About the Role
Deliver an enterprise exposure management and asset visibility capability for a major Australian client, transforming raw asset data into actionable risk insights for security leadership. This is a hands-on role where you will be the technical authority, leading design, deployment, and operational handover.
Responsibilities
- Design and deploy an agentless asset discovery and exposure management platform across corporate IT, cloud, OT, and unmanaged device estates.
- Plan and execute safe active scanning in fragile environments, including production OT and legacy embedded systems, without operational disruption.
- Build and tune asset fingerprinting, classification, and ownership models across a large, heterogeneous estate.
- Integrate discovery data with the client’s existing CMDB, vulnerability management, EDR, and SIEM tooling via API.
- Develop risk prioritisation logic, dashboards, and executive reporting that map findings to NIST CSF, the Essential Eight, and the client’s regulatory obligations.
- Identify unmanaged, unagentable, and end-of-life assets, and drive remediation plans with asset owners.
- Validate network segmentation integrity and map attack paths across IT and OT boundaries.
- Produce operational runbooks and transition the capability to the client’s BAU security team.
Requirements
- Seven or more years in cyber security, with at least three in asset visibility, exposure management, or vulnerability management delivery.
- Hands-on experience with one or more CAASM or asset intelligence platforms (e.g., Armis, Claroty xDome, Forescout, Nozomi Networks, Axonius, Sevco, JupiterOne, Lansweeper, or Tenable OT Security).
- Strong practical networking skills: TCP/IP, routing and switching, VLANs, network segmentation, and the ability to read a packet capture.
- Working knowledge of OT and industrial protocols (Modbus, DNP3, BACnet, EtherNet/IP) and the operational sensitivities of scanning production control systems.
- Experience integrating security tooling via REST APIs.
- Scripting in Python or PowerShell for data enrichment and reporting.
- Familiarity with vulnerability management platforms such as Tenable, Qualys, or Rapid7, and understanding how asset context improves their output.
- Ability to write clearly for both engineers and executives.
- Ability to hold your own in a room with a CISO.
- Valid Australian work rights.
- Ability to obtain a Baseline or NV1 clearance is advantageous.
- Exposure to Purdue model architectures and IEC 62443 (Nice to have).
- Prior consulting or systems integrator delivery experience (Nice to have).
- Certifications such as GICSP, GRID, CISSP, OSCP, or vendor-specific asset platform accreditations (Nice to have).
- Experience in regulated industries — utilities, telecommunications, financial services, or critical infrastructure under the SOCI Act (Nice to have).
- Applicants may be required to undergo relevant background, probity, and police checks.
Skills
- Asset visibility
- Exposure management
- Vulnerability management
- CAASM platforms
- Asset intelligence platforms
- Networking (TCP/IP, routing, switching, VLANs, network segmentation)
- Packet capture analysis
- OT and industrial protocols (Modbus, DNP3, BACnet, EtherNet/IP)
- API integration (REST)
- Python scripting
- PowerShell scripting
- Vulnerability management platforms (Tenable, Qualys, Rapid7)
- Technical design
- Deployment
- Operational handover
- Risk prioritisation
- Dashboard development
- Executive reporting
- Purdue model architectures
- IEC 62443
Location
- Australia
Work Type
- Full-time
Experience Level
- Senior
About the Company
- NCS Australia believes in doing technology services better through quality, people focus, and challenging traditional thinking.
- The company partners with clients and communities to make tomorrow together.
- NCS is committed to creating an environment that prioritises innovation, collaboration, and purposeful work.
- The diverse team is empowered to make a meaningful impact with curiosity, creativity, and resilience.
- NCS values Adventure, Excellence, Integrity, Ownership, and Unity.
Equal Opportunity
- We celebrate diversity and inclusion.
- We value the different perspectives, experiences, and strengths our people bring.
- We’re committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed.
- We provide equal employment opportunities and reasonable adjustments throughout the recruitment process.
