platforms such as Tenable, Qualys, or Rapid7, and understanding how asset context improves their output.
  • Ability to write clearly for both engineers and executives.
  • Ability to hold your own in a room with a CISO.
  • Valid Australian work rights.
  • Ability to obtain a Baseline or NV1 clearance is advantageous.
  • Exposure to Purdue model architectures and IEC 62443 (Nice to have).
  • Prior consulting or systems integrator delivery experience (Nice to have).
  • Certifications such as GICSP, GRID, CISSP, OSCP, or vendor-specific asset platform accreditations (Nice to have).
  • Experience in regulated industries — utilities, telecommunications, financial services, or critical infrastructure under the SOCI Act (Nice to have).
  • Applicants may be required to undergo relevant background, probity, and police checks.

Skills

  • Asset visibility
  • Exposure management
  • Vulnerability management
  • CAASM platforms
  • Asset intelligence platforms
  • Networking (TCP/IP, routing, switching, VLANs, network segmentation)
  • Packet capture analysis
  • OT and industrial protocols (Modbus, DNP3, BACnet, EtherNet/IP)
  • API integration (REST)
  • Python scripting
  • PowerShell scripting
  • Vulnerability management platforms (Tenable, Qualys, Rapid7)
  • Technical design
  • Deployment
  • Operational handover
  • Risk prioritisation
  • Dashboard development
  • Executive reporting
  • Purdue model architectures
  • IEC 62443

Location

  • Australia

Work Type

  • Full-time

Experience Level

  • Senior

About the Company

  • NCS Australia believes in doing technology services better through quality, people focus, and challenging traditional thinking.
  • The company partners with clients and communities to make tomorrow together.
  • NCS is committed to creating an environment that prioritises innovation, collaboration, and purposeful work.
  • The diverse team is empowered to make a meaningful impact with curiosity, creativity, and resilience.
  • NCS values Adventure, Excellence, Integrity, Ownership, and Unity.

Equal Opportunity

  • We celebrate diversity and inclusion.
  • We value the different perspectives, experiences, and strengths our people bring.
  • We’re committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed.
  • We provide equal employment opportunities and reasonable adjustments throughout the recruitment process.